cpuoct2025csaf

HIGH CVSS 8.2 csaf_oracle
Description

No description available.

Timeline
Published
2025-10-21 13:00 UTC
Last Modified
2025-10-20
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "document": {
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Oracle. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp"
      }
    },
    "publisher": {
      "category": "vendor",
      "name": "Oracle",
      "namespace": "https://www.oracle.com"
    },
    "references": [
      {
        "summary": "URL to html version of Advisory",
        "url": "https://www.oracle.com/security-alerts/cpuoct2025.html"
      },
      {
        "category": "self",
        "summary": "URL to CSAF version of Advisory",
        "url": "https://www.oracle.com/docs/tech/security-alerts/cpuoct2025csaf.json"
      }
    ],
    "title": "Oracle Critical Patch Update Advisory - October 2025 - Oracle CSAF",
    "tracking": {
      "current_release_date": "2025-10-20T13:00:00-07:00",
      "id": "CPUOct2025csaf",
      "initial_release_date": "2025-10-21T13:00:00-07:00",
      "revision_history": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "number": "1",
          "summary": "Initial Release"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle BI Publisher Version 7.6.0.0.0",
                    "product": {
                      "name": "Oracle BI Publisher Version 7.6.0.0.0",
                      "product_id": "P-1479V-7.6.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:bi_publisher:7.6.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle BI Publisher Version 8.2.0.0.0",
                    "product": {
                      "name": "Oracle BI Publisher Version 8.2.0.0.0",
                      "product_id": "P-1479V-8.2.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:bi_publisher:8.2.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle BI Publisher"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Business Intelligence Enterprise Edition Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Business Intelligence Enterprise Edition Version 12.2.1.4.0",
                      "product_id": "P-2025V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Business Intelligence Enterprise Edition Version 7.6.0.0.0",
                    "product": {
                      "name": "Oracle Business Intelligence Enterprise Edition Version 7.6.0.0.0",
                      "product_id": "P-2025V-7.6.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:business_intelligence:7.6.0.0.0:*:*:*:enterprise:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Business Intelligence Enterprise Edition Version 8.2.0.0.0",
                    "product": {
                      "name": "Oracle Business Intelligence Enterprise Edition Version 8.2.0.0.0",
                      "product_id": "P-2025V-8.2.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:business_intelligence:8.2.0.0.0:*:*:*:enterprise:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Business Intelligence Enterprise Edition"
              }
            ],
            "category": "product_family",
            "name": "Oracle Analytics"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Commerce Guided Search(Content Acquisition System) Version 11.4.0",
                    "product": {
                      "name": "Oracle Commerce Guided Search(Content Acquisition System) Version 11.4.0",
                      "product_id": "P-9633(Content Acquisition System)V-11.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:commerce_guided_search:11.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Commerce Guided Search(Tools And Frameworks) Version 11.4.0",
                    "product": {
                      "name": "Oracle Commerce Guided Search(Tools And Frameworks) Version 11.4.0",
                      "product_id": "P-9633(Tools And Frameworks)V-11.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:commerce_guided_search:11.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Commerce Guided Search(Tools And Frameworks, Content Acquisition System, Platform Services) Version 11.4.0",
                    "product": {
                      "name": "Oracle Commerce Guided Search(Tools And Frameworks, Content Acquisition System, Platform Services) Version 11.4.0",
                      "product_id": "P-9633(Tools And Frameworks, Content Acquisition System, Platform Services)V-11.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:commerce_guided_search:11.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Commerce Guided Search"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Commerce Platform Version 11.4.0",
                    "product": {
                      "name": "Oracle Commerce Platform Version 11.4.0",
                      "product_id": "P-9348V-11.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:commerce_platform:11.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Commerce Platform"
              }
            ],
            "category": "product_family",
            "name": "Oracle Commerce"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Management Cloud Engine Version 25.1.0.0.0",
                    "product": {
                      "name": "Management Cloud Engine Version 25.1.0.0.0",
                      "product_id": "P-14252V-25.1.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:management_cloud_engine:25.1.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Management Cloud Engine"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Automated Test Suite Version 24.2.6",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Automated Test Suite Version 24.2.6",
                      "product_id": "P-14488V-24.2.6",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:24.2.6:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Automated Test Suite Version 25.1.202",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Automated Test Suite Version 25.1.202",
                      "product_id": "P-14488V-25.1.202",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:25.1.202:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Automated Test Suite"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Cloud Native Core Binding Support Function(Alarms, KPI, and Measurements) Version 24.2.7-25.1.200",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Binding Support Function(Alarms, KPI, and Measurements) Version 24.2.7-25.1.200",
                      "product_id": "P-14121(Alarms, KPI, and Measurements)V-24.2.7-25.1.200",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:24.2.7-25.1.200:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Cloud Native Core Binding Support Function(Install) Version 24.2.7-25.1.200",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Binding Support Function(Install) Version 24.2.7-25.1.200",
                      "product_id": "P-14121(Install)V-24.2.7-25.1.200",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:24.2.7-25.1.200:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Cloud Native Core Binding Support Function Version 24.2.7-25.1.200",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Binding Support Function Version 24.2.7-25.1.200",
                      "product_id": "P-14121V-24.2.7-25.1.200",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:24.2.7-25.1.200:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Binding Support Function"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Certificate Management Version 25.1.200",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Certificate Management Version 25.1.200",
                      "product_id": "P-14868V-25.1.200",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_certificate_management:25.1.200:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Certificate Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Console Version 24.2.5",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Console Version 24.2.5",
                      "product_id": "P-14250V-24.2.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_console:24.2.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Console Version 25.1.200",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Console Version 25.1.200",
                      "product_id": "P-14250V-25.1.200",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_console:25.1.200:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Console"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core DBTier Version 25.1.200",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core DBTier Version 25.1.200",
                      "product_id": "P-14974V-25.1.200",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_dbtier:25.1.200:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core DBTier"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Network Function Cloud Native Environment Version 25.1.100",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Network Function Cloud Native Environment Version 25.1.100",
                      "product_id": "P-14125V-25.1.100",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:25.1.100:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Network Function Cloud Native Environment Version 25.1.200",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Network Function Cloud Native Environment Version 25.1.200",
                      "product_id": "P-14125V-25.1.200",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:25.1.200:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Network Function Cloud Native Environment"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Network Repository Function(Signaling) Version 24.2.5",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Network Repository Function(Signaling) Version 24.2.5",
                      "product_id": "P-14118(Signaling)V-24.2.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:24.2.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Network Repository Function(Signaling) Version 25.1.202",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Network Repository Function(Signaling) Version 25.1.202",
                      "product_id": "P-14118(Signaling)V-25.1.202",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:25.1.202:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Network Repository Function"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Cloud Native Core Network Slice Selection Function Version 25.1.100-25.1.200",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Network Slice Selection Function Version 25.1.100-25.1.200",
                      "product_id": "P-14130V-25.1.100-25.1.200",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:25.1.100-25.1.200:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Network Slice Selection Function Version 25.1.200",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Network Slice Selection Function Version 25.1.200",
                      "product_id": "P-14130V-25.1.200",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:25.1.200:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Network Slice Selection Function"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Cloud Native Core Policy(Alarms, KPI, and Measurements) Version 24.2.7-25.1.200",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Policy(Alarms, KPI, and Measurements) Version 24.2.7-25.1.200",
                      "product_id": "P-14277(Alarms, KPI, and Measurements)V-24.2.7-25.1.200",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_policy:24.2.7-25.1.200:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Cloud Native Core Policy(Configuration) Version 24.2.7-25.1.200",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Policy(Configuration) Version 24.2.7-25.1.200",
                      "product_id": "P-14277(Configuration)V-24.2.7-25.1.200",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_policy:24.2.7-25.1.200:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Cloud Native Core Policy Version 24.2.7-25.1.200",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Policy Version 24.2.7-25.1.200",
                      "product_id": "P-14277V-24.2.7-25.1.200",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_policy:24.2.7-25.1.200:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Policy"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 24.2.5",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 24.2.5",
                      "product_id": "P-14123V-24.2.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:24.2.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 25.1.200",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 25.1.200",
                      "product_id": "P-14123V-25.1.200",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:25.1.200:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 25.1.201",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 25.1.201",
                      "product_id": "P-14123V-25.1.201",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:25.1.201:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Service Communication Proxy Version 25.1.200",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Service Communication Proxy Version 25.1.200",
                      "product_id": "P-14117V-25.1.200",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:25.1.200:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Service Communication Proxy Version 25.2.100",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Service Communication Proxy Version 25.2.100",
                      "product_id": "P-14117V-25.2.100",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:25.2.100:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Service Communication Proxy"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Unified Data Repository Version 25.1.100",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Unified Data Repository Version 25.1.100",
                      "product_id": "P-14119V-25.1.100",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:25.1.100:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Unified Data Repository Version 25.1.200",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Unified Data Repository Version 25.1.200",
                      "product_id": "P-14119V-25.1.200",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:25.1.200:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Unified Data Repository"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Diameter Signaling Router Version 9.0.0.0.0",
                    "product": {
                      "name": "Oracle Communications Diameter Signaling Router Version 9.0.0.0.0",
                      "product_id": "P-10899V-9.0.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_diameter_signaling_router:9.0.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Diameter Signaling Router Version 9.1.0.0.0",
                    "product": {
                      "name": "Oracle Communications Diameter Signaling Router Version 9.1.0.0.0",
                      "product_id": "P-10899V-9.1.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_diameter_signaling_router:9.1.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Diameter Signaling Router"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications EAGLE Element Management System Version 46.6",
                    "product": {
                      "name": "Oracle Communications EAGLE Element Management System Version 46.6",
                      "product_id": "P-11125V-46.6",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_eagle_element_management_system:46.6:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications EAGLE Element Management System Version 47.0",
                    "product": {
                      "name": "Oracle Communications EAGLE Element Management System Version 47.0",
                      "product_id": "P-11125V-47.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_eagle_element_management_system:47.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications EAGLE Element Management System"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications EAGLE LNP Application Processor Version 10.2.1.0",
                    "product": {
                      "name": "Oracle Communications EAGLE LNP Application Processor Version 10.2.1.0",
                      "product_id": "P-11118V-10.2.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_eagle_lnp_application_processor:10.2.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications EAGLE LNP Application Processor Version 11.0.0.1-11.0.0.2",
                    "product": {
                      "name": "Oracle Communications EAGLE LNP Application Processor Version 11.0.0.1-11.0.0.2",
                      "product_id": "P-11118V-11.0.0.1-11.0.0.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_eagle_lnp_application_processor:11.0.0.1-11.0.0.2:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications EAGLE LNP Application Processor"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications LSMS Version 13.5.1.0",
                    "product": {
                      "name": "Oracle Communications LSMS Version 13.5.1.0",
                      "product_id": "P-11114V-13.5.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_lsms:13.5.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications LSMS Version 14.0.0.1",
                    "product": {
                      "name": "Oracle Communications LSMS Version 14.0.0.1",
                      "product_id": "P-11114V-14.0.0.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_lsms:14.0.0.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications LSMS Version 14.0.0.2",
                    "product": {
                      "name": "Oracle Communications LSMS Version 14.0.0.2",
                      "product_id": "P-11114V-14.0.0.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_lsms:14.0.0.2:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications LSMS"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Analytics Data Director Version 24.2.0",
                    "product": {
                      "name": "Oracle Communications Network Analytics Data Director Version 24.2.0",
                      "product_id": "P-14547V-24.2.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_analytics_data_director:24.2.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Network Analytics Data Director Version 24.2.0-24.2.1",
                    "product": {
                      "name": "Oracle Communications Network Analytics Data Director Version 24.2.0-24.2.1",
                      "product_id": "P-14547V-24.2.0-24.2.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_analytics_data_director:24.2.0-24.2.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Analytics Data Director Version 24.2.1",
                    "product": {
                      "name": "Oracle Communications Network Analytics Data Director Version 24.2.1",
                      "product_id": "P-14547V-24.2.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_analytics_data_director:24.2.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Analytics Data Director Version 24.3.0",
                    "product": {
                      "name": "Oracle Communications Network Analytics Data Director Version 24.3.0",
                      "product_id": "P-14547V-24.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_analytics_data_director:24.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Analytics Data Director Version 25.1.100",
                    "product": {
                      "name": "Oracle Communications Network Analytics Data Director Version 25.1.100",
                      "product_id": "P-14547V-25.1.100",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_analytics_data_director:25.1.100:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Analytics Data Director Version 25.1.200",
                    "product": {
                      "name": "Oracle Communications Network Analytics Data Director Version 25.1.200",
                      "product_id": "P-14547V-25.1.200",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_analytics_data_director:25.1.200:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Network Analytics Data Director"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Operations Monitor Version 5.1",
                    "product": {
                      "name": "Oracle Communications Operations Monitor Version 5.1",
                      "product_id": "P-10761V-5.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_operations_monitor:5.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Operations Monitor Version 5.2",
                    "product": {
                      "name": "Oracle Communications Operations Monitor Version 5.2",
                      "product_id": "P-10761V-5.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_operations_monitor:5.2:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Operations Monitor Version 6.0",
                    "product": {
                      "name": "Oracle Communications Operations Monitor Version 6.0",
                      "product_id": "P-10761V-6.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_operations_monitor:6.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Operations Monitor"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Session Border Controller Version 10.0.0",
                    "product": {
                      "name": "Oracle Communications Session Border Controller Version 10.0.0",
                      "product_id": "P-10750V-10.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_session_border_controller:10.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Session Border Controller Version 4.1.0",
                    "product": {
                      "name": "Oracle Communications Session Border Controller Version 4.1.0",
                      "product_id": "P-10750V-4.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_session_border_controller:4.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Session Border Controller Version 9.0.0",
                    "product": {
                      "name": "Oracle Communications Session Border Controller Version 9.0.0",
                      "product_id": "P-10750V-9.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_session_border_controller:9.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Session Border Controller Version 9.2.0-9.3.0",
                    "product": {
                      "name": "Oracle Communications Session Border Controller Version 9.2.0-9.3.0",
                      "product_id": "P-10750V-9.2.0-9.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_session_border_controller:9.2.0-9.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Session Border Controller Version 9.3.0",
                    "product": {
                      "name": "Oracle Communications Session Border Controller Version 9.3.0",
                      "product_id": "P-10750V-9.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_session_border_controller:9.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Session Border Controller"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Enterprise Communications Broker Version 4.1.0",
                    "product": {
                      "name": "Oracle Enterprise Communications Broker Version 4.1.0",
                      "product_id": "P-10758V-4.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:enterprise_communications_broker:4.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Enterprise Communications Broker Version 4.1.0-4.2.0",
                    "product": {
                      "name": "Oracle Enterprise Communications Broker Version 4.1.0-4.2.0",
                      "product_id": "P-10758V-4.1.0-4.2.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:enterprise_communications_broker:4.1.0-4.2.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Enterprise Communications Broker Version 4.2.0",
                    "product": {
                      "name": "Oracle Enterprise Communications Broker Version 4.2.0",
                      "product_id": "P-10758V-4.2.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:enterprise_communications_broker:4.2.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Enterprise Communications Broker Version 5.0.0",
                    "product": {
                      "name": "Oracle Enterprise Communications Broker Version 5.0.0",
                      "product_id": "P-10758V-5.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:enterprise_communications_broker:5.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Enterprise Communications Broker"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Enterprise Operations Monitor Version 5.1",
                    "product": {
                      "name": "Oracle Enterprise Operations Monitor Version 5.1",
                      "product_id": "P-10762V-5.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:enterprise_operations_monitor:5.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Enterprise Operations Monitor Version 5.2",
                    "product": {
                      "name": "Oracle Enterprise Operations Monitor Version 5.2",
                      "product_id": "P-10762V-5.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:enterprise_operations_monitor:5.2:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Enterprise Operations Monitor Version 6.0",
                    "product": {
                      "name": "Oracle Enterprise Operations Monitor Version 6.0",
                      "product_id": "P-10762V-6.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:enterprise_operations_monitor:6.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Enterprise Operations Monitor"
              }
            ],
            "category": "product_family",
            "name": "Oracle Communications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Billing and Revenue Management(Platform) Version 12.0.0.4.0-15.0.1.0.0",
                    "product": {
                      "name": "Oracle Communications Billing and Revenue Management(Platform) Version 12.0.0.4.0-15.0.1.0.0",
                      "product_id": "P-2136(Platform)V-12.0.0.4.0-15.0.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.4.0-15.0.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Billing and Revenue Management(Security) Version 12.0.0.4.0-15.0.1.0.0",
                    "product": {
                      "name": "Oracle Communications Billing and Revenue Management(Security) Version 12.0.0.4.0-15.0.1.0.0",
                      "product_id": "P-2136(Security)V-12.0.0.4.0-15.0.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.4.0-15.0.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Billing and Revenue Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Calendar Server Version 8.0.0.7.0",
                    "product": {
                      "name": "Oracle Communications Calendar Server Version 8.0.0.7.0",
                      "product_id": "P-8494V-8.0.0.7.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_calendar_server:8.0.0.7.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Calendar Server Version 8.0.0.8.0",
                    "product": {
                      "name": "Oracle Communications Calendar Server Version 8.0.0.8.0",
                      "product_id": "P-8494V-8.0.0.8.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_calendar_server:8.0.0.8.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Calendar Server"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Contacts Server Version 8.0.0.9.0",
                    "product": {
                      "name": "Oracle Communications Contacts Server Version 8.0.0.9.0",
                      "product_id": "P-10696V-8.0.0.9.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_contacts_server:8.0.0.9.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Contacts Server"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Converged Charging System Version 2.0.0.0.0",
                    "product": {
                      "name": "Oracle Communications Converged Charging System Version 2.0.0.0.0",
                      "product_id": "P-14565V-2.0.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_converged_charging_system:2.0.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Converged Charging System Version 2.0.0.0.0-2.0.0.1.0",
                    "product": {
                      "name": "Oracle Communications Converged Charging System Version 2.0.0.0.0-2.0.0.1.0",
                      "product_id": "P-14565V-2.0.0.0.0-2.0.0.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_converged_charging_system:2.0.0.0.0-2.0.0.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Converged Charging System Version 2.0.0.1.0",
                    "product": {
                      "name": "Oracle Communications Converged Charging System Version 2.0.0.1.0",
                      "product_id": "P-14565V-2.0.0.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_converged_charging_system:2.0.0.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Converged Charging System"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Convergence Version 3.0.3.3.0",
                    "product": {
                      "name": "Oracle Communications Convergence Version 3.0.3.3.0",
                      "product_id": "P-8501V-3.0.3.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_convergence:3.0.3.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Convergence Version 3.0.3.4.0",
                    "product": {
                      "name": "Oracle Communications Convergence Version 3.0.3.4.0",
                      "product_id": "P-8501V-3.0.3.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_convergence:3.0.3.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Convergence"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Convergent Charging Controller Version 12.0.1.0.0-12.0.6.0.0",
                    "product": {
                      "name": "Oracle Communications Convergent Charging Controller Version 12.0.1.0.0-12.0.6.0.0",
                      "product_id": "P-12985V-12.0.1.0.0-12.0.6.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_convergent_charging_controller:12.0.1.0.0-12.0.6.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Convergent Charging Controller Version 12.0.3.0.0-12.0.6.0.0",
                    "product": {
                      "name": "Oracle Communications Convergent Charging Controller Version 12.0.3.0.0-12.0.6.0.0",
                      "product_id": "P-12985V-12.0.3.0.0-12.0.6.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_convergent_charging_controller:12.0.3.0.0-12.0.6.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Convergent Charging Controller Version 15.0.0.0.0-15.0.1.0.0",
                    "product": {
                      "name": "Oracle Communications Convergent Charging Controller Version 15.0.0.0.0-15.0.1.0.0",
                      "product_id": "P-12985V-15.0.0.0.0-15.0.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_convergent_charging_controller:15.0.0.0.0-15.0.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Convergent Charging Controller Version 15.1.0.0.0",
                    "product": {
                      "name": "Oracle Communications Convergent Charging Controller Version 15.1.0.0.0",
                      "product_id": "P-12985V-15.1.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_convergent_charging_controller:15.1.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Convergent Charging Controller"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Messaging Server Version 8.1.0.28",
                    "product": {
                      "name": "Oracle Communications Messaging Server Version 8.1.0.28",
                      "product_id": "P-8496V-8.1.0.28",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_messaging_server:8.1.0.28:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Messaging Server"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Network Charging and Control Version 12.0.1.0.0-12.0.6.0.0",
                    "product": {
                      "name": "Oracle Communications Network Charging and Control Version 12.0.1.0.0-12.0.6.0.0",
                      "product_id": "P-4623V-12.0.1.0.0-12.0.6.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_charging_and_control:12.0.1.0.0-12.0.6.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Network Charging and Control Version 12.0.3.0.0-12.0.6.0.0",
                    "product": {
                      "name": "Oracle Communications Network Charging and Control Version 12.0.3.0.0-12.0.6.0.0",
                      "product_id": "P-4623V-12.0.3.0.0-12.0.6.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_charging_and_control:12.0.3.0.0-12.0.6.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Charging and Control Version 12.0.6.0.0",
                    "product": {
                      "name": "Oracle Communications Network Charging and Control Version 12.0.6.0.0",
                      "product_id": "P-4623V-12.0.6.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_charging_and_control:12.0.6.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Network Charging and Control Version 15.0.0.0.0-15.0.1.0.0",
                    "product": {
                      "name": "Oracle Communications Network Charging and Control Version 15.0.0.0.0-15.0.1.0.0",
                      "product_id": "P-4623V-15.0.0.0.0-15.0.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_charging_and_control:15.0.0.0.0-15.0.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Charging and Control Version 15.1.0.0.0",
                    "product": {
                      "name": "Oracle Communications Network Charging and Control Version 15.1.0.0.0",
                      "product_id": "P-4623V-15.1.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_charging_and_control:15.1.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Network Charging and Control"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Integrity Version 7.3.6",
                    "product": {
                      "name": "Oracle Communications Network Integrity Version 7.3.6",
                      "product_id": "P-4491V-7.3.6",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_integrity:7.3.6:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Integrity Version 7.4.0",
                    "product": {
                      "name": "Oracle Communications Network Integrity Version 7.4.0",
                      "product_id": "P-4491V-7.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_integrity:7.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Integrity Version 7.5.0",
                    "product": {
                      "name": "Oracle Communications Network Integrity Version 7.5.0",
                      "product_id": "P-4491V-7.5.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_integrity:7.5.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Network Integrity"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Offline Mediation Controller Version 15.0.0.0.0",
                    "product": {
                      "name": "Oracle Communications Offline Mediation Controller Version 15.0.0.0.0",
                      "product_id": "P-2269V-15.0.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_offline_mediation_controller:15.0.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Offline Mediation Controller Version 15.0.0.0.0-15.0.1.0.0",
                    "product": {
                      "name": "Oracle Communications Offline Mediation Controller Version 15.0.0.0.0-15.0.1.0.0",
                      "product_id": "P-2269V-15.0.0.0.0-15.0.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_offline_mediation_controller:15.0.0.0.0-15.0.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Offline Mediation Controller Version 15.0.1.0.0",
                    "product": {
                      "name": "Oracle Communications Offline Mediation Controller Version 15.0.1.0.0",
                      "product_id": "P-2269V-15.0.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_offline_mediation_controller:15.0.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Offline Mediation Controller Version 15.1.0.0.0",
                    "product": {
                      "name": "Oracle Communications Offline Mediation Controller Version 15.1.0.0.0",
                      "product_id": "P-2269V-15.1.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_offline_mediation_controller:15.1.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Offline Mediation Controller"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Order and Service Management Version 7.4.0",
                    "product": {
                      "name": "Oracle Communications Order and Service Management Version 7.4.0",
                      "product_id": "P-2270V-7.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_order_and_service_management:7.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Order and Service Management Version 7.4.1",
                    "product": {
                      "name": "Oracle Communications Order and Service Management Version 7.4.1",
                      "product_id": "P-2270V-7.4.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_order_and_service_management:7.4.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Order and Service Management Version 7.5.0",
                    "product": {
                      "name": "Oracle Communications Order and Service Management Version 7.5.0",
                      "product_id": "P-2270V-7.5.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_order_and_service_management:7.5.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Order and Service Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Pricing Design Center Version 12.0.0.4.0-12.0.0.8.0",
                    "product": {
                      "name": "Oracle Communications Pricing Design Center Version 12.0.0.4.0-12.0.0.8.0",
                      "product_id": "P-9437V-12.0.0.4.0-12.0.0.8.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_pricing_design_center:12.0.0.4.0-12.0.0.8.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Pricing Design Center Version 15.0.0.0.0-15.0.1.0.0",
                    "product": {
                      "name": "Oracle Communications Pricing Design Center Version 15.0.0.0.0-15.0.1.0.0",
                      "product_id": "P-9437V-15.0.0.0.0-15.0.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_pricing_design_center:15.0.0.0.0-15.0.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Pricing Design Center"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Service Catalog and Design Version 8.0.0.5.0",
                    "product": {
                      "name": "Oracle Communications Service Catalog and Design Version 8.0.0.5.0",
                      "product_id": "P-2283V-8.0.0.5.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_service_catalog_and_design:8.0.0.5.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Service Catalog and Design Version 8.1.0.4.0",
                    "product": {
                      "name": "Oracle Communications Service Catalog and Design Version 8.1.0.4.0",
                      "product_id": "P-2283V-8.1.0.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_service_catalog_and_design:8.1.0.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Service Catalog and Design Version 8.2.0.1.0",
                    "product": {
                      "name": "Oracle Communications Service Catalog and Design Version 8.2.0.1.0",
                      "product_id": "P-2283V-8.2.0.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_service_catalog_and_design:8.2.0.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Service Catalog and Design"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Unified Assurance Version 6.1.0-6.1.1",
                    "product": {
                      "name": "Oracle Communications Unified Assurance Version 6.1.0-6.1.1",
                      "product_id": "P-14597V-6.1.0-6.1.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_unified_assurance:6.1.0-6.1.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Unified Assurance Version 6.1.1",
                    "product": {
                      "name": "Oracle Communications Unified Assurance Version 6.1.1",
                      "product_id": "P-14597V-6.1.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_unified_assurance:6.1.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Unified Assurance"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Unified Inventory Management Version 7.5.0-7.5.1",
                    "product": {
                      "name": "Oracle Communications Unified Inventory Management Version 7.5.0-7.5.1",
                      "product_id": "P-4516V-7.5.0-7.5.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_unified_inventory_management:7.5.0-7.5.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Unified Inventory Management Version 7.5.1",
                    "product": {
                      "name": "Oracle Communications Unified Inventory Management Version 7.5.1",
                      "product_id": "P-4516V-7.5.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_unified_inventory_management:7.5.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Unified Inventory Management Version 7.6.0-7.8.0",
                    "product": {
                      "name": "Oracle Communications Unified Inventory Management Version 7.6.0-7.8.0",
                      "product_id": "P-4516V-7.6.0-7.8.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_unified_inventory_management:7.6.0-7.8.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Unified Inventory Management Version 7.7.0",
                    "product": {
                      "name": "Oracle Communications Unified Inventory Management Version 7.7.0",
                      "product_id": "P-4516V-7.7.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_unified_inventory_management:7.7.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Unified Inventory Management Version 7.7.0-7.8.0",
                    "product": {
                      "name": "Oracle Communications Unified Inventory Management Version 7.7.0-7.8.0",
                      "product_id": "P-4516V-7.7.0-7.8.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_unified_inventory_management:7.7.0-7.8.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Unified Inventory Management Version 7.8.0",
                    "product": {
                      "name": "Oracle Communications Unified Inventory Management Version 7.8.0",
                      "product_id": "P-4516V-7.8.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_unified_inventory_management:7.8.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Unified Inventory Management"
              }
            ],
            "category": "product_family",
            "name": "Oracle Communications Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Primavera Gateway Version 20.12.0-20.12.17",
                    "product": {
                      "name": "Primavera Gateway Version 20.12.0-20.12.17",
                      "product_id": "P-10605V-20.12.0-20.12.17",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_gateway:20.12.0-20.12.17:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Primavera Gateway Version 21.12.0-21.12.15",
                    "product": {
                      "name": "Primavera Gateway Version 21.12.0-21.12.15",
                      "product_id": "P-10605V-21.12.0-21.12.15",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_gateway:21.12.0-21.12.15:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Primavera Gateway"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Primavera P6 Enterprise Project Portfolio Management Version 20.12.0.0-20.12.21.0",
                    "product": {
                      "name": "Primavera P6 Enterprise Project Portfolio Management Version 20.12.0.0-20.12.21.0",
                      "product_id": "P-5579V-20.12.0.0-20.12.21.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:20.12.0.0-20.12.21.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Primavera P6 Enterprise Project Portfolio Management Version 21.12.0.0-21.12.21.2",
                    "product": {
                      "name": "Primavera P6 Enterprise Project Portfolio Management Version 21.12.0.0-21.12.21.2",
                      "product_id": "P-5579V-21.12.0.0-21.12.21.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:21.12.0.0-21.12.21.2:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Primavera P6 Enterprise Project Portfolio Management Version 22.12.0.0-22.12.20.0",
                    "product": {
                      "name": "Primavera P6 Enterprise Project Portfolio Management Version 22.12.0.0-22.12.20.0",
                      "product_id": "P-5579V-22.12.0.0-22.12.20.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:22.12.0.0-22.12.20.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Primavera P6 Enterprise Project Portfolio Management Version 23.12.0.0-23.12.14.0",
                    "product": {
                      "name": "Primavera P6 Enterprise Project Portfolio Management Version 23.12.0.0-23.12.14.0",
                      "product_id": "P-5579V-23.12.0.0-23.12.14.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:23.12.0.0-23.12.14.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Primavera P6 Enterprise Project Portfolio Management Version 24.12.0.0-24.12.4.0",
                    "product": {
                      "name": "Primavera P6 Enterprise Project Portfolio Management Version 24.12.0.0-24.12.4.0",
                      "product_id": "P-5579V-24.12.0.0-24.12.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:24.12.0.0-24.12.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Primavera P6 Enterprise Project Portfolio Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Primavera Unifier Version 20.12.0-20.12.16",
                    "product": {
                      "name": "Primavera Unifier Version 20.12.0-20.12.16",
                      "product_id": "P-10354V-20.12.0-20.12.16",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_unifier:20.12.0-20.12.16:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Primavera Unifier Version 21.12.0-21.12.17",
                    "product": {
                      "name": "Primavera Unifier Version 21.12.0-21.12.17",
                      "product_id": "P-10354V-21.12.0-21.12.17",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_unifier:21.12.0-21.12.17:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Primavera Unifier Version 22.12.0-22.12.15",
                    "product": {
                      "name": "Primavera Unifier Version 22.12.0-22.12.15",
                      "product_id": "P-10354V-22.12.0-22.12.15",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_unifier:22.12.0-22.12.15:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Primavera Unifier Version 23.12.0-23.12.15",
                    "product": {
                      "name": "Primavera Unifier Version 23.12.0-23.12.15",
                      "product_id": "P-10354V-23.12.0-23.12.15",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_unifier:23.12.0-23.12.15:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Primavera Unifier Version 24.12.0-24.12.9",
                    "product": {
                      "name": "Primavera Unifier Version 24.12.0-24.12.9",
                      "product_id": "P-10354V-24.12.0-24.12.9",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_unifier:24.12.0-24.12.9:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Primavera Unifier"
              }
            ],
            "category": "product_family",
            "name": "Oracle Construction and Engineering"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Database) Version 19.3-19.28",
                    "product": {
                      "name": "Oracle Database Server(Database) Version 19.3-19.28",
                      "product_id": "P-5(Database)V-19.3-19.28",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_database:19.3-19.28:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Java VM) Version 19.3-19.28",
                    "product": {
                      "name": "Oracle Database Server(Java VM) Version 19.3-19.28",
                      "product_id": "P-5(Java VM)V-19.3-19.28",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_java_vm:19.3-19.28:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Portable Clusterware) Version 19.3-19.28",
                    "product": {
                      "name": "Oracle Database Server(Portable Clusterware) Version 19.3-19.28",
                      "product_id": "P-5(Portable Clusterware)V-19.3-19.28",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_portable_clusterware:19.3-19.28:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(RDBMS) Version 19.3-19.28",
                    "product": {
                      "name": "Oracle Database Server(RDBMS) Version 19.3-19.28",
                      "product_id": "P-5(RDBMS)V-19.3-19.28",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_rdbms:19.3-19.28:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Database) Version 21.3-21.19",
                    "product": {
                      "name": "Oracle Database Server(Database) Version 21.3-21.19",
                      "product_id": "P-5(Database)V-21.3-21.19",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_database:21.3-21.19:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(GraalVM Multilingual Engine) Version 21.3-21.19",
                    "product": {
                      "name": "Oracle Database Server(GraalVM Multilingual Engine) Version 21.3-21.19",
                      "product_id": "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_graalvm_multilingual_engine:21.3-21.19:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Java VM) Version 21.3-21.19",
                    "product": {
                      "name": "Oracle Database Server(Java VM) Version 21.3-21.19",
                      "product_id": "P-5(Java VM)V-21.3-21.19",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_java_vm:21.3-21.19:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Portable Clusterware) Version 21.3-21.19",
                    "product": {
                      "name": "Oracle Database Server(Portable Clusterware) Version 21.3-21.19",
                      "product_id": "P-5(Portable Clusterware)V-21.3-21.19",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_portable_clusterware:21.3-21.19:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(RDBMS) Version 21.3-21.19",
                    "product": {
                      "name": "Oracle Database Server(RDBMS) Version 21.3-21.19",
                      "product_id": "P-5(RDBMS)V-21.3-21.19",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_rdbms:21.3-21.19:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Database) Version 23.4-23.9",
                    "product": {
                      "name": "Oracle Database Server(Database) Version 23.4-23.9",
                      "product_id": "P-5(Database)V-23.4-23.9",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_database:23.4-23.9:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(GraalVM Multilingual Engine) Version 23.4-23.9",
                    "product": {
                      "name": "Oracle Database Server(GraalVM Multilingual Engine) Version 23.4-23.9",
                      "product_id": "P-5(GraalVM Multilingual Engine)V-23.4-23.9",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_graalvm_multilingual_engine:23.4-23.9:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Java VM) Version 23.4-23.9",
                    "product": {
                      "name": "Oracle Database Server(Java VM) Version 23.4-23.9",
                      "product_id": "P-5(Java VM)V-23.4-23.9",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_java_vm:23.4-23.9:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Portable Clusterware) Version 23.4-23.9",
                    "product": {
                      "name": "Oracle Database Server(Portable Clusterware) Version 23.4-23.9",
                      "product_id": "P-5(Portable Clusterware)V-23.4-23.9",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_portable_clusterware:23.4-23.9:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(RDBMS Functional Index) Version 23.4-23.9",
                    "product": {
                      "name": "Oracle Database Server(RDBMS Functional Index) Version 23.4-23.9",
                      "product_id": "P-5(RDBMS Functional Index)V-23.4-23.9",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_rdbms_functional_index:23.4-23.9:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(RDBMS) Version 23.4-23.9",
                    "product": {
                      "name": "Oracle Database Server(RDBMS) Version 23.4-23.9",
                      "product_id": "P-5(RDBMS)V-23.4-23.9",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_rdbms:23.4-23.9:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(SQLcl) Version 23.4-23.9",
                    "product": {
                      "name": "Oracle Database Server(SQLcl) Version 23.4-23.9",
                      "product_id": "P-5(SQLcl)V-23.4-23.9",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_sqlcl:23.4-23.9:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Unified Audit) Version 23.4-23.9",
                    "product": {
                      "name": "Oracle Database Server(Unified Audit) Version 23.4-23.9",
                      "product_id": "P-5(Unified Audit)V-23.4-23.9",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_unified_audit:23.4-23.9:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Database Server"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "SQLcl Version 23.4-23.9",
                    "product": {
                      "name": "SQLcl Version 23.4-23.9",
                      "product_id": "P-13824V-23.4-23.9",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:sqlcl:23.4-23.9:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "SQLcl"
              }
            ],
            "category": "product_family",
            "name": "Oracle Database Server"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Applications Framework Version 12.2.3-12.2.14",
                    "product": {
                      "name": "Oracle Applications Framework Version 12.2.3-12.2.14",
                      "product_id": "P-208V-12.2.3-12.2.14",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:applications_framework:12.2.3-12.2.14:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Applications Framework Version 12.2.3-12.2.14",
                    "product": {
                      "name": "Oracle Applications Framework Version 12.2.3-12.2.14",
                      "product_id": "P-1472V-12.2.3-12.2.14",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:applications_framework:12.2.3-12.2.14:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Applications Framework"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Applications Manager Version 12.2.3-12.2.14",
                    "product": {
                      "name": "Oracle Applications Manager Version 12.2.3-12.2.14",
                      "product_id": "P-99V-12.2.3-12.2.14",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:applications_manager:12.2.3-12.2.14:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Applications Manager"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Marketing Version 12.2.3-12.2.14",
                    "product": {
                      "name": "Oracle Marketing Version 12.2.3-12.2.14",
                      "product_id": "P-229V-12.2.3-12.2.14",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:marketing:12.2.3-12.2.14:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Marketing"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Product Hub Version 12.2.3-12.2.14",
                    "product": {
                      "name": "Oracle Product Hub Version 12.2.3-12.2.14",
                      "product_id": "P-1313V-12.2.3-12.2.14",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:product_hub:12.2.3-12.2.14:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Product Hub"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Scripting Version 12.2.3-12.2.14",
                    "product": {
                      "name": "Oracle Scripting Version 12.2.3-12.2.14",
                      "product_id": "P-433V-12.2.3-12.2.14",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:scripting:12.2.3-12.2.14:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Scripting"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Workflow Version 12.2.3-12.2.14",
                    "product": {
                      "name": "Oracle Workflow Version 12.2.3-12.2.14",
                      "product_id": "P-174V-12.2.3-12.2.14",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:workflow:12.2.3-12.2.14:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Workflow"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle iStore Version 12.2.5-12.2.14",
                    "product": {
                      "name": "Oracle iStore Version 12.2.5-12.2.14",
                      "product_id": "P-384V-12.2.5-12.2.14",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:istore:12.2.5-12.2.14:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle iStore"
              }
            ],
            "category": "product_family",
            "name": "Oracle E-Business Suite"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Enterprise Manager Base Platform Version 13.5",
                    "product": {
                      "name": "Enterprise Manager Base Platform Version 13.5",
                      "product_id": "P-1370V-13.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Enterprise Manager Base Platform Version 24.1",
                    "product": {
                      "name": "Enterprise Manager Base Platform Version 24.1",
                      "product_id": "P-1370V-24.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Enterprise Manager Base Platform"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Application Testing Suite Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Application Testing Suite Version 12.2.1.4.0",
                      "product_id": "P-4622V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:application_testing_suite:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Application Testing Suite Version 14.1.1.0.0",
                    "product": {
                      "name": "Oracle Application Testing Suite Version 14.1.1.0.0",
                      "product_id": "P-4622V-14.1.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:application_testing_suite:14.1.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Application Testing Suite Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle Application Testing Suite Version 14.1.2.0.0",
                      "product_id": "P-4622V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:application_testing_suite:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Application Testing Suite"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Enterprise Manager for Fusion Middleware(Infrastructure Management) Version 13.5",
                    "product": {
                      "name": "Oracle Enterprise Manager for Fusion Middleware(Infrastructure Management) Version 13.5",
                      "product_id": "P-1369(Infrastructure Management)V-13.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:enterprise_manager_for_fusion_middleware:13.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Enterprise Manager for Fusion Middleware(Infrastructure Management) Version 24.1",
                    "product": {
                      "name": "Oracle Enterprise Manager for Fusion Middleware(Infrastructure Management) Version 24.1",
                      "product_id": "P-1369(Infrastructure Management)V-24.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:enterprise_manager_for_fusion_middleware:24.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Enterprise Manager for Fusion Middleware"
              }
            ],
            "category": "product_family",
            "name": "Oracle Enterprise Manager"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Essbase Version 21.7.3.0.0",
                    "product": {
                      "name": "Oracle Essbase Version 21.7.3.0.0",
                      "product_id": "P-4379V-21.7.3.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:essbase:21.7.3.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Essbase"
              }
            ],
            "category": "product_family",
            "name": "Oracle Essbase"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Banking Branch Version 14.5.0.0.0-14.8.0.0.0",
                    "product": {
                      "name": "Oracle Banking Branch Version 14.5.0.0.0-14.8.0.0.0",
                      "product_id": "P-14324V-14.5.0.0.0-14.8.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:banking_branch:14.5.0.0.0-14.8.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Banking Branch"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Banking Corporate Lending Process Management Version 14.4.0.0.0-14.7.0.0.0",
                    "product": {
                      "name": "Oracle Banking Corporate Lending Process Management Version 14.4.0.0.0-14.7.0.0.0",
                      "product_id": "P-13701V-14.4.0.0.0-14.7.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.4.0.0.0-14.7.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Banking Corporate Lending Process Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Banking Origination Version 14.5.0.0.0-14.7.0.0.0",
                    "product": {
                      "name": "Oracle Banking Origination Version 14.5.0.0.0-14.7.0.0.0",
                      "product_id": "P-14325V-14.5.0.0.0-14.7.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:banking_origination:14.5.0.0.0-14.7.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Banking Origination"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.0.7.9",
                    "product": {
                      "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.0.7.9",
                      "product_id": "P-5680V-8.0.7.9",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.7.9:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.0.8.7",
                    "product": {
                      "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.0.8.7",
                      "product_id": "P-5680V-8.0.8.7",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.8.7:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.1.2.5",
                    "product": {
                      "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.1.2.5",
                      "product_id": "P-5680V-8.1.2.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.2.5:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Financial Services Analytical Applications Infrastructure"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Behavior Detection Platform Version 8.0.8.1",
                    "product": {
                      "name": "Oracle Financial Services Behavior Detection Platform Version 8.0.8.1",
                      "product_id": "P-9190V-8.0.8.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.0.8.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Behavior Detection Platform Version 8.1.2.10",
                    "product": {
                      "name": "Oracle Financial Services Behavior Detection Platform Version 8.1.2.10",
                      "product_id": "P-9190V-8.1.2.10",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.2.10:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Behavior Detection Platform Version 8.1.2.9",
                    "product": {
                      "name": "Oracle Financial Services Behavior Detection Platform Version 8.1.2.9",
                      "product_id": "P-9190V-8.1.2.9",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.2.9:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Financial Services Behavior Detection Platform"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Compliance Studio Version 8.1.2.8",
                    "product": {
                      "name": "Oracle Financial Services Compliance Studio Version 8.1.2.8",
                      "product_id": "P-14392V-8.1.2.8",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:financial_services_compliance_studio:8.1.2.8:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Financial Services Compliance Studio"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Model Management and Governance Version 8.1.2.7",
                    "product": {
                      "name": "Oracle Financial Services Model Management and Governance Version 8.1.2.7",
                      "product_id": "P-14276V-8.1.2.7",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:financial_services_model_management_and_governance:8.1.2.7:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Model Management and Governance Version 8.1.3.2",
                    "product": {
                      "name": "Oracle Financial Services Model Management and Governance Version 8.1.3.2",
                      "product_id": "P-14276V-8.1.3.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:financial_services_model_management_and_governance:8.1.3.2:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Financial Services Model Management and Governance"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Financial Services Revenue Management and Billing Version 2.9.0.0.0-7.2.0.0.0",
                    "product": {
                      "name": "Oracle Financial Services Revenue Management and Billing Version 2.9.0.0.0-7.2.0.0.0",
                      "product_id": "P-5322V-2.9.0.0.0-7.2.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:financial_services_revenue_management_and_billing:2.9.0.0.0-7.2.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Financial Services Revenue Management and Billing"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition Version 8.0.8",
                    "product": {
                      "name": "Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition Version 8.0.8",
                      "product_id": "P-13789V-8.0.8",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:financial_services_trade-based_anti_money_laundering:8.0.8:*:*:*:enterprise:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition"
              }
            ],
            "category": "product_family",
            "name": "Oracle Financial Services Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Identity Manager Version 12.2.1.4.0",
                    "product": {
                      "name": "Identity Manager Version 12.2.1.4.0",
                      "product_id": "P-1980V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Identity Manager Version 14.1.2.1.0",
                    "product": {
                      "name": "Identity Manager Version 14.1.2.1.0",
                      "product_id": "P-1980V-14.1.2.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Identity Manager"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Coherence Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Coherence Version 12.2.1.4.0",
                      "product_id": "P-2545V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Coherence Version 14.1.1.0.0",
                    "product": {
                      "name": "Oracle Coherence Version 14.1.1.0.0",
                      "product_id": "P-2545V-14.1.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Coherence Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle Coherence Version 14.1.2.0.0",
                      "product_id": "P-2545V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Coherence"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Enterprise Data Quality Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Enterprise Data Quality Version 12.2.1.4.0",
                      "product_id": "P-9464V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:enterprise_data_quality:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Enterprise Data Quality Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle Enterprise Data Quality Version 14.1.2.0.0",
                      "product_id": "P-9464V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:enterprise_data_quality:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Enterprise Data Quality"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Fusion Middleware MapViewer Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Fusion Middleware MapViewer Version 12.2.1.4.0",
                      "product_id": "P-1215V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:fusion_middleware_mapviewer:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Fusion Middleware MapViewer"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Global Lifecycle Management NextGen OUI Framework Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Global Lifecycle Management NextGen OUI Framework Version 12.2.1.4.0",
                      "product_id": "P-12738V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:global_lifecycle_management_nextgen_oui_framework:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Global Lifecycle Management NextGen OUI Framework Version 14.1.1.0.0",
                    "product": {
                      "name": "Oracle Global Lifecycle Management NextGen OUI Framework Version 14.1.1.0.0",
                      "product_id": "P-12738V-14.1.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:global_lifecycle_management_nextgen_oui_framework:14.1.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Global Lifecycle Management NextGen OUI Framework Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle Global Lifecycle Management NextGen OUI Framework Version 14.1.2.0.0",
                      "product_id": "P-12738V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:global_lifecycle_management_nextgen_oui_framework:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Global Lifecycle Management NextGen OUI Framework"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle JDeveloper Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle JDeveloper Version 12.2.1.4.0",
                      "product_id": "P-807V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:jdeveloper:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle JDeveloper"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Middleware Common Libraries and Tools Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Middleware Common Libraries and Tools Version 12.2.1.4.0",
                      "product_id": "P-4647V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:middleware_common_libraries_and_tools:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Middleware Common Libraries and Tools Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle Middleware Common Libraries and Tools Version 14.1.2.0.0",
                      "product_id": "P-4647V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:middleware_common_libraries_and_tools:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Middleware Common Libraries and Tools"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Outside In Technology Version 8.5.7",
                    "product": {
                      "name": "Oracle Outside In Technology Version 8.5.7",
                      "product_id": "P-2276V-8.5.7",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:outside_in_technology:8.5.7:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Outside In Technology Version 8.5.8",
                    "product": {
                      "name": "Oracle Outside In Technology Version 8.5.8",
                      "product_id": "P-2276V-8.5.8",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:outside_in_technology:8.5.8:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Outside In Technology"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle SOA Suite Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle SOA Suite Version 14.1.2.0.0",
                      "product_id": "P-1162V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:soa_suite:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle SOA Suite"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Security Service Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Security Service Version 12.2.1.4.0",
                      "product_id": "P-991V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:security_service:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Security Service"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle WebCenter Forms Recognition Version 14.1.1.0.0",
                    "product": {
                      "name": "Oracle WebCenter Forms Recognition Version 14.1.1.0.0",
                      "product_id": "P-5746V-14.1.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:webcenter_forms_recognition:14.1.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle WebCenter Forms Recognition"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle WebCenter Portal Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle WebCenter Portal Version 12.2.1.4.0",
                      "product_id": "P-1696V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle WebCenter Portal"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle WebCenter Sites Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle WebCenter Sites Version 14.1.2.0.0",
                      "product_id": "P-9617V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:webcenter_sites:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle WebCenter Sites"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle WebLogic Server Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle WebLogic Server Version 12.2.1.4.0",
                      "product_id": "P-5242V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle WebLogic Server Version 14.1.1.0.0",
                    "product": {
                      "name": "Oracle WebLogic Server Version 14.1.1.0.0",
                      "product_id": "P-5242V-14.1.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle WebLogic Server Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle WebLogic Server Version 14.1.2.0.0",
                      "product_id": "P-5242V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle WebLogic Server"
              }
            ],
            "category": "product_family",
            "name": "Oracle Fusion Middleware"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "GoldenGate Stream Analytics Version 19.1.0.0.0-19.1.0.0.9",
                    "product": {
                      "name": "GoldenGate Stream Analytics Version 19.1.0.0.0-19.1.0.0.9",
                      "product_id": "P-14015V-19.1.0.0.0-19.1.0.0.9",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:goldengate_stream_analytics:19.1.0.0.0-19.1.0.0.9:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "GoldenGate Stream Analytics"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Management Pack for Oracle GoldenGate Version 12.2.1.2.0",
                    "product": {
                      "name": "Management Pack for Oracle GoldenGate Version 12.2.1.2.0",
                      "product_id": "P-5759V-12.2.1.2.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:management_pack_for_oracle_goldengate:12.2.1.2.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Management Pack for Oracle GoldenGate"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle GoldenGate Version 19.1.0.0.0-19.28.0.0.250715",
                    "product": {
                      "name": "Oracle GoldenGate Version 19.1.0.0.0-19.28.0.0.250715",
                      "product_id": "P-5757V-19.1.0.0.0-19.28.0.0.250715",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:goldengate:19.1.0.0.0-19.28.0.0.250715:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle GoldenGate Version 21.3-21.19",
                    "product": {
                      "name": "Oracle GoldenGate Version 21.3-21.19",
                      "product_id": "P-5757V-21.3-21.19",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:goldengate:21.3-21.19:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle GoldenGate Version 23.4-23.9",
                    "product": {
                      "name": "Oracle GoldenGate Version 23.4-23.9",
                      "product_id": "P-5757V-23.4-23.9",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:goldengate:23.4-23.9:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle GoldenGate"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle GoldenGate Big Data and Application Adapters Version 21.3-21.19",
                    "product": {
                      "name": "Oracle GoldenGate Big Data and Application Adapters Version 21.3-21.19",
                      "product_id": "P-5760V-21.3-21.19",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:goldengate_big_data_and_application_adapters:21.3-21.19:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle GoldenGate Big Data and Application Adapters Version 23.4-23.9",
                    "product": {
                      "name": "Oracle GoldenGate Big Data and Application Adapters Version 23.4-23.9",
                      "product_id": "P-5760V-23.4-23.9",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:goldengate_big_data_and_application_adapters:23.4-23.9:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle GoldenGate Big Data and Application Adapters"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle GoldenGate Stream Analytics Version 19.1.0.0.0-19.1.0.0.11",
                    "product": {
                      "name": "Oracle GoldenGate Stream Analytics Version 19.1.0.0.0-19.1.0.0.11",
                      "product_id": "P-14015V-19.1.0.0.0-19.1.0.0.11",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:goldengate_stream_analytics:19.1.0.0.0-19.1.0.0.11:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle GoldenGate Stream Analytics Version 19.1.0.0.0-19.1.0.0.12",
                    "product": {
                      "name": "Oracle GoldenGate Stream Analytics Version 19.1.0.0.0-19.1.0.0.12",
                      "product_id": "P-14015V-19.1.0.0.0-19.1.0.0.12",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:goldengate_stream_analytics:19.1.0.0.0-19.1.0.0.12:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle GoldenGate Stream Analytics"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle GoldenGate Studio Version 12.2.0.4.0",
                    "product": {
                      "name": "Oracle GoldenGate Studio Version 12.2.0.4.0",
                      "product_id": "P-10945V-12.2.0.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:goldengate_studio:12.2.0.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle GoldenGate Studio"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle GoldenGate Veridata Version 12.2.1.4.0-12.2.1.4.250515",
                    "product": {
                      "name": "Oracle GoldenGate Veridata Version 12.2.1.4.0-12.2.1.4.250515",
                      "product_id": "P-5758V-12.2.1.4.0-12.2.1.4.250515",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:goldengate_veridata:12.2.1.4.0-12.2.1.4.250515:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle GoldenGate Veridata Version 23.1.0.0.0-23.4.0.0.0",
                    "product": {
                      "name": "Oracle GoldenGate Veridata Version 23.1.0.0.0-23.4.0.0.0",
                      "product_id": "P-5758V-23.1.0.0.0-23.4.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:goldengate_veridata:23.1.0.0.0-23.4.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle GoldenGate Veridata"
              }
            ],
            "category": "product_family",
            "name": "Oracle GoldenGate"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Graph Server and Client Version 24.4.1",
                    "product": {
                      "name": "Graph Server and Client Version 24.4.1",
                      "product_id": "P-14069V-24.4.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:graph_server_and_client:24.4.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Graph Server and Client Version 24.4.3",
                    "product": {
                      "name": "Graph Server and Client Version 24.4.3",
                      "product_id": "P-14069V-24.4.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:graph_server_and_client:24.4.3:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Graph Server and Client Version 25.1.0",
                    "product": {
                      "name": "Graph Server and Client Version 25.1.0",
                      "product_id": "P-14069V-25.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:graph_server_and_client:25.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Graph Server and Client Version 25.3.0",
                    "product": {
                      "name": "Graph Server and Client Version 25.3.0",
                      "product_id": "P-14069V-25.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:graph_server_and_client:25.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Graph Server and Client"
              }
            ],
            "category": "product_family",
            "name": "Oracle Graph Server and Client"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Health Sciences Data Management Workbench Version 3.4.0.1.3",
                    "product": {
                      "name": "Oracle Health Sciences Data Management Workbench Version 3.4.0.1.3",
                      "product_id": "P-9581V-3.4.0.1.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:health_sciences_data_management_workbench:3.4.0.1.3:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Health Sciences Data Management Workbench Version 3.4.1.0.10",
                    "product": {
                      "name": "Oracle Health Sciences Data Management Workbench Version 3.4.1.0.10",
                      "product_id": "P-9581V-3.4.1.0.10",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:health_sciences_data_management_workbench:3.4.1.0.10:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Health Sciences Data Management Workbench"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Life Sciences InForm Version 7.0.1.0",
                    "product": {
                      "name": "Oracle Life Sciences InForm Version 7.0.1.0",
                      "product_id": "P-9636V-7.0.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:life_sciences_inform:7.0.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Life Sciences InForm"
              }
            ],
            "category": "product_family",
            "name": "Oracle Health Sciences Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Healthcare Data Repository Version 8.2.0.5",
                    "product": {
                      "name": "Oracle Healthcare Data Repository Version 8.2.0.5",
                      "product_id": "P-9161V-8.2.0.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:healthcare_data_repository:8.2.0.5:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Healthcare Data Repository"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Healthcare Master Person Index Version 5.0.0.0-5.0.9.2",
                    "product": {
                      "name": "Oracle Healthcare Master Person Index Version 5.0.0.0-5.0.9.2",
                      "product_id": "P-8575V-5.0.0.0-5.0.9.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:healthcare_master_person_index:5.0.0.0-5.0.9.2:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Healthcare Master Person Index"
              }
            ],
            "category": "product_family",
            "name": "Oracle HealthCare Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Hospitality Cruise Shipboard Property Management (SPMS) Version 23.2.5",
                    "product": {
                      "name": "Oracle Hospitality Cruise Shipboard Property Management (SPMS) Version 23.2.5",
                      "product_id": "P-11607V-23.2.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:hospitality_cruise_shipboard_property_management:23.2.5:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Hospitality Cruise Shipboard Property Management (SPMS)"
              }
            ],
            "category": "product_family",
            "name": "Oracle Hospitality Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Hyperion Calculation Manager Version 11.2.22.0.000",
                    "product": {
                      "name": "Oracle Hyperion Calculation Manager Version 11.2.22.0.000",
                      "product_id": "P-5685V-11.2.22.0.000",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:hyperion_calculation_manager:11.2.22.0.000:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Hyperion Calculation Manager"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Hyperion Data Relationship Management Version 11.2.22.0.000",
                    "product": {
                      "name": "Oracle Hyperion Data Relationship Management Version 11.2.22.0.000",
                      "product_id": "P-4375V-11.2.22.0.000",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:hyperion_data_relationship_management:11.2.22.0.000:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Hyperion Data Relationship Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Hyperion Financial Management Version 11.2.22.0.000",
                    "product": {
                      "name": "Oracle Hyperion Financial Management Version 11.2.22.0.000",
                      "product_id": "P-4390V-11.2.22.0.000",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:hyperion_financial_management:11.2.22.0.000:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Hyperion Financial Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Hyperion Infrastructure Technology Version 11.2.22.0.000",
                    "product": {
                      "name": "Oracle Hyperion Infrastructure Technology Version 11.2.22.0.000",
                      "product_id": "P-4392V-11.2.22.0.000",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.22.0.000:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Hyperion Infrastructure Technology"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Hyperion Planning Version 11.2.22.0.000",
                    "product": {
                      "name": "Oracle Hyperion Planning Version 11.2.22.0.000",
                      "product_id": "P-4402V-11.2.22.0.000",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:hyperion_planning:11.2.22.0.000:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Hyperion Planning"
              }
            ],
            "category": "product_family",
            "name": "Oracle Hyperion"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Documaker Version 12.7.2.4",
                    "product": {
                      "name": "Oracle Documaker Version 12.7.2.4",
                      "product_id": "P-5477V-12.7.2.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:documaker:12.7.2.4:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Documaker Version 13.0.0.3",
                    "product": {
                      "name": "Oracle Documaker Version 13.0.0.3",
                      "product_id": "P-5477V-13.0.0.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:documaker:13.0.0.3:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Documaker Version 13.0.1.1",
                    "product": {
                      "name": "Oracle Documaker Version 13.0.1.1",
                      "product_id": "P-5477V-13.0.1.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:documaker:13.0.1.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Documaker"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Insurance Policy Administration J2EE Version 11.3.1-12.0.5",
                    "product": {
                      "name": "Oracle Insurance Policy Administration J2EE Version 11.3.1-12.0.5",
                      "product_id": "P-5279V-11.3.1-12.0.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:insurance_policy_administration_j2ee:11.3.1-12.0.5:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Insurance Policy Administration J2EE"
              }
            ],
            "category": "product_family",
            "name": "Oracle Insurance Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "JD Edwards EnterpriseOne Orchestrator Version 9.2.0.0-9.2.9.4",
                    "product": {
                      "name": "JD Edwards EnterpriseOne Orchestrator Version 9.2.0.0-9.2.9.4",
                      "product_id": "P-11681V-9.2.0.0-9.2.9.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:jd_edwards_enterpriseone_orchestrator:9.2.0.0-9.2.9.4:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "JD Edwards EnterpriseOne Orchestrator"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "JD Edwards EnterpriseOne Tools Version 9.2.0.0-9.2.9.4",
                    "product": {
                      "name": "JD Edwards EnterpriseOne Tools Version 9.2.0.0-9.2.9.4",
                      "product_id": "P-4781V-9.2.0.0-9.2.9.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2.0.0-9.2.9.4:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "JD Edwards EnterpriseOne Tools"
              }
            ],
            "category": "product_family",
            "name": "Oracle JD Edwards"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle GraalVM Enterprise Edition Version 21.3.15",
                    "product": {
                      "name": "Oracle GraalVM Enterprise Edition Version 21.3.15",
                      "product_id": "P-13497V-21.3.15",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:graalvm:21.3.15:*:*:*:enterprise:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle GraalVM Enterprise Edition"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle GraalVM for JDK Version 17.0.16",
                    "product": {
                      "name": "Oracle GraalVM for JDK Version 17.0.16",
                      "product_id": "P-13497V-17.0.16",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:graalvm_for_jdk:17.0.16:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle GraalVM for JDK Version 21.0.8",
                    "product": {
                      "name": "Oracle GraalVM for JDK Version 21.0.8",
                      "product_id": "P-13497V-21.0.8",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:graalvm_for_jdk:21.0.8:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle GraalVM for JDK"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Java SE Version 11.0.28",
                    "product": {
                      "name": "Oracle Java SE Version 11.0.28",
                      "product_id": "P-856V-11.0.28",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:java_se:11.0.28:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Java SE Version 17.0.16",
                    "product": {
                      "name": "Oracle Java SE Version 17.0.16",
                      "product_id": "P-856V-17.0.16",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:java_se:17.0.16:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Java SE Version 21.0.8",
                    "product": {
                      "name": "Oracle Java SE Version 21.0.8",
                      "product_id": "P-856V-21.0.8",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:java_se:21.0.8:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Java SE Version 25",
                    "product": {
                      "name": "Oracle Java SE Version 25",
                      "product_id": "P-856V-25",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:java_se:25:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Java SE Version 8u461",
                    "product": {
                      "name": "Oracle Java SE Version 8u461",
                      "product_id": "P-856V-8u461",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:java_se:8u461:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Java SE Version 8u461-b50",
                    "product": {
                      "name": "Oracle Java SE Version 8u461-b50",
                      "product_id": "P-856V-8u461-b50",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:java_se:8u461-b50:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Java SE Version 8u461-perf",
                    "product": {
                      "name": "Oracle Java SE Version 8u461-perf",
                      "product_id": "P-856V-8u461-perf",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:java_se:8u461:*:*:*:enterprise_performance:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Java SE"
              }
            ],
            "category": "product_family",
            "name": "Oracle Java SE"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "MySQL Cluster Version 8.0.0-8.0.40",
                    "product": {
                      "name": "MySQL Cluster Version 8.0.0-8.0.40",
                      "product_id": "P-8479V-8.0.0-8.0.40",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.0.0-8.0.40:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Cluster Version 8.0.0-8.0.43",
                    "product": {
                      "name": "MySQL Cluster Version 8.0.0-8.0.43",
                      "product_id": "P-8479V-8.0.0-8.0.43",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.0.0-8.0.43:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Cluster Version 8.4.0-8.4.3",
                    "product": {
                      "name": "MySQL Cluster Version 8.4.0-8.4.3",
                      "product_id": "P-8479V-8.4.0-8.4.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.4.0-8.4.3:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Cluster Version 8.4.0-8.4.6",
                    "product": {
                      "name": "MySQL Cluster Version 8.4.0-8.4.6",
                      "product_id": "P-8479V-8.4.0-8.4.6",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.4.0-8.4.6:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Cluster Version 9.0.0-9.1.0",
                    "product": {
                      "name": "MySQL Cluster Version 9.0.0-9.1.0",
                      "product_id": "P-8479V-9.0.0-9.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_cluster:9.0.0-9.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Cluster Version 9.0.0-9.4.0",
                    "product": {
                      "name": "MySQL Cluster Version 9.0.0-9.4.0",
                      "product_id": "P-8479V-9.0.0-9.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_cluster:9.0.0-9.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "MySQL Cluster"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "MySQL Enterprise Backup Version 8.0.0-8.0.42",
                    "product": {
                      "name": "MySQL Enterprise Backup Version 8.0.0-8.0.42",
                      "product_id": "P-4629V-8.0.0-8.0.42",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_enterprise_backup:8.0.0-8.0.42:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Enterprise Backup Version 8.4.0-8.4.5",
                    "product": {
                      "name": "MySQL Enterprise Backup Version 8.4.0-8.4.5",
                      "product_id": "P-4629V-8.4.0-8.4.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_enterprise_backup:8.4.0-8.4.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Enterprise Backup Version 9.0.0-9.3.0",
                    "product": {
                      "name": "MySQL Enterprise Backup Version 9.0.0-9.3.0",
                      "product_id": "P-4629V-9.0.0-9.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_enterprise_backup:9.0.0-9.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "MySQL Enterprise Backup"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(InnoDB) Version 8.0.0-8.0.43",
                    "product": {
                      "name": "MySQL Server(InnoDB) Version 8.0.0-8.0.43",
                      "product_id": "P-8478(InnoDB)V-8.0.0-8.0.43",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.0.0-8.0.43:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Components Services) Version 8.0.0-8.0.43",
                    "product": {
                      "name": "MySQL Server(Server: Components Services) Version 8.0.0-8.0.43",
                      "product_id": "P-8478(Server: Components Services)V-8.0.0-8.0.43",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.0.0-8.0.43:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: DML) Version 8.0.0-8.0.43",
                    "product": {
                      "name": "MySQL Server(Server: DML) Version 8.0.0-8.0.43",
                      "product_id": "P-8478(Server: DML)V-8.0.0-8.0.43",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.0.0-8.0.43:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Optimizer) Version 8.0.0-8.0.43",
                    "product": {
                      "name": "MySQL Server(Server: Optimizer) Version 8.0.0-8.0.43",
                      "product_id": "P-8478(Server: Optimizer)V-8.0.0-8.0.43",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.0.0-8.0.43:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(InnoDB) Version 8.4.0-8.4.6",
                    "product": {
                      "name": "MySQL Server(InnoDB) Version 8.4.0-8.4.6",
                      "product_id": "P-8478(InnoDB)V-8.4.0-8.4.6",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.6:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Components Services) Version 8.4.0-8.4.6",
                    "product": {
                      "name": "MySQL Server(Server: Components Services) Version 8.4.0-8.4.6",
                      "product_id": "P-8478(Server: Components Services)V-8.4.0-8.4.6",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.6:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: DML) Version 8.4.0-8.4.6",
                    "product": {
                      "name": "MySQL Server(Server: DML) Version 8.4.0-8.4.6",
                      "product_id": "P-8478(Server: DML)V-8.4.0-8.4.6",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.6:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Optimizer) Version 8.4.0-8.4.6",
                    "product": {
                      "name": "MySQL Server(Server: Optimizer) Version 8.4.0-8.4.6",
                      "product_id": "P-8478(Server: Optimizer)V-8.4.0-8.4.6",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.6:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(InnoDB) Version 9.0.0-9.4.0",
                    "product": {
                      "name": "MySQL Server(InnoDB) Version 9.0.0-9.4.0",
                      "product_id": "P-8478(InnoDB)V-9.0.0-9.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:9.0.0-9.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Components Services) Version 9.0.0-9.4.0",
                    "product": {
                      "name": "MySQL Server(Server: Components Services) Version 9.0.0-9.4.0",
                      "product_id": "P-8478(Server: Components Services)V-9.0.0-9.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:9.0.0-9.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: DML) Version 9.0.0-9.4.0",
                    "product": {
                      "name": "MySQL Server(Server: DML) Version 9.0.0-9.4.0",
                      "product_id": "P-8478(Server: DML)V-9.0.0-9.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:9.0.0-9.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Optimizer) Version 9.0.0-9.4.0",
                    "product": {
                      "name": "MySQL Server(Server: Optimizer) Version 9.0.0-9.4.0",
                      "product_id": "P-8478(Server: Optimizer)V-9.0.0-9.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:9.0.0-9.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "MySQL Server"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "MySQL Shell(Shell: Core Client) Version 8.0.40-8.0.43",
                    "product": {
                      "name": "MySQL Shell(Shell: Core Client) Version 8.0.40-8.0.43",
                      "product_id": "P-8478(Shell: Core Client)V-8.0.40-8.0.43",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_shell:8.0.40-8.0.43:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Shell(Shell: Core Client) Version 8.4.3-8.4.6",
                    "product": {
                      "name": "MySQL Shell(Shell: Core Client) Version 8.4.3-8.4.6",
                      "product_id": "P-8478(Shell: Core Client)V-8.4.3-8.4.6",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_shell:8.4.3-8.4.6:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Shell(Shell: Core Client) Version 9.1.0-9.4.0",
                    "product": {
                      "name": "MySQL Shell(Shell: Core Client) Version 9.1.0-9.4.0",
                      "product_id": "P-8478(Shell: Core Client)V-9.1.0-9.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_shell:9.1.0-9.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "MySQL Shell"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "MySQL Workbench Version 8.0.0-8.0.43",
                    "product": {
                      "name": "MySQL Workbench Version 8.0.0-8.0.43",
                      "product_id": "P-4627V-8.0.0-8.0.43",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_workbench:8.0.0-8.0.43:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "MySQL Workbench"
              }
            ],
            "category": "product_family",
            "name": "Oracle MySQL"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "PeopleSoft Enterprise CS Financial Aid Version 9.2",
                    "product": {
                      "name": "PeopleSoft Enterprise CS Financial Aid Version 9.2",
                      "product_id": "P-5178V-9.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_cs_financial_aid:9.2:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "PeopleSoft Enterprise CS Financial Aid"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "PeopleSoft Enterprise FIN IT Asset Management Version 9.2",
                    "product": {
                      "name": "PeopleSoft Enterprise FIN IT Asset Management Version 9.2",
                      "product_id": "P-5000V-9.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_fin_it_asset_management:9.2:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "PeopleSoft Enterprise FIN IT Asset Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "PeopleSoft Enterprise FIN Maintenance Management Version 9.2",
                    "product": {
                      "name": "PeopleSoft Enterprise FIN Maintenance Management Version 9.2",
                      "product_id": "P-5001V-9.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_fin_maintenance_management:9.2:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "PeopleSoft Enterprise FIN Maintenance Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "PeopleSoft Enterprise FIN Payables Version 9.2",
                    "product": {
                      "name": "PeopleSoft Enterprise FIN Payables Version 9.2",
                      "product_id": "P-5008V-9.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_fin_payables:9.2:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "PeopleSoft Enterprise FIN Payables"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "PeopleSoft Enterprise PeopleTools Version 8.60",
                    "product": {
                      "name": "PeopleSoft Enterprise PeopleTools Version 8.60",
                      "product_id": "P-5085V-8.60",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.60:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "PeopleSoft Enterprise PeopleTools Version 8.61",
                    "product": {
                      "name": "PeopleSoft Enterprise PeopleTools Version 8.61",
                      "product_id": "P-5085V-8.61",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.61:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "PeopleSoft Enterprise PeopleTools Version 8.62",
                    "product": {
                      "name": "PeopleSoft Enterprise PeopleTools Version 8.62",
                      "product_id": "P-5085V-8.62",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.62:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "PeopleSoft Enterprise PeopleTools"
              }
            ],
            "category": "product_family",
            "name": "Oracle PeopleSoft"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle REST Data Services Version 25.2.1",
                    "product": {
                      "name": "Oracle REST Data Services Version 25.2.1",
                      "product_id": "P-9456V-25.2.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:rest_data_services:25.2.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle REST Data Services"
              }
            ],
            "category": "product_family",
            "name": "Oracle REST Data Services"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Advanced Inventory Planning Version 15.0.3",
                    "product": {
                      "name": "Oracle Retail Advanced Inventory Planning Version 15.0.3",
                      "product_id": "P-1785V-15.0.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_advanced_inventory_planning:15.0.3:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Advanced Inventory Planning Version 16.0.3",
                    "product": {
                      "name": "Oracle Retail Advanced Inventory Planning Version 16.0.3",
                      "product_id": "P-1785V-16.0.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_advanced_inventory_planning:16.0.3:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Advanced Inventory Planning"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Financial Integration Version 14.1.3.2",
                    "product": {
                      "name": "Oracle Retail Financial Integration Version 14.1.3.2",
                      "product_id": "P-10722V-14.1.3.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_financial_integration:14.1.3.2:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Financial Integration Version 15.0.3.1",
                    "product": {
                      "name": "Oracle Retail Financial Integration Version 15.0.3.1",
                      "product_id": "P-10722V-15.0.3.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_financial_integration:15.0.3.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Financial Integration Version 16.0.3",
                    "product": {
                      "name": "Oracle Retail Financial Integration Version 16.0.3",
                      "product_id": "P-10722V-16.0.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_financial_integration:16.0.3:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Financial Integration Version 19.0.1",
                    "product": {
                      "name": "Oracle Retail Financial Integration Version 19.0.1",
                      "product_id": "P-10722V-19.0.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_financial_integration:19.0.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Financial Integration"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Integration Bus Version 14.1.3.2",
                    "product": {
                      "name": "Oracle Retail Integration Bus Version 14.1.3.2",
                      "product_id": "P-1807V-14.1.3.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_integration_bus:14.1.3.2:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Integration Bus Version 15.0.3.1",
                    "product": {
                      "name": "Oracle Retail Integration Bus Version 15.0.3.1",
                      "product_id": "P-1807V-15.0.3.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_integration_bus:15.0.3.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Integration Bus Version 16.0.3",
                    "product": {
                      "name": "Oracle Retail Integration Bus Version 16.0.3",
                      "product_id": "P-1807V-16.0.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_integration_bus:16.0.3:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Integration Bus Version 19.0.1",
                    "product": {
                      "name": "Oracle Retail Integration Bus Version 19.0.1",
                      "product_id": "P-1807V-19.0.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_integration_bus:19.0.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Integration Bus"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Invoice Matching Version 15.0.3.1",
                    "product": {
                      "name": "Oracle Retail Invoice Matching Version 15.0.3.1",
                      "product_id": "P-1810V-15.0.3.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_invoice_matching:15.0.3.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Invoice Matching Version 16.0.3",
                    "product": {
                      "name": "Oracle Retail Invoice Matching Version 16.0.3",
                      "product_id": "P-1810V-16.0.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_invoice_matching:16.0.3:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Invoice Matching"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Merchandising System Version 16.0.3",
                    "product": {
                      "name": "Oracle Retail Merchandising System Version 16.0.3",
                      "product_id": "P-1816V-16.0.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_merchandising_system:16.0.3:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Merchandising System Version 19.0.1",
                    "product": {
                      "name": "Oracle Retail Merchandising System Version 19.0.1",
                      "product_id": "P-1816V-19.0.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_merchandising_system:19.0.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Merchandising System"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Price Management Version 15.0.3.1",
                    "product": {
                      "name": "Oracle Retail Price Management Version 15.0.3.1",
                      "product_id": "P-1824V-15.0.3.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_price_management:15.0.3.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Price Management Version 16.0.3",
                    "product": {
                      "name": "Oracle Retail Price Management Version 16.0.3",
                      "product_id": "P-1824V-16.0.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_price_management:16.0.3:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Price Management Version 19.0.1",
                    "product": {
                      "name": "Oracle Retail Price Management Version 19.0.1",
                      "product_id": "P-1824V-19.0.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_price_management:19.0.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Price Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Sales Audit Version 15.0.3.1",
                    "product": {
                      "name": "Oracle Retail Sales Audit Version 15.0.3.1",
                      "product_id": "P-1834V-15.0.3.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_sales_audit:15.0.3.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Sales Audit Version 16.0.3",
                    "product": {
                      "name": "Oracle Retail Sales Audit Version 16.0.3",
                      "product_id": "P-1834V-16.0.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_sales_audit:16.0.3:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Sales Audit Version 19.0.1",
                    "product": {
                      "name": "Oracle Retail Sales Audit Version 19.0.1",
                      "product_id": "P-1834V-19.0.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_sales_audit:19.0.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Sales Audit"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Service Backbone Version 14.1.3.2",
                    "product": {
                      "name": "Oracle Retail Service Backbone Version 14.1.3.2",
                      "product_id": "P-10867V-14.1.3.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_service_backbone:14.1.3.2:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Service Backbone Version 15.0.3.1",
                    "product": {
                      "name": "Oracle Retail Service Backbone Version 15.0.3.1",
                      "product_id": "P-10867V-15.0.3.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_service_backbone:15.0.3.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Service Backbone Version 16.0.3",
                    "product": {
                      "name": "Oracle Retail Service Backbone Version 16.0.3",
                      "product_id": "P-10867V-16.0.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_service_backbone:16.0.3:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Service Backbone Version 19.0.1",
                    "product": {
                      "name": "Oracle Retail Service Backbone Version 19.0.1",
                      "product_id": "P-10867V-19.0.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_service_backbone:19.0.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Service Backbone"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Office Version 20.0.5",
                    "product": {
                      "name": "Oracle Retail Xstore Office Version 20.0.5",
                      "product_id": "P-11560V-20.0.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_office:20.0.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Office Version 21.0.4",
                    "product": {
                      "name": "Oracle Retail Xstore Office Version 21.0.4",
                      "product_id": "P-11560V-21.0.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_office:21.0.4:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Office Version 22.0.2",
                    "product": {
                      "name": "Oracle Retail Xstore Office Version 22.0.2",
                      "product_id": "P-11560V-22.0.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_office:22.0.2:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Office Version 23.0.2",
                    "product": {
                      "name": "Oracle Retail Xstore Office Version 23.0.2",
                      "product_id": "P-11560V-23.0.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_office:23.0.2:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Office Version 24.0.1",
                    "product": {
                      "name": "Oracle Retail Xstore Office Version 24.0.1",
                      "product_id": "P-11560V-24.0.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_office:24.0.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Office Version 25.0.0",
                    "product": {
                      "name": "Oracle Retail Xstore Office Version 25.0.0",
                      "product_id": "P-11560V-25.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_office:25.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Xstore Office"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Point of Service Version 20.0.5",
                    "product": {
                      "name": "Oracle Retail Xstore Point of Service Version 20.0.5",
                      "product_id": "P-11513V-20.0.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_point_of_service:20.0.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Point of Service Version 21.0.4",
                    "product": {
                      "name": "Oracle Retail Xstore Point of Service Version 21.0.4",
                      "product_id": "P-11513V-21.0.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_point_of_service:21.0.4:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Point of Service Version 22.0.2",
                    "product": {
                      "name": "Oracle Retail Xstore Point of Service Version 22.0.2",
                      "product_id": "P-11513V-22.0.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_point_of_service:22.0.2:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Point of Service Version 23.0.2",
                    "product": {
                      "name": "Oracle Retail Xstore Point of Service Version 23.0.2",
                      "product_id": "P-11513V-23.0.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_point_of_service:23.0.2:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Point of Service Version 24.0.1",
                    "product": {
                      "name": "Oracle Retail Xstore Point of Service Version 24.0.1",
                      "product_id": "P-11513V-24.0.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_point_of_service:24.0.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Point of Service Version 25.0.0",
                    "product": {
                      "name": "Oracle Retail Xstore Point of Service Version 25.0.0",
                      "product_id": "P-11513V-25.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_point_of_service:25.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Xstore Point of Service"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Retail Predictive Application Server Version 15.0.3",
                    "product": {
                      "name": "Retail Predictive Application Server Version 15.0.3",
                      "product_id": "P-1823V-15.0.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_predictive_application_server:15.0.3:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Retail Predictive Application Server Version 16.0.3",
                    "product": {
                      "name": "Retail Predictive Application Server Version 16.0.3",
                      "product_id": "P-1823V-16.0.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_predictive_application_server:16.0.3:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Retail Predictive Application Server"
              }
            ],
            "category": "product_family",
            "name": "Oracle Retail Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Secure Backup Version 19.1.0.1.0",
                    "product": {
                      "name": "Oracle Secure Backup Version 19.1.0.1.0",
                      "product_id": "P-1522V-19.1.0.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:secure_backup:19.1.0.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Secure Backup"
              }
            ],
            "category": "product_family",
            "name": "Oracle Secure Backup"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Siebel Apps - Marketing(Marketing) Version Prior to 25.7",
                    "product": {
                      "name": "Siebel Apps - Marketing(Marketing) Version Prior to 25.7",
                      "product_id": "P-8974(Marketing)V-Prior to 25.7",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:siebel_apps_-_marketing:prior_to_25.7:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Siebel Apps - Marketing(Web Marketing) Version Prior to 25.7",
                    "product": {
                      "name": "Siebel Apps - Marketing(Web Marketing) Version Prior to 25.7",
                      "product_id": "P-8974(Web Marketing)V-Prior to 25.7",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:siebel_apps_-_marketing:prior_to_25.7:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Siebel Apps - Marketing"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Siebel CRM Deployment Version Prior to 25.7",
                    "product": {
                      "name": "Siebel CRM Deployment Version Prior to 25.7",
                      "product_id": "P-9019V-Prior to 25.7",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:siebel_crm_deployment:prior_to_25.7:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Siebel CRM Deployment Version Prior to 25.8",
                    "product": {
                      "name": "Siebel CRM Deployment Version Prior to 25.8",
                      "product_id": "P-9019V-Prior to 25.8",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:siebel_crm_deployment:prior_to_25.8:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Siebel CRM Deployment"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Siebel CRM Development Version Prior to 25.7",
                    "product": {
                      "name": "Siebel CRM Development Version Prior to 25.7",
                      "product_id": "P-9001V-Prior to 25.7",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:siebel_crm_development:prior_to_25.7:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Siebel CRM Development"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Siebel CRM End User Version Prior to 25.10",
                    "product": {
                      "name": "Siebel CRM End User Version Prior to 25.10",
                      "product_id": "P-9011V-Prior to 25.10",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:siebel_crm_end_user:prior_to_25.10:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Siebel CRM End User Version Prior to 25.7",
                    "product": {
                      "name": "Siebel CRM End User Version Prior to 25.7",
                      "product_id": "P-9011V-Prior to 25.7",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:siebel_crm_end_user:prior_to_25.7:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Siebel CRM End User"
              }
            ],
            "category": "product_family",
            "name": "Oracle Siebel CRM"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Spatial Studio Version 24.2.0",
                    "product": {
                      "name": "Oracle Spatial Studio Version 24.2.0",
                      "product_id": "P-13600V-24.2.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:spatial_studio:24.2.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Spatial Studio Version 25.1.2",
                    "product": {
                      "name": "Oracle Spatial Studio Version 25.1.2",
                      "product_id": "P-13600V-25.1.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:spatial_studio:25.1.2:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Spatial Studio"
              }
            ],
            "category": "product_family",
            "name": "Oracle Spatial Studio"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Transportation Management Version 6.5.3",
                    "product": {
                      "name": "Oracle Transportation Management Version 6.5.3",
                      "product_id": "P-1991V-6.5.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:transportation_management:6.5.3:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Transportation Management"
              }
            ],
            "category": "product_family",
            "name": "Oracle Supply Chain"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Solaris Version 11",
                    "product": {
                      "name": "Oracle Solaris Version 11",
                      "product_id": "P-10006V-11",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:solaris:11:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Solaris"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Solaris Cluster Version 4",
                    "product": {
                      "name": "Oracle Solaris Cluster Version 4",
                      "product_id": "P-10005V-4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:solaris_cluster:4:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Solaris Cluster"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle ZFS Storage Appliance Kit Version 8.8",
                    "product": {
                      "name": "Oracle ZFS Storage Appliance Kit Version 8.8",
                      "product_id": "P-10026V-8.8",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle ZFS Storage Appliance Kit"
              }
            ],
            "category": "product_family",
            "name": "Oracle Systems"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle TimesTen In-Memory Database Version 18.1.4.1.0-18.1.4.48.0",
                    "product": {
                      "name": "Oracle TimesTen In-Memory Database Version 18.1.4.1.0-18.1.4.48.0",
                      "product_id": "P-1870V-18.1.4.1.0-18.1.4.48.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:timesten_in-memory_database:18.1.4.1.0-18.1.4.48.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle TimesTen In-Memory Database Version 18.1.4.1.0-18.1.4.53.0",
                    "product": {
                      "name": "Oracle TimesTen In-Memory Database Version 18.1.4.1.0-18.1.4.53.0",
                      "product_id": "P-1870V-18.1.4.1.0-18.1.4.53.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:timesten_in-memory_database:18.1.4.1.0-18.1.4.53.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle TimesTen In-Memory Database Version 18.1.4.39.0-18.1.4.53.0",
                    "product": {
                      "name": "Oracle TimesTen In-Memory Database Version 18.1.4.39.0-18.1.4.53.0",
                      "product_id": "P-1870V-18.1.4.39.0-18.1.4.53.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:timesten_in-memory_database:18.1.4.39.0-18.1.4.53.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle TimesTen In-Memory Database Version 22.1.1.1.0-22.1.1.30.0",
                    "product": {
                      "name": "Oracle TimesTen In-Memory Database Version 22.1.1.1.0-22.1.1.30.0",
                      "product_id": "P-1870V-22.1.1.1.0-22.1.1.30.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:timesten_in-memory_database:22.1.1.1.0-22.1.1.30.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle TimesTen In-Memory Database Version 22.1.1.1.0-22.1.1.35.0",
                    "product": {
                      "name": "Oracle TimesTen In-Memory Database Version 22.1.1.1.0-22.1.1.35.0",
                      "product_id": "P-1870V-22.1.1.1.0-22.1.1.35.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:timesten_in-memory_database:22.1.1.1.0-22.1.1.35.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle TimesTen In-Memory Database Version 22.1.1.19.0-22.1.1.33.0",
                    "product": {
                      "name": "Oracle TimesTen In-Memory Database Version 22.1.1.19.0-22.1.1.33.0",
                      "product_id": "P-1870V-22.1.1.19.0-22.1.1.33.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:timesten_in-memory_database:22.1.1.19.0-22.1.1.33.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle TimesTen In-Memory Database"
              }
            ],
            "category": "product_family",
            "name": "Oracle TimesTen In-Memory Database"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 24.2.0.0.0",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 24.2.0.0.0",
                      "product_id": "P-2245V-24.2.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:24.2.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 24.3.0.0.0",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 24.3.0.0.0",
                      "product_id": "P-2245V-24.3.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:24.3.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 25.10",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 25.10",
                      "product_id": "P-2245V-25.10",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:25.10:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 25.4",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 25.4",
                      "product_id": "P-2245V-25.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:25.4:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 4.3.0.5.0",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 4.3.0.5.0",
                      "product_id": "P-2245V-4.3.0.5.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.3.0.5.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 4.3.0.6.0",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 4.3.0.6.0",
                      "product_id": "P-2245V-4.3.0.6.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.3.0.6.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 4.4.0.0.0",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 4.4.0.0.0",
                      "product_id": "P-2245V-4.4.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.4.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 4.4.0.2.0",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 4.4.0.2.0",
                      "product_id": "P-2245V-4.4.0.2.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.4.0.2.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 4.4.0.3.0",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 4.4.0.3.0",
                      "product_id": "P-2245V-4.4.0.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.4.0.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 4.4.0.4.0",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 4.4.0.4.0",
                      "product_id": "P-2245V-4.4.0.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.4.0.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 4.5.0.0.0",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 4.5.0.0.0",
                      "product_id": "P-2245V-4.5.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.5.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 4.5.0.1.1",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 4.5.0.1.1",
                      "product_id": "P-2245V-4.5.0.1.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.5.0.1.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 4.5.0.1.3",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 4.5.0.1.3",
                      "product_id": "P-2245V-4.5.0.1.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.5.0.1.3:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 4.5.0.2.0",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 4.5.0.2.0",
                      "product_id": "P-2245V-4.5.0.2.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.5.0.2.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Utilities Application Framework"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Network Management System Version 2.4.0.1.31",
                    "product": {
                      "name": "Oracle Utilities Network Management System Version 2.4.0.1.31",
                      "product_id": "P-2241V-2.4.0.1.31",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:2.4.0.1.31:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Network Management System Version 2.5.0.1.15",
                    "product": {
                      "name": "Oracle Utilities Network Management System Version 2.5.0.1.15",
                      "product_id": "P-2241V-2.5.0.1.15",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:2.5.0.1.15:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Network Management System Version 2.5.0.2.9",
                    "product": {
                      "name": "Oracle Utilities Network Management System Version 2.5.0.2.9",
                      "product_id": "P-2241V-2.5.0.2.9",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:2.5.0.2.9:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Network Management System Version 2.6.0.1.8",
                    "product": {
                      "name": "Oracle Utilities Network Management System Version 2.6.0.1.8",
                      "product_id": "P-2241V-2.6.0.1.8",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:2.6.0.1.8:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Network Management System Version 2.6.0.2.3",
                    "product": {
                      "name": "Oracle Utilities Network Management System Version 2.6.0.2.3",
                      "product_id": "P-2241V-2.6.0.2.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:2.6.0.2.3:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Utilities Network Management System"
              }
            ],
            "category": "product_family",
            "name": "Oracle Utilities Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle VM VirtualBox Version 7.1.12",
                    "product": {
                      "name": "Oracle VM VirtualBox Version 7.1.12",
                      "product_id": "P-8370V-7.1.12",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:vm_virtualbox:7.1.12:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle VM VirtualBox Version 7.2.2",
                    "product": {
                      "name": "Oracle VM VirtualBox Version 7.2.2",
                      "product_id": "P-8370V-7.2.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:vm_virtualbox:7.2.2:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle VM VirtualBox"
              }
            ],
            "category": "product_family",
            "name": "Oracle Virtualization"
          }
        ],
        "category": "vendor",
        "name": "Oracle"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2020-11988",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
          "text": "37645544"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform (Apache XmlGraphics Commons)).  Supported versions that are affected are 8.0.7.9, 8.0.8.7 and  8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Analytical Applications Infrastructure accessible data as well as  unauthorized update, insert or delete access to some of Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5680V-8.1.2.5",
          "P-5680V-8.0.7.9",
          "P-5680V-8.0.8.7"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.7.9",
            "P-5680V-8.0.8.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104221.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.7.9",
            "P-5680V-8.0.8.7"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-13956",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Essbase",
          "text": "38258822"
        },
        {
          "system_name": "Oracle Bug ID of Siebel CRM Development",
          "text": "32899635"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Siebel Approval Manager (Apache HttpClient)).  Supported versions that are affected are Prior to 25.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Development.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel CRM Development accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in Oracle Essbase (component: Security and Provisioning (Apache HttpClient)).   The supported version that is affected is 21.7.3.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Essbase.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Essbase accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9001V-Prior to 25.7",
          "P-4379V-21.7.3.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9001V-Prior to 25.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106900.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4379V-21.7.3.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9001V-Prior to 25.7"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4379V-21.7.3.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-15250",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle WebLogic Server",
          "text": "38261161"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (GlassFish Server)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle WebLogic Server executes to compromise Oracle WebLogic Server.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5242V-12.2.1.4.0",
          "P-5242V-14.1.2.0.0",
          "P-5242V-14.1.1.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5242V-14.1.1.0.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105435.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5242V-14.1.1.0.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-17521",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Solaris Cluster",
          "text": "32398339"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Solaris Cluster product of Oracle Systems (component: Core (Apache Groovy)).   The supported version that is affected is 4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris Cluster executes to compromise Oracle Solaris Cluster.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Solaris Cluster accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10005V-4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10005V-4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106603.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-10005V-4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-22897",
      "ids": [
        {
          "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
          "text": "34018910"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure SEC (curl)).  Supported versions that are affected are 9.2.0.0-9.2.9.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4781V-9.2.0.0-9.2.9.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4781V-9.2.0.0-9.2.9.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106891.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4781V-9.2.0.0-9.2.9.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-28165",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Siebel CRM End User",
          "text": "32888158"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Desktop Integration Siebel Agent (Apache ZooKeeper)).  Supported versions that are affected are Prior to 25.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM End User.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM End User. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9011V-Prior to 25.7"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9011V-Prior to 25.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106900.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-9011V-Prior to 25.7"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-3711",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
          "text": "33309916"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Installation (OpenSSL)).   The supported version that is affected is 11.2.22.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4390V-11.2.22.0.000"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4390V-11.2.22.0.000"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2775466.2"
        }
      ]
    },
    {
      "cve": "CVE-2021-3712",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
          "text": "33309916"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Installation (OpenSSL)).   The supported version that is affected is 11.2.22.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.4 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4390V-11.2.22.0.000"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4390V-11.2.22.0.000"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2775466.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.4,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-4390V-11.2.22.0.000"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-0839",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-5759V-12.2.1.2.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Management Pack for Oracle GoldenGate",
          "text": "38073836"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Management Pack for Oracle GoldenGate product of Oracle GoldenGate (component: Monitor (jackson-databind)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-5759V-12.2.1.2.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5759V-12.2.1.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5759V-12.2.1.2.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-5759V-12.2.1.2.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-22968",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Siebel CRM Deployment",
          "text": "37275021"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Keyword Automation (Spring Framework)).  Supported versions that are affected are Prior to 25.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Deployment.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9019V-Prior to 25.8"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9019V-Prior to 25.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106900.1"
        }
      ]
    },
    {
      "cve": "CVE-2022-24329",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Documaker",
          "text": "36545391"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Documaker product of Oracle Insurance Applications (component: EWPS (JetBrains Kotlin)).  Supported versions that are affected are 12.7.2.4, 13.0.0.3 and  13.0.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Documaker.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Documaker accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5477V-13.0.0.3",
          "P-5477V-13.0.1.1",
          "P-5477V-12.7.2.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5477V-13.0.0.3",
            "P-5477V-13.0.1.1",
            "P-5477V-12.7.2.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3107101.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5477V-13.0.0.3",
            "P-5477V-13.0.1.1",
            "P-5477V-12.7.2.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-25647",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Siebel CRM Deployment",
          "text": "37275021"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Keyword Automation (Spring Framework)).  Supported versions that are affected are Prior to 25.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Deployment.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9019V-Prior to 25.8"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9019V-Prior to 25.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106900.1"
        }
      ]
    },
    {
      "cve": "CVE-2023-1370",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-9617V-14.1.2.0.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle WebCenter Sites",
          "text": "38105699"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites (json-smart)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-9617V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9617V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105435.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9617V-14.1.2.0.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-9617V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2023-26551",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Session Border Controller",
          "text": "35529042"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Session Border Controller product of Oracle Communications (component: Routing (NTP)).   The supported version that is affected is 9.0.0. Difficult to exploit vulnerability allows physical access to compromise Oracle Communications Session Border Controller.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Session Border Controller.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10750V-9.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10750V-9.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105851.1"
        }
      ]
    },
    {
      "cve": "CVE-2023-26552",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Session Border Controller",
          "text": "35529042"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Session Border Controller product of Oracle Communications (component: Routing (NTP)).   The supported version that is affected is 9.0.0. Difficult to exploit vulnerability allows physical access to compromise Oracle Communications Session Border Controller.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Session Border Controller.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10750V-9.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10750V-9.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105851.1"
        }
      ]
    },
    {
      "cve": "CVE-2023-26553",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Session Border Controller",
          "text": "35529042"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Session Border Controller product of Oracle Communications (component: Routing (NTP)).   The supported version that is affected is 9.0.0. Difficult to exploit vulnerability allows physical access to compromise Oracle Communications Session Border Controller.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Session Border Controller.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10750V-9.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10750V-9.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105851.1"
        }
      ]
    },
    {
      "cve": "CVE-2023-26554",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Session Border Controller",
          "text": "35529042"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Session Border Controller product of Oracle Communications (component: Routing (NTP)).   The supported version that is affected is 9.0.0. Difficult to exploit vulnerability allows physical access to compromise Oracle Communications Session Border Controller.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Session Border Controller.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10750V-9.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10750V-9.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105851.1"
        }
      ]
    },
    {
      "cve": "CVE-2023-26555",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Session Border Controller",
          "text": "35529042"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Session Border Controller product of Oracle Communications (component: Routing (NTP)).   The supported version that is affected is 9.0.0. Difficult to exploit vulnerability allows physical access to compromise Oracle Communications Session Border Controller.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Session Border Controller. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10750V-9.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10750V-9.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105851.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10750V-9.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2023-2976",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Documaker",
          "text": "36545315"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Documaker product of Oracle Insurance Applications (component: EWPS (Google Guava)).  Supported versions that are affected are 12.7.2.4, 13.0.0.3 and  13.0.1.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Documaker executes to compromise Oracle Documaker.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Documaker accessible data as well as  unauthorized access to critical data or complete access to all Oracle Documaker accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5477V-13.0.0.3",
          "P-5477V-13.0.1.1",
          "P-5477V-12.7.2.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5477V-13.0.0.3",
            "P-5477V-13.0.1.1",
            "P-5477V-12.7.2.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3107101.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5477V-13.0.0.3",
            "P-5477V-13.0.1.1",
            "P-5477V-12.7.2.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2023-33201",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.9"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of GoldenGate Stream Analytics",
          "text": "35761837"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security (Bouncy Castle Java Library)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-14015V-19.1.0.0.0-19.1.0.0.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14015V-19.1.0.0.0-19.1.0.0.9"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.9"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2023-34053",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Retail Merchandising System",
          "text": "36110751"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Merchandising System product of Oracle Retail Applications (component: Foundation (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Merchandising System.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Merchandising System. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1816V-19.0.1",
          "P-1816V-16.0.3"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1816V-16.0.3",
            "P-1816V-19.0.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104399.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-1816V-16.0.3",
            "P-1816V-19.0.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2023-34055",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-9617V-14.1.2.0.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle WebCenter Sites",
          "text": "38105930"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites (Spring Security)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-9617V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9617V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105435.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9617V-14.1.2.0.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-9617V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2023-44483",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Retail Advanced Inventory Planning",
          "text": "35977864"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Advanced Inventory Planning product of Oracle Retail Applications (component: Internal Operations (Apache Santuario XML Security For Java)).  Supported versions that are affected are 15.0.3 and  16.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Retail Advanced Inventory Planning.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Advanced Inventory Planning accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1785V-16.0.3",
          "P-1785V-15.0.3"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1785V-15.0.3",
            "P-1785V-16.0.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104399.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1785V-15.0.3",
            "P-1785V-16.0.3"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2023-45853",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Outside In Technology",
          "text": "38111853"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Search Export SDK (zlib)).  Supported versions that are affected are 8.5.7 and  8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology.  Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2276V-8.5.8",
          "P-2276V-8.5.7"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2276V-8.5.8",
            "P-2276V-8.5.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105435.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-2276V-8.5.8",
            "P-2276V-8.5.7"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2023-5072",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-5757V-23.4-23.9",
            "P-5757V-21.3-21.19",
            "P-5757V-19.1.0.0.0-19.28.0.0.250715"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate",
          "text": "38442664"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle GoldenGate (component: OGG Configuration Assistant (JSON-java)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-5757V-23.4-23.9",
          "P-5757V-21.3-21.19",
          "P-5757V-19.1.0.0.0-19.28.0.0.250715"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5757V-23.4-23.9",
            "P-5757V-21.3-21.19",
            "P-5757V-19.1.0.0.0-19.28.0.0.250715"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5757V-23.4-23.9",
            "P-5757V-21.3-21.19",
            "P-5757V-19.1.0.0.0-19.28.0.0.250715"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-5757V-23.4-23.9",
            "P-5757V-21.3-21.19",
            "P-5757V-19.1.0.0.0-19.28.0.0.250715"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2023-7256",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "37107952"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (libpcap)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.0-6.1.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        }
      ]
    },
    {
      "cve": "CVE-2024-12133",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Cluster",
          "text": "37847488"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications EAGLE LNP Application Processor",
          "text": "37847515"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications LSMS",
          "text": "37847516"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
          "text": "37847507"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Converged Charging System",
          "text": "37847508"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications EAGLE LNP Application Processor product of Oracle Communications (component: Patches (Libtasn1)).  Supported versions that are affected are 10.2.1.0 and  11.0.0.1-11.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE LNP Application Processor.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications EAGLE LNP Application Processor. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications LSMS product of Oracle Communications (component: Platform (Libtasn1)).  Supported versions that are affected are 13.5.1.0, 14.0.0.1 and  14.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications LSMS.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications LSMS. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General (Libtasn1)).  Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and  9.0.0-9.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Cluster. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Signaling (Libtasn1)).   The supported version that is affected is 25.1.100. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Converged Charging System product of Oracle Communications Applications (component: Installation (Libtasn1)).  Supported versions that are affected are 2.0.0.0.0-2.0.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Converged Charging System.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Converged Charging System. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8479V-8.4.0-8.4.6",
          "P-11114V-13.5.1.0",
          "P-11118V-11.0.0.1-11.0.0.2",
          "P-11114V-14.0.0.2",
          "P-8479V-8.0.0-8.0.43",
          "P-11114V-14.0.0.1",
          "P-8479V-9.0.0-9.4.0",
          "P-14119V-25.1.100",
          "P-14565V-2.0.0.0.0-2.0.0.1.0",
          "P-11118V-10.2.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11118V-11.0.0.1-11.0.0.2",
            "P-11118V-10.2.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105431.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11114V-13.5.1.0",
            "P-11114V-14.0.0.2",
            "P-11114V-14.0.0.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105432.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8479V-8.4.0-8.4.6",
            "P-8479V-8.0.0-8.0.43",
            "P-8479V-9.0.0-9.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14119V-25.1.100"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105405.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14565V-2.0.0.0.0-2.0.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105318.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-8479V-8.4.0-8.4.6",
            "P-11114V-13.5.1.0",
            "P-11118V-11.0.0.1-11.0.0.2",
            "P-11114V-14.0.0.2",
            "P-8479V-8.0.0-8.0.43",
            "P-11114V-14.0.0.1",
            "P-8479V-9.0.0-9.4.0",
            "P-14119V-25.1.100",
            "P-14565V-2.0.0.0.0-2.0.0.1.0",
            "P-11118V-10.2.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-12254",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38183449"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the RDBMS (Python) component of Oracle Database Server.  Supported versions that are affected are 21.3-21.19 and  23.4-23.9. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with logon to the infrastructure where RDBMS (Python) executes to compromise RDBMS (Python).  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of RDBMS (Python).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5(RDBMS)V-21.3-21.19",
          "P-5(RDBMS)V-23.4-23.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(RDBMS)V-21.3-21.19",
            "P-5(RDBMS)V-23.4-23.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ]
    },
    {
      "cve": "CVE-2024-12718",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core DBTier",
          "text": "38183439"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38183449"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
          "text": "38183437"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38183448"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "38183447"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Workbench",
          "text": "38183431"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
          "text": "38183441"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
          "text": "38183446"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
          "text": "38183444"
        },
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "38183466"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: ATS Framework (Python)).  Supported versions that are affected are 24.2.0, 24.2.1, 24.3.0, 25.1.100 and  25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Network Analytics Data Director accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Network Analytics Data Director accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Network Analytics Data Director.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: ATS Framework (Python)).   The supported version that is affected is 9.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Diameter Signaling Router accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Diameter Signaling Router accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Diameter Signaling Router.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Python)).  Supported versions that are affected are 24.2.7-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Policy.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Python)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (Python)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core DBTier accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core DBTier accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core DBTier.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Python)).  Supported versions that are affected are 24.2.7-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Binding Support Function accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Binding Support Function.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (Python)).  Supported versions that are affected are 8.0.0-8.0.43. Easily exploitable vulnerability allows unauthenticated attacker with network access via MySQL Workbench to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Workbench accessible data as well as  unauthorized access to critical data or complete access to all MySQL Workbench accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Workbench.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Python)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Porting (Python)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the RDBMS (Python) component of Oracle Database Server.  Supported versions that are affected are 21.3-21.19 and  23.4-23.9. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with logon to the infrastructure where RDBMS (Python) executes to compromise RDBMS (Python).  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of RDBMS (Python).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14547V-25.1.200",
          "P-14547V-25.1.100",
          "P-14277V-24.2.7-25.1.200",
          "P-5(RDBMS)V-21.3-21.19",
          "P-14547V-24.2.0",
          "P-14974V-25.1.200",
          "P-14597V-6.1.0-6.1.1",
          "P-14547V-24.2.1",
          "P-14547V-24.3.0",
          "P-5(RDBMS)V-23.4-23.9",
          "P-14130V-25.1.200",
          "P-4627V-8.0.0-8.0.43",
          "P-10899V-9.1.0.0.0",
          "P-14121V-24.2.7-25.1.200",
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-14547V-24.2.0",
            "P-14547V-24.2.1",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105450.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10899V-9.1.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105378.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-24.2.7-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105404.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14130V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105448.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14974V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105407.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14121V-24.2.7-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105418.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4627V-8.0.0-8.0.43"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106893.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(RDBMS)V-21.3-21.19",
            "P-5(RDBMS)V-23.4-23.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ]
    },
    {
      "cve": "CVE-2024-12797",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
          "text": "38167795"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (Cryptography)).  Supported versions that are affected are 7.6.0.0.0 and  8.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data as well as  unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2025V-7.6.0.0.0",
          "P-2025V-8.2.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2025V-7.6.0.0.0",
            "P-2025V-8.2.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105456.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "P-2025V-7.6.0.0.0",
            "P-2025V-8.2.0.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-12798",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Hospitality Cruise Shipboard Property Management (SPMS)",
          "text": "38228257"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management (SPMS) product of Oracle Hospitality Applications (component: Next-Gen SPMS (logback)).   The supported version that is affected is 23.2.5. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hospitality Cruise Shipboard Property Management (SPMS) executes to compromise Oracle Hospitality Cruise Shipboard Property Management (SPMS).  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hospitality Cruise Shipboard Property Management (SPMS) accessible data as well as  unauthorized read access to a subset of Oracle Hospitality Cruise Shipboard Property Management (SPMS) accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hospitality Cruise Shipboard Property Management (SPMS). CVSS 3.1 Base Score 6.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-11607V-23.2.5"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11607V-23.2.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106506.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:L",
            "version": "3.1"
          },
          "products": [
            "P-11607V-23.2.5"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-13009",
      "ids": [
        {
          "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Orchestrator",
          "text": "38178215"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security (Eclipse Jetty)).  Supported versions that are affected are 9.2.0.0-9.2.9.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Orchestrator.  While the vulnerability is in JD Edwards EnterpriseOne Orchestrator, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Orchestrator accessible data as well as  unauthorized read access to a subset of JD Edwards EnterpriseOne Orchestrator accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-11681V-9.2.0.0-9.2.9.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11681V-9.2.0.0-9.2.9.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106891.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-11681V-9.2.0.0-9.2.9.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-23807",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
          "text": "36754779"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security (Apache Xerces-C++)).   The supported version that is affected is 11.2.22.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management.  Note: Apply to Linux release only. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4390V-11.2.22.0.000"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4390V-11.2.22.0.000"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2775466.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-4390V-11.2.22.0.000"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-26462",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Converged Charging System",
          "text": "37034620"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Converged Charging System product of Oracle Communications Applications (component: Security (Kerberos)).  Supported versions that are affected are 2.0.0.0.0-2.0.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Converged Charging System.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Converged Charging System accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Converged Charging System.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14565V-2.0.0.0.0-2.0.0.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14565V-2.0.0.0.0-2.0.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105318.1"
        }
      ]
    },
    {
      "cve": "CVE-2024-28168",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
          "text": "37570655"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform (Apache FOP)).  Supported versions that are affected are 8.0.7.9, 8.0.8.7 and  8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5680V-8.1.2.5",
          "P-5680V-8.0.7.9",
          "P-5680V-8.0.8.7"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.7.9",
            "P-5680V-8.0.8.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104221.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.7.9",
            "P-5680V-8.0.8.7"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-28182",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Converged Charging System",
          "text": "36754860"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Converged Charging System product of Oracle Communications Applications (component: Installation (Nghttp2)).   The supported version that is affected is 2.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Converged Charging System.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Converged Charging System. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14565V-2.0.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14565V-2.0.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105318.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14565V-2.0.0.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-35164",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38152773"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Apache Guacamole)).  Supported versions that are affected are 6.1.0-6.1.1. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.0-6.1.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.6,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.1.0-6.1.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-35195",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Cluster",
          "text": "37182000"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General (Requests)).  Supported versions that are affected are 8.0.0-8.0.40, 8.4.0-8.4.3 and  9.0.0-9.1.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Cluster accessible data as well as  unauthorized access to critical data or complete access to all MySQL Cluster accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8479V-8.4.0-8.4.3",
          "P-8479V-8.0.0-8.0.40",
          "P-8479V-9.0.0-9.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8479V-8.4.0-8.4.3",
            "P-8479V-8.0.0-8.0.40",
            "P-8479V-9.0.0-9.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.6,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-8479V-8.4.0-8.4.3",
            "P-8479V-8.0.0-8.0.40",
            "P-8479V-9.0.0-9.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-37370",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Converged Charging System",
          "text": "37034620"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Converged Charging System product of Oracle Communications Applications (component: Security (Kerberos)).  Supported versions that are affected are 2.0.0.0.0-2.0.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Converged Charging System.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Converged Charging System accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Converged Charging System.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14565V-2.0.0.0.0-2.0.0.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14565V-2.0.0.0.0-2.0.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105318.1"
        }
      ]
    },
    {
      "cve": "CVE-2024-37371",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Converged Charging System",
          "text": "37034620"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Converged Charging System product of Oracle Communications Applications (component: Security (Kerberos)).  Supported versions that are affected are 2.0.0.0.0-2.0.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Converged Charging System.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Converged Charging System accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Converged Charging System. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14565V-2.0.0.0.0-2.0.0.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14565V-2.0.0.0.0-2.0.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105318.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14565V-2.0.0.0.0-2.0.0.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-38819",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-9617V-14.1.2.0.0",
            "P-10945V-12.2.0.4.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Enterprise Manager for Fusion Middleware",
          "text": "37260040"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Studio",
          "text": "37260076"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Solaris Cluster",
          "text": "37260119"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Healthcare Data Repository",
          "text": "37260081"
        },
        {
          "system_name": "Oracle Bug ID of Oracle WebCenter Sites",
          "text": "38105930"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Solaris Cluster product of Oracle Systems (component: Core (Spring Framework)).   The supported version that is affected is 4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Solaris Cluster.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Solaris Cluster accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Healthcare Data Repository product of Oracle HealthCare Applications (component: FHIR Server (Spring Framework)).   The supported version that is affected is 8.2.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Data Repository.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Healthcare Data Repository accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle GoldenGate Studio product of Oracle GoldenGate (component: GoldenGate Studio (Spring Framework)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: Infrastructure Management (Spring Framework)).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager for Fusion Middleware.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Enterprise Manager for Fusion Middleware accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites (Spring Security)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10005V-4",
          "P-1369(Infrastructure Management)V-24.1",
          "P-9161V-8.2.0.5",
          "P-1369(Infrastructure Management)V-13.5"
        ],
        "known_not_affected": [
          "P-10945V-12.2.0.4.0",
          "P-9617V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10005V-4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106603.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9161V-8.2.0.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106837.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10945V-12.2.0.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1369(Infrastructure Management)V-24.1",
            "P-1369(Infrastructure Management)V-13.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102566.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9617V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105435.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-10005V-4",
            "P-9161V-8.2.0.5",
            "P-1369(Infrastructure Management)V-24.1",
            "P-1369(Infrastructure Management)V-13.5"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9617V-14.1.2.0.0",
            "P-10945V-12.2.0.4.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-9617V-14.1.2.0.0",
            "P-10945V-12.2.0.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-38820",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-10945V-12.2.0.4.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Enterprise Manager for Fusion Middleware",
          "text": "37260040"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
          "text": "38490026"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Studio",
          "text": "37260076"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Solaris Cluster",
          "text": "37260119"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Healthcare Data Repository",
          "text": "37260081"
        },
        {
          "system_name": "Oracle Bug ID of Siebel CRM Deployment",
          "text": "37275021"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Solaris Cluster product of Oracle Systems (component: Core (Spring Framework)).   The supported version that is affected is 4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Solaris Cluster.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Solaris Cluster accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Healthcare Data Repository product of Oracle HealthCare Applications (component: FHIR Server (Spring Framework)).   The supported version that is affected is 8.2.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Data Repository.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Healthcare Data Repository accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle GoldenGate Studio product of Oracle GoldenGate (component: GoldenGate Studio (Spring Framework)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: Infrastructure Management (Spring Framework)).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager for Fusion Middleware.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Enterprise Manager for Fusion Middleware accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Keyword Automation (Spring Framework)).  Supported versions that are affected are Prior to 25.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Deployment.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Tools And Frameworks, Content Acquisition System, Platform Services (Spring Framework)).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Commerce Guided Search accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10005V-4",
          "P-9161V-8.2.0.5",
          "P-9633(Tools And Frameworks, Content Acquisition System, Platform Services)V-11.4.0",
          "P-1369(Infrastructure Management)V-24.1",
          "P-9019V-Prior to 25.8",
          "P-1369(Infrastructure Management)V-13.5"
        ],
        "known_not_affected": [
          "P-10945V-12.2.0.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10005V-4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106603.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9161V-8.2.0.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106837.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10945V-12.2.0.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1369(Infrastructure Management)V-24.1",
            "P-1369(Infrastructure Management)V-13.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102566.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9019V-Prior to 25.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106900.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9633(Tools And Frameworks, Content Acquisition System, Platform Services)V-11.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106894.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-10945V-12.2.0.4.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-10945V-12.2.0.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-38821",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-9617V-14.1.2.0.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle WebCenter Sites",
          "text": "38105930"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites (Spring Security)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-9617V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9617V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105435.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9617V-14.1.2.0.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-9617V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-38827",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-9617V-14.1.2.0.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle WebCenter Sites",
          "text": "38105930"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites (Spring Security)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-9617V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9617V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105435.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9617V-14.1.2.0.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-9617V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-38828",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-9617V-14.1.2.0.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle WebCenter Sites",
          "text": "38105930"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites (Spring Security)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-9617V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9617V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105435.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9617V-14.1.2.0.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-9617V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-4140",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Siebel CRM Deployment",
          "text": "37170995"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Keyword Automation (Email-MIME)).  Supported versions that are affected are Prior to 25.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9019V-Prior to 25.7"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9019V-Prior to 25.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106900.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-9019V-Prior to 25.7"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-41909",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
          "text": "38230151"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Mina SSHD)).   The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4647V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4647V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105435.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4647V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-47554",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Siebel Apps - Marketing",
          "text": "37477262"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Solaris Cluster",
          "text": "37477196"
        },
        {
          "system_name": "Oracle Bug ID of Siebel Apps - Marketing",
          "text": "37610168"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Merchandising System",
          "text": "37477171"
        },
        {
          "system_name": "Oracle Bug ID of Siebel CRM Deployment",
          "text": "37275021"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
          "text": "37476984"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications EAGLE Element Management System",
          "text": "37477014"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
          "text": "37760393"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Documaker",
          "text": "37477044"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Price Management",
          "text": "37477176"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Documaker product of Oracle Insurance Applications (component: EWPS (Apache Commons IO)).  Supported versions that are affected are 12.7.2.4, 13.0.0.3 and  13.0.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Documaker.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Documaker. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications EAGLE Element Management System product of Oracle Communications (component: Security (Apache Commons IO)).  Supported versions that are affected are 46.6 and  47.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Element Management System.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications EAGLE Element Management System. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (Apache Commons IO)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Keyword Automation (Spring Framework)).  Supported versions that are affected are Prior to 25.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Merchandising System product of Oracle Retail Applications (component: Foundation (Apache Commons IO)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Merchandising System.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Merchandising System. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (Apache Commons IO)).  Supported versions that are affected are 7.6.0.0.0, 8.2.0.0.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing (Apache Commons IO)).  Supported versions that are affected are Prior to 25.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel Apps - Marketing. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Web Marketing (Apache Commons IO)).  Supported versions that are affected are Prior to 25.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel Apps - Marketing. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Solaris Cluster product of Oracle Systems (component: Core (Apache Commons IO)).   The supported version that is affected is 4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Solaris Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Solaris Cluster. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Price Management product of Oracle Retail Applications (component: Security (Apache Commons IO)).  Supported versions that are affected are 15.0.3.1, 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Price Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Price Management. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5477V-13.0.0.3",
          "P-11125V-47.0",
          "P-10005V-4",
          "P-5477V-13.0.1.1",
          "P-2025V-12.2.1.4.0",
          "P-2025V-7.6.0.0.0",
          "P-2025V-8.2.0.0.0",
          "P-11125V-46.6",
          "P-1816V-16.0.3",
          "P-9019V-Prior to 25.8",
          "P-1824V-16.0.3",
          "P-1824V-15.0.3.1",
          "P-9633(Content Acquisition System)V-11.4.0",
          "P-8974(Marketing)V-Prior to 25.7",
          "P-8974(Web Marketing)V-Prior to 25.7",
          "P-5477V-12.7.2.4",
          "P-1824V-19.0.1",
          "P-1816V-19.0.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5477V-13.0.0.3",
            "P-5477V-13.0.1.1",
            "P-5477V-12.7.2.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3107101.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11125V-47.0",
            "P-11125V-46.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105423.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9633(Content Acquisition System)V-11.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106894.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8974(Marketing)V-Prior to 25.7",
            "P-8974(Web Marketing)V-Prior to 25.7",
            "P-9019V-Prior to 25.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106900.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1824V-15.0.3.1",
            "P-1816V-16.0.3",
            "P-1824V-19.0.1",
            "P-1816V-19.0.1",
            "P-1824V-16.0.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104399.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2025V-12.2.1.4.0",
            "P-2025V-7.6.0.0.0",
            "P-2025V-8.2.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105456.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10005V-4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106603.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-5477V-13.0.0.3",
            "P-11125V-47.0",
            "P-10005V-4",
            "P-5477V-13.0.1.1",
            "P-2025V-12.2.1.4.0",
            "P-2025V-7.6.0.0.0",
            "P-2025V-8.2.0.0.0",
            "P-11125V-46.6",
            "P-1816V-16.0.3",
            "P-9019V-Prior to 25.8",
            "P-1824V-16.0.3",
            "P-1824V-15.0.3.1",
            "P-9633(Content Acquisition System)V-11.4.0",
            "P-8974(Marketing)V-Prior to 25.7",
            "P-8974(Web Marketing)V-Prior to 25.7",
            "P-5477V-12.7.2.4",
            "P-1824V-19.0.1",
            "P-1816V-19.0.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-48014",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Security Service",
          "text": "38039542"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: C Oracle SSL API (Dell BSAFE Micro Edition Suite)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Security Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Security Service. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-991V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-991V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105435.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-991V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-50608",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38191267"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (fluentbit)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.0-6.1.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        }
      ]
    },
    {
      "cve": "CVE-2024-50609",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38191267"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (fluentbit)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 4.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.0-6.1.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.1.0-6.1.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-51504",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.12",
            "P-1870V-22.1.1.1.0-22.1.1.35.0",
            "P-1870V-18.1.4.1.0-18.1.4.53.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38237914"
        },
        {
          "system_name": "Oracle Bug ID of Oracle TimesTen In-Memory Database",
          "text": "38237933"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Stream Analytics",
          "text": "38237918"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Apache ZooKeeper)).   The supported version that is affected is 6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 6.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security (Apache ZooKeeper)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle TimesTen In-Memory Database (component: TimesTen Grid (Apache ZooKeeper)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.1"
        ],
        "known_not_affected": [
          "P-14015V-19.1.0.0.0-19.1.0.0.12",
          "P-1870V-22.1.1.1.0-22.1.1.35.0",
          "P-1870V-18.1.4.1.0-18.1.4.53.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.12",
            "P-1870V-22.1.1.1.0-22.1.1.35.0",
            "P-1870V-18.1.4.1.0-18.1.4.53.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.1.1"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14015V-19.1.0.0.0-19.1.0.0.12",
            "P-1870V-22.1.1.1.0-22.1.1.35.0",
            "P-1870V-18.1.4.1.0-18.1.4.53.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.12",
            "P-1870V-22.1.1.1.0-22.1.1.35.0",
            "P-1870V-18.1.4.1.0-18.1.4.53.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-52046",
      "ids": [
        {
          "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
          "text": "37444774"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infra SEC (Apache Mina)).  Supported versions that are affected are 9.2.0.0-9.2.9.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via SFTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4781V-9.2.0.0-9.2.9.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4781V-9.2.0.0-9.2.9.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106891.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-4781V-9.2.0.0-9.2.9.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-52533",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
          "text": "38315760"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Configuration (glibc)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Certificate Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Certificate Management.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14868V-25.1.200"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14868V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105451.1"
        }
      ]
    },
    {
      "cve": "CVE-2024-52577",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Stream Analytics",
          "text": "37680572"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle GoldenGate Stream Analytics product of Oracle GoldenGate (component: General (Apache Ignite)).  Supported versions that are affected are 19.1.0.0.0-19.1.0.0.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GoldenGate Stream Analytics.  Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate Stream Analytics. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14015V-19.1.0.0.0-19.1.0.0.11"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.11"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14015V-19.1.0.0.0-19.1.0.0.11"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-54160",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "38129033"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards (OpenSearch Dashboards)).   The supported version that is affected is 8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  While the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106893.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5085V-8.62"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-56406",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-1870V-22.1.1.19.0-22.1.1.33.0",
            "P-1870V-18.1.4.39.0-18.1.4.53.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle TimesTen In-Memory Database",
          "text": "37889120"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle TimesTen In-Memory Database (component: TimesTen Install (Perl)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-1870V-18.1.4.39.0-18.1.4.53.0",
          "P-1870V-22.1.1.19.0-22.1.1.33.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1870V-22.1.1.19.0-22.1.1.33.0",
            "P-1870V-18.1.4.39.0-18.1.4.53.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1870V-22.1.1.19.0-22.1.1.33.0",
            "P-1870V-18.1.4.39.0-18.1.4.53.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-1870V-22.1.1.19.0-22.1.1.33.0",
            "P-1870V-18.1.4.39.0-18.1.4.53.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-57699",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-10945V-12.2.0.4.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Veridata",
          "text": "37692935"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Converged Charging System",
          "text": "37680956"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Solaris Cluster",
          "text": "37693200"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
          "text": "37680943"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Studio",
          "text": "37692933"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (json-smart)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search. CVSS 3.1 Base Score 2.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Converged Charging System product of Oracle Communications Applications (component: Installation (json-smart)).  Supported versions that are affected are 2.0.0.0.0 and  2.0.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Converged Charging System.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Converged Charging System. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle GoldenGate Studio product of Oracle GoldenGate (component: GoldenGate Studio (json-smart)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle GoldenGate Veridata product of Oracle GoldenGate (component: General (json-smart)).  Supported versions that are affected are 12.2.1.4.0-12.2.1.4.250515. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GoldenGate Veridata executes to compromise Oracle GoldenGate Veridata.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GoldenGate Veridata. CVSS 3.1 Base Score 4.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Solaris Cluster product of Oracle Systems (component: Core (json-smart)).   The supported version that is affected is 4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Solaris Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris Cluster. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10005V-4",
          "P-14565V-2.0.0.1.0",
          "P-9633(Content Acquisition System)V-11.4.0",
          "P-14565V-2.0.0.0.0",
          "P-5758V-12.2.1.4.0-12.2.1.4.250515"
        ],
        "known_not_affected": [
          "P-10945V-12.2.0.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9633(Content Acquisition System)V-11.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106894.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14565V-2.0.0.0.0",
            "P-14565V-2.0.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105318.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5758V-12.2.1.4.0-12.2.1.4.250515",
            "P-10945V-12.2.0.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10005V-4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106603.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 2.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-9633(Content Acquisition System)V-11.4.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10005V-4",
            "P-14565V-2.0.0.0.0",
            "P-14565V-2.0.0.1.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-10945V-12.2.0.4.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 4.7,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-5758V-12.2.1.4.0-12.2.1.4.250515"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-10945V-12.2.0.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-6923",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38183449"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the RDBMS (Python) component of Oracle Database Server.  Supported versions that are affected are 21.3-21.19 and  23.4-23.9. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with logon to the infrastructure where RDBMS (Python) executes to compromise RDBMS (Python).  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of RDBMS (Python).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5(RDBMS)V-21.3-21.19",
          "P-5(RDBMS)V-23.4-23.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(RDBMS)V-21.3-21.19",
            "P-5(RDBMS)V-23.4-23.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ]
    },
    {
      "cve": "CVE-2024-7254",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Converged Charging System",
          "text": "37599158"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
          "text": "37275395"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (Google Protobuf-Java)).   The supported version that is affected is 7.6.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Converged Charging System product of Oracle Communications Applications (component: Installation (Google Protobuf-Java)).  Supported versions that are affected are 2.0.0.0.0 and  2.0.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Converged Charging System.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Converged Charging System. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2025V-7.6.0.0.0",
          "P-14565V-2.0.0.1.0",
          "P-14565V-2.0.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2025V-7.6.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105456.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14565V-2.0.0.0.0",
            "P-14565V-2.0.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105318.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14565V-2.0.0.0.0",
            "P-2025V-7.6.0.0.0",
            "P-14565V-2.0.0.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-8006",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "37107952"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (libpcap)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.0-6.1.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.1.0-6.1.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-8088",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38183449"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the RDBMS (Python) component of Oracle Database Server.  Supported versions that are affected are 21.3-21.19 and  23.4-23.9. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with logon to the infrastructure where RDBMS (Python) executes to compromise RDBMS (Python).  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of RDBMS (Python).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5(RDBMS)V-21.3-21.19",
          "P-5(RDBMS)V-23.4-23.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(RDBMS)V-21.3-21.19",
            "P-5(RDBMS)V-23.4-23.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ]
    },
    {
      "cve": "CVE-2024-9143",
      "ids": [
        {
          "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
          "text": "37522821"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure SEC (OpenSSL)).  Supported versions that are affected are 9.2.0.0-9.2.9.4. Easily exploitable vulnerability allows low privileged attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4781V-9.2.0.0-9.2.9.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4781V-9.2.0.0-9.2.9.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106891.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4781V-9.2.0.0-9.2.9.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-9287",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "38183466"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Porting (Python)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106893.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-0411",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-1870V-18.1.4.1.0-18.1.4.48.0",
            "P-1870V-22.1.1.1.0-22.1.1.30.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle TimesTen In-Memory Database",
          "text": "37581857"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle TimesTen In-Memory Database (component: EM TimesTen plug-in (7-Zip)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-1870V-22.1.1.1.0-22.1.1.30.0",
          "P-1870V-18.1.4.1.0-18.1.4.48.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1870V-18.1.4.1.0-18.1.4.48.0",
            "P-1870V-22.1.1.1.0-22.1.1.30.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1870V-18.1.4.1.0-18.1.4.48.0",
            "P-1870V-22.1.1.1.0-22.1.1.30.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-1870V-18.1.4.1.0-18.1.4.48.0",
            "P-1870V-22.1.1.1.0-22.1.1.30.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-10148",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-4379V-21.7.3.0.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
          "text": "38448051"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Essbase",
          "text": "38448057"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Security (curl)).  Supported versions that are affected are 7.7.0-7.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle Essbase (component: Essbase Web Platform (curl)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4516V-7.7.0-7.8.0"
        ],
        "known_not_affected": [
          "P-4379V-21.7.3.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.7.0-7.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105322.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4379V-21.7.3.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4379V-21.7.3.0.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-4379V-21.7.3.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-1220",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-1522V-19.1.0.1.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Secure Backup",
          "text": "38268922"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle Secure Backup (component: Oracle Secure Backup (PHP)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-1522V-19.1.0.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1522V-19.1.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1522V-19.1.0.1.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-1522V-19.1.0.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-1735",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-1522V-19.1.0.1.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Secure Backup",
          "text": "38268922"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle Secure Backup (component: Oracle Secure Backup (PHP)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-1522V-19.1.0.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1522V-19.1.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1522V-19.1.0.1.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-1522V-19.1.0.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-1795",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38183449"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the RDBMS (Python) component of Oracle Database Server.  Supported versions that are affected are 21.3-21.19 and  23.4-23.9. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with logon to the infrastructure where RDBMS (Python) executes to compromise RDBMS (Python).  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of RDBMS (Python).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5(RDBMS)V-21.3-21.19",
          "P-5(RDBMS)V-23.4-23.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(RDBMS)V-21.3-21.19",
            "P-5(RDBMS)V-23.4-23.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-1948",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications EAGLE Element Management System",
          "text": "38017342"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications EAGLE Element Management System product of Oracle Communications (component: Security (Eclipse Jetty)).   The supported version that is affected is 47.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Element Management System.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications EAGLE Element Management System. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-11125V-47.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11125V-47.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105423.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-11125V-47.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-22227",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-5760V-23.4-23.9"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters",
          "text": "38347485"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: Java Delivery (Reactor Netty)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-5760V-23.4-23.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5760V-23.4-23.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5760V-23.4-23.9"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-5760V-23.4-23.9"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-22228",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-9617V-14.1.2.0.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle WebCenter Sites",
          "text": "38105930"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites (Spring Security)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-9617V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9617V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105435.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9617V-14.1.2.0.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-9617V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-22233",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
          "text": "38490026"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Commerce Platform",
          "text": "38436792"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework (Spring Framework)).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Platform.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 3.1 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Tools And Frameworks, Content Acquisition System, Platform Services (Spring Framework)).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Commerce Guided Search accessible data. CVSS 3.1 Base Score 3.1 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9348V-11.4.0",
          "P-9633(Tools And Frameworks, Content Acquisition System, Platform Services)V-11.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9348V-11.4.0",
            "P-9633(Tools And Frameworks, Content Acquisition System, Platform Services)V-11.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106894.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 3.1,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9348V-11.4.0",
            "P-9633(Tools And Frameworks, Content Acquisition System, Platform Services)V-11.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-22235",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-9617V-14.1.2.0.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle WebCenter Sites",
          "text": "38105930"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites (Spring Security)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-9617V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9617V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105435.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9617V-14.1.2.0.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-9617V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-23084",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-14125V-25.1.100",
            "P-14125V-25.1.200"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Function Cloud Native Environment",
          "text": "38231262"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38231263"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: Configuration (Node.js)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Node.js)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.0-6.1.1"
        ],
        "known_not_affected": [
          "P-14125V-25.1.100",
          "P-14125V-25.1.200"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14125V-25.1.100",
            "P-14125V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105380.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14125V-25.1.100",
            "P-14125V-25.1.200"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-14125V-25.1.100",
            "P-14125V-25.1.200"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-23166",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38021373"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the GraalVM Multilingual Engine component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
          "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
            "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
            "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-23184",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Commerce Platform",
          "text": "38295206"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Endeca Integration (Apache CXF)).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Commerce Platform.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Commerce Platform accessible data as well as  unauthorized read access to a subset of Oracle Commerce Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Platform.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9348V-11.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9348V-11.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106894.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-24189",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38167315"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (WebKitGTK)).  Supported versions that are affected are Oracle Java SE: 8u461-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u461-b50"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u461-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104405.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-24855",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38021373"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the GraalVM Multilingual Engine component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
          "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
            "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
            "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-24970",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Converged Charging System",
          "text": "38312727"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Converged Charging System product of Oracle Communications Applications (component: Installation (Netty)).  Supported versions that are affected are 2.0.0.0.0 and  2.0.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Converged Charging System.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Converged Charging System.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14565V-2.0.0.1.0",
          "P-14565V-2.0.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14565V-2.0.0.0.0",
            "P-14565V-2.0.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105318.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-25193",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Converged Charging System",
          "text": "38312727"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
          "text": "37696250"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (Netty)).   The supported version that is affected is 7.6.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Converged Charging System product of Oracle Communications Applications (component: Installation (Netty)).  Supported versions that are affected are 2.0.0.0.0 and  2.0.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Converged Charging System.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Converged Charging System.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2025V-7.6.0.0.0",
          "P-14565V-2.0.0.1.0",
          "P-14565V-2.0.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2025V-7.6.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105456.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14565V-2.0.0.0.0",
            "P-14565V-2.0.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105318.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-2025V-7.6.0.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-25724",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "38144364"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Core (libarchive)).  Supported versions that are affected are 24.2.0-24.2.1, 24.3.0, 25.1.100 and  25.1.200. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Network Analytics Data Director executes to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Network Analytics Data Director. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14547V-24.2.0-24.2.1",
          "P-14547V-24.3.0",
          "P-14547V-25.1.200",
          "P-14547V-25.1.100"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-24.2.0-24.2.1",
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105450.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14547V-24.2.0-24.2.1",
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-14547V-24.3.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-26333",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-5(RDBMS)V-21.3-21.19",
            "P-5(RDBMS)V-23.4-23.9",
            "P-5(RDBMS)V-19.3-19.28"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38540156"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the RDBMS (Dell BSAFE Crypto-J) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-5(RDBMS)V-23.4-23.9",
          "P-5(RDBMS)V-19.3-19.28",
          "P-5(RDBMS)V-21.3-21.19"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(RDBMS)V-21.3-21.19",
            "P-5(RDBMS)V-23.4-23.9",
            "P-5(RDBMS)V-19.3-19.28"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(RDBMS)V-21.3-21.19",
            "P-5(RDBMS)V-23.4-23.9",
            "P-5(RDBMS)V-19.3-19.28"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-5(RDBMS)V-21.3-21.19",
            "P-5(RDBMS)V-23.4-23.9",
            "P-5(RDBMS)V-19.3-19.28"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-27113",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38021373"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the GraalVM Multilingual Engine component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
          "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
            "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
            "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-27209",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-14125V-25.1.100",
            "P-14125V-25.1.200"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Function Cloud Native Environment",
          "text": "38231262"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38231263"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: Configuration (Node.js)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Node.js)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.0-6.1.1"
        ],
        "known_not_affected": [
          "P-14125V-25.1.100",
          "P-14125V-25.1.200"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14125V-25.1.100",
            "P-14125V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105380.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14125V-25.1.100",
            "P-14125V-25.1.200"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-14125V-25.1.100",
            "P-14125V-25.1.200"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-27210",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-14125V-25.1.100",
            "P-14125V-25.1.200"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Function Cloud Native Environment",
          "text": "38231262"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38231263"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: Configuration (Node.js)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Node.js)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 4.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.0-6.1.1"
        ],
        "known_not_affected": [
          "P-14125V-25.1.100",
          "P-14125V-25.1.200"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14125V-25.1.100",
            "P-14125V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105380.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14125V-25.1.100",
            "P-14125V-25.1.200"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 4.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.1.0-6.1.1"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-14125V-25.1.100",
            "P-14125V-25.1.200"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-27363",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Primavera P6 Enterprise Project Portfolio Management",
          "text": "37735486"
        },
        {
          "system_name": "Oracle Bug ID of Primavera Unifier",
          "text": "37735487"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Documaker",
          "text": "37735466"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Documaker product of Oracle Insurance Applications (component: Documaker Core (FreeType)).  Supported versions that are affected are 13.0.0.3 and  13.0.1.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Documaker.  Successful attacks of this vulnerability can result in takeover of Oracle Documaker. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Outside In Technology Installer in P6 (FreeType)).  Supported versions that are affected are 20.12.0.0-20.12.21.0, 21.12.0.0-21.12.21.2, 22.12.0.0-22.12.20.0, 23.12.0.0-23.12.14.0 and  24.12.0.0-24.12.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management.  Successful attacks of this vulnerability can result in takeover of Primavera P6 Enterprise Project Portfolio Management. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Document Management (FreeType)).  Supported versions that are affected are 20.12.0-20.12.16, 21.12.0-21.12.17, 22.12.0-22.12.15, 23.12.0-23.12.15 and   24.12.0-24.12.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in takeover of Primavera Unifier. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5477V-13.0.0.3",
          "P-5579V-24.12.0.0-24.12.4.0",
          "P-5477V-13.0.1.1",
          "P-10354V-24.12.0-24.12.9",
          "P-10354V-20.12.0-20.12.16",
          "P-10354V-22.12.0-22.12.15",
          "P-10354V-23.12.0-23.12.15",
          "P-5579V-20.12.0.0-20.12.21.0",
          "P-5579V-22.12.0.0-22.12.20.0",
          "P-10354V-21.12.0-21.12.17",
          "P-5579V-21.12.0.0-21.12.21.2",
          "P-5579V-23.12.0.0-23.12.14.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5477V-13.0.0.3",
            "P-5477V-13.0.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3107101.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10354V-20.12.0-20.12.16",
            "P-10354V-22.12.0-22.12.15",
            "P-10354V-23.12.0-23.12.15",
            "P-5579V-20.12.0.0-20.12.21.0",
            "P-5579V-24.12.0.0-24.12.4.0",
            "P-5579V-22.12.0.0-22.12.20.0",
            "P-10354V-21.12.0-21.12.17",
            "P-5579V-21.12.0.0-21.12.21.2",
            "P-10354V-24.12.0-24.12.9",
            "P-5579V-23.12.0.0-23.12.14.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106664.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10354V-20.12.0-20.12.16",
            "P-10354V-22.12.0-22.12.15",
            "P-10354V-23.12.0-23.12.15",
            "P-5477V-13.0.0.3",
            "P-5579V-20.12.0.0-20.12.21.0",
            "P-5579V-24.12.0.0-24.12.4.0",
            "P-5477V-13.0.1.1",
            "P-5579V-22.12.0.0-22.12.20.0",
            "P-10354V-21.12.0-21.12.17",
            "P-5579V-21.12.0.0-21.12.21.2",
            "P-10354V-24.12.0-24.12.9",
            "P-5579V-23.12.0.0-23.12.14.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-27533",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.12"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38268768"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Stream Analytics",
          "text": "38268788"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Enterprise Data Quality",
          "text": "38268756"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Enterprise Data Quality product of Oracle Fusion Middleware (component: General (Apache ActiveMQ)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Enterprise Data Quality.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Enterprise Data Quality. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle GoldenGate Stream Analytics product of Oracle GoldenGate (component: General Issues (Apache ActiveMQ)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Apache ActiveMQ)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9464V-14.1.2.0.0",
          "P-14597V-6.1.0-6.1.1",
          "P-9464V-12.2.1.4.0"
        ],
        "known_not_affected": [
          "P-14015V-19.1.0.0.0-19.1.0.0.12"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9464V-12.2.1.4.0",
            "P-9464V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105435.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.12"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-9464V-12.2.1.4.0",
            "P-9464V-14.1.2.0.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14015V-19.1.0.0.0-19.1.0.0.12"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.1.0-6.1.1"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.12"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-27553",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Primavera Gateway",
          "text": "38259683"
        },
        {
          "system_name": "Oracle Bug ID of Graph Server and Client",
          "text": "38259640"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications EAGLE Element Management System",
          "text": "38259598"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Order and Service Management",
          "text": "38259599"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
          "text": "38259613"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
          "text": "38259605"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Security (Apache Commons VFS)).  Supported versions that are affected are 7.5.0-7.5.1 and  7.6.0-7.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Inventory Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security (Apache Commons VFS)).  Supported versions that are affected are 7.4.0, 7.4.1 and  7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Order and Service Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Order and Service Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications EAGLE Element Management System product of Oracle Communications (component: Security (Apache Commons VFS)).   The supported version that is affected is 47.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Element Management System.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications EAGLE Element Management System accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform (Apache Commons VFS)).  Supported versions that are affected are 8.0.7.9 and  8.0.8.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Graph Server and Client product of Oracle Graph Server and Client (component: Packaging (Apache Commons VFS)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Primavera Gateway product of Oracle Construction and Engineering (component: Admin (Apache Commons VFS)).  Supported versions that are affected are 20.12.0-20.12.17 and  21.12.0-21.12.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Gateway.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Primavera Gateway accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-11125V-47.0",
          "P-4516V-7.6.0-7.8.0",
          "P-10605V-21.12.0-21.12.15",
          "P-10605V-20.12.0-20.12.17",
          "P-2270V-7.4.0",
          "P-2270V-7.4.1",
          "P-2270V-7.5.0",
          "P-5680V-8.0.7.9",
          "P-5680V-8.0.8.7",
          "P-4516V-7.5.0-7.5.1"
        ],
        "known_not_affected": [
          "P-14069V-24.4.1",
          "P-14069V-25.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.6.0-7.8.0",
            "P-4516V-7.5.0-7.5.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105322.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2270V-7.4.0",
            "P-2270V-7.4.1",
            "P-2270V-7.5.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105308.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11125V-47.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105423.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5680V-8.0.7.9",
            "P-5680V-8.0.8.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104221.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10605V-21.12.0-21.12.15",
            "P-10605V-20.12.0-20.12.17"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106664.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-11125V-47.0",
            "P-4516V-7.6.0-7.8.0",
            "P-10605V-21.12.0-21.12.15",
            "P-10605V-20.12.0-20.12.17",
            "P-2270V-7.4.0",
            "P-2270V-7.4.1",
            "P-2270V-7.5.0",
            "P-5680V-8.0.7.9",
            "P-5680V-8.0.8.7",
            "P-4516V-7.5.0-7.5.1"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-27587",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
          "text": "38168445"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Configuration (OpenSSL)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Certificate Management accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14868V-25.1.200"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14868V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105451.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14868V-25.1.200"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-27817",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.12"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Billing and Revenue Management",
          "text": "38128821"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
          "text": "38237107"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Stream Analytics",
          "text": "38128877"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Branch",
          "text": "38128803"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Convergent Charging Controller",
          "text": "38128825"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38128829"
        },
        {
          "system_name": "Oracle Bug ID of Oracle SOA Suite",
          "text": "38128817"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Charging and Control",
          "text": "38128828"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Platform (Apache Kafka)).  Supported versions that are affected are 12.0.0.4.0-15.0.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Billing and Revenue Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Adapters (Apache Kafka)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle SOA Suite accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports (Apache Kafka)).  Supported versions that are affected are 14.5.0.0.0-14.8.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Branch.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Banking Branch accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications Applications (component: Notification Gateway (Apache Kafka)).  Supported versions that are affected are 12.0.3.0.0-12.0.6.0.0, 15.0.0.0.0-15.0.1.0.0 and  15.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Convergent Charging Controller.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Convergent Charging Controller accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications Applications (component: Solution Designer (Apache Kafka)).  Supported versions that are affected are 8.0.0.5.0, 8.1.0.4.0 and  8.2.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Service Catalog and Design accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle GoldenGate Stream Analytics product of Oracle GoldenGate (component: General Issues (Apache Kafka)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Apache Kafka)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Charging and Control product of Oracle Communications Applications (component: Notification Gateway (Apache Kafka)).  Supported versions that are affected are 12.0.3.0.0-12.0.6.0.0, 15.0.0.0.0-15.0.1.0.0 and  15.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Charging and Control.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Network Charging and Control accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2136(Platform)V-12.0.0.4.0-15.0.1.0.0",
          "P-12985V-15.1.0.0.0",
          "P-12985V-15.0.0.0.0-15.0.1.0.0",
          "P-4623V-15.1.0.0.0",
          "P-12985V-12.0.3.0.0-12.0.6.0.0",
          "P-14597V-6.1.0-6.1.1",
          "P-1162V-14.1.2.0.0",
          "P-4623V-12.0.3.0.0-12.0.6.0.0",
          "P-2283V-8.0.0.5.0",
          "P-4623V-15.0.0.0.0-15.0.1.0.0",
          "P-2283V-8.2.0.1.0",
          "P-14324V-14.5.0.0.0-14.8.0.0.0",
          "P-2283V-8.1.0.4.0"
        ],
        "known_not_affected": [
          "P-14015V-19.1.0.0.0-19.1.0.0.12"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2136(Platform)V-12.0.0.4.0-15.0.1.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105317.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1162V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105435.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14324V-14.5.0.0.0-14.8.0.0.0"
          ],
          "url": "https://support.oracle.com"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4623V-12.0.3.0.0-12.0.6.0.0",
            "P-12985V-15.1.0.0.0",
            "P-12985V-15.0.0.0.0-15.0.1.0.0",
            "P-4623V-15.1.0.0.0",
            "P-12985V-12.0.3.0.0-12.0.6.0.0",
            "P-4623V-15.0.0.0.0-15.0.1.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105320.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2283V-8.0.0.5.0",
            "P-2283V-8.2.0.1.0",
            "P-2283V-8.1.0.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105310.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.12"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-2136(Platform)V-12.0.0.4.0-15.0.1.0.0",
            "P-12985V-15.1.0.0.0",
            "P-12985V-15.0.0.0.0-15.0.1.0.0",
            "P-4623V-15.1.0.0.0",
            "P-12985V-12.0.3.0.0-12.0.6.0.0",
            "P-14597V-6.1.0-6.1.1",
            "P-1162V-14.1.2.0.0",
            "P-4623V-12.0.3.0.0-12.0.6.0.0",
            "P-2283V-8.0.0.5.0",
            "P-4623V-15.0.0.0.0-15.0.1.0.0",
            "P-2283V-8.2.0.1.0",
            "P-14324V-14.5.0.0.0-14.8.0.0.0",
            "P-2283V-8.1.0.4.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14015V-19.1.0.0.0-19.1.0.0.12"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.12"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-27818",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.12"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Billing and Revenue Management",
          "text": "38128821"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Stream Analytics",
          "text": "38128877"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Branch",
          "text": "38128803"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Convergent Charging Controller",
          "text": "38128825"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38128829"
        },
        {
          "system_name": "Oracle Bug ID of Oracle SOA Suite",
          "text": "38128817"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Charging and Control",
          "text": "38128828"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports (Apache Kafka)).  Supported versions that are affected are 14.5.0.0.0-14.8.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Branch.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Banking Branch accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Adapters (Apache Kafka)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle SOA Suite accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Charging and Control product of Oracle Communications Applications (component: Notification Gateway (Apache Kafka)).  Supported versions that are affected are 12.0.3.0.0-12.0.6.0.0, 15.0.0.0.0-15.0.1.0.0 and  15.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Charging and Control.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Network Charging and Control accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Apache Kafka)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications Applications (component: Notification Gateway (Apache Kafka)).  Supported versions that are affected are 12.0.3.0.0-12.0.6.0.0, 15.0.0.0.0-15.0.1.0.0 and  15.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Convergent Charging Controller.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Convergent Charging Controller accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Platform (Apache Kafka)).  Supported versions that are affected are 12.0.0.4.0-15.0.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Billing and Revenue Management accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle GoldenGate Stream Analytics product of Oracle GoldenGate (component: General Issues (Apache Kafka)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4623V-12.0.3.0.0-12.0.6.0.0",
          "P-2136(Platform)V-12.0.0.4.0-15.0.1.0.0",
          "P-12985V-15.1.0.0.0",
          "P-12985V-15.0.0.0.0-15.0.1.0.0",
          "P-4623V-15.1.0.0.0",
          "P-4623V-15.0.0.0.0-15.0.1.0.0",
          "P-12985V-12.0.3.0.0-12.0.6.0.0",
          "P-14597V-6.1.0-6.1.1",
          "P-14324V-14.5.0.0.0-14.8.0.0.0",
          "P-1162V-14.1.2.0.0"
        ],
        "known_not_affected": [
          "P-14015V-19.1.0.0.0-19.1.0.0.12"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14324V-14.5.0.0.0-14.8.0.0.0"
          ],
          "url": "https://support.oracle.com"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1162V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105435.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4623V-12.0.3.0.0-12.0.6.0.0",
            "P-12985V-15.1.0.0.0",
            "P-12985V-15.0.0.0.0-15.0.1.0.0",
            "P-4623V-15.1.0.0.0",
            "P-4623V-15.0.0.0.0-15.0.1.0.0",
            "P-12985V-12.0.3.0.0-12.0.6.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105320.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2136(Platform)V-12.0.0.4.0-15.0.1.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105317.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.12"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14015V-19.1.0.0.0-19.1.0.0.12"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.12"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-30474",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Primavera Gateway",
          "text": "38259683"
        },
        {
          "system_name": "Oracle Bug ID of Graph Server and Client",
          "text": "38259640"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications EAGLE Element Management System",
          "text": "38259598"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Order and Service Management",
          "text": "38259599"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
          "text": "38259613"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
          "text": "38259605"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Graph Server and Client product of Oracle Graph Server and Client (component: Packaging (Apache Commons VFS)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security (Apache Commons VFS)).  Supported versions that are affected are 7.4.0, 7.4.1 and  7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Order and Service Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Order and Service Management accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Security (Apache Commons VFS)).  Supported versions that are affected are 7.5.0-7.5.1 and  7.6.0-7.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Inventory Management accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Primavera Gateway product of Oracle Construction and Engineering (component: Admin (Apache Commons VFS)).  Supported versions that are affected are 20.12.0-20.12.17 and  21.12.0-21.12.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Gateway.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Primavera Gateway accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications EAGLE Element Management System product of Oracle Communications (component: Security (Apache Commons VFS)).   The supported version that is affected is 47.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Element Management System.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications EAGLE Element Management System accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform (Apache Commons VFS)).  Supported versions that are affected are 8.0.7.9 and  8.0.8.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Analytical Applications Infrastructure accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-11125V-47.0",
          "P-4516V-7.6.0-7.8.0",
          "P-10605V-21.12.0-21.12.15",
          "P-10605V-20.12.0-20.12.17",
          "P-2270V-7.4.0",
          "P-2270V-7.4.1",
          "P-2270V-7.5.0",
          "P-5680V-8.0.7.9",
          "P-5680V-8.0.8.7",
          "P-4516V-7.5.0-7.5.1"
        ],
        "known_not_affected": [
          "P-14069V-24.4.1",
          "P-14069V-25.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2270V-7.4.0",
            "P-2270V-7.4.1",
            "P-2270V-7.5.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105308.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.6.0-7.8.0",
            "P-4516V-7.5.0-7.5.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105322.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10605V-21.12.0-21.12.15",
            "P-10605V-20.12.0-20.12.17"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106664.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11125V-47.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105423.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5680V-8.0.7.9",
            "P-5680V-8.0.8.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104221.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-30749",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38021373"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the GraalVM Multilingual Engine component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
          "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
            "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
            "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-30752",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38021373"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the GraalVM Multilingual Engine component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
          "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
            "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
            "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-30754",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38021373"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the GraalVM Multilingual Engine component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
          "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
            "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
            "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-30761",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38021373"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the GraalVM Multilingual Engine component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
          "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
            "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
            "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-31257",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38167315"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (WebKitGTK)).  Supported versions that are affected are Oracle Java SE: 8u461-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u461-b50"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u461-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104405.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-856V-8u461-b50"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-31273",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38167315"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (WebKitGTK)).  Supported versions that are affected are Oracle Java SE: 8u461-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u461-b50"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u461-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104405.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-31278",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38167315"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (WebKitGTK)).  Supported versions that are affected are Oracle Java SE: 8u461-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u461-b50"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u461-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104405.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-31650",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Siebel CRM Deployment",
          "text": "37926486"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface (Apache Tomcat)).  Supported versions that are affected are Prior to 25.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9019V-Prior to 25.8"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9019V-Prior to 25.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106900.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-31651",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Siebel CRM Deployment",
          "text": "37926486"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface (Apache Tomcat)).  Supported versions that are affected are Prior to 25.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9019V-Prior to 25.8"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9019V-Prior to 25.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106900.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-9019V-Prior to 25.8"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-31672",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-13824V-23.4-23.9"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "37899983"
        },
        {
          "system_name": "Oracle Bug ID of SQLcl (Apache POI)",
          "text": "38178010"
        },
        {
          "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
          "text": "38202099"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
          "text": "37885535"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC (Apache POI)).  Supported versions that are affected are 9.2.0.0-9.2.9.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: nVision (Apache POI)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform (Apache POI)).  Supported versions that are affected are 8.0.7.9, 8.0.8.7 and  8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the SQLcl (Apache POI) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5680V-8.1.2.5",
          "P-5680V-8.0.7.9",
          "P-5680V-8.0.8.7",
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-4781V-9.2.0.0-9.2.9.4",
          "P-5085V-8.62"
        ],
        "known_not_affected": [
          "P-13824V-23.4-23.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4781V-9.2.0.0-9.2.9.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106891.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106893.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.7.9",
            "P-5680V-8.0.8.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104221.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13824V-23.4-23.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.7.9",
            "P-5680V-8.0.8.7",
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-4781V-9.2.0.0-9.2.9.4",
            "P-5085V-8.62"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-13824V-23.4-23.9"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-13824V-23.4-23.9"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-32414",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Banking Corporate Lending Process Management",
          "text": "37950891"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Origination",
          "text": "37950898"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Maintenance (libxml2)).  Supported versions that are affected are 14.5.0.0.0-14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Origination.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Platform (libxml2)).  Supported versions that are affected are 14.4.0.0.0-14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Corporate Lending Process Management.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13701V-14.4.0.0.0-14.7.0.0.0",
          "P-14325V-14.5.0.0.0-14.7.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13701V-14.4.0.0.0-14.7.0.0.0",
            "P-14325V-14.5.0.0.0-14.7.0.0.0"
          ],
          "url": "https://support.oracle.com"
        }
      ]
    },
    {
      "cve": "CVE-2025-32415",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Banking Corporate Lending Process Management",
          "text": "37950891"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38385251"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Origination",
          "text": "37950898"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Platform (libxml2)).  Supported versions that are affected are 14.4.0.0.0-14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Corporate Lending Process Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Maintenance (libxml2)).  Supported versions that are affected are 14.5.0.0.0-14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Origination. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (libxml2)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.0-6.1.1",
          "P-13701V-14.4.0.0.0-14.7.0.0.0",
          "P-14325V-14.5.0.0.0-14.7.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13701V-14.4.0.0.0-14.7.0.0.0",
            "P-14325V-14.5.0.0.0-14.7.0.0.0"
          ],
          "url": "https://support.oracle.com"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-13701V-14.4.0.0.0-14.7.0.0.0",
            "P-14325V-14.5.0.0.0-14.7.0.0.0",
            "P-14597V-6.1.0-6.1.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-32728",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Enterprise Communications Broker",
          "text": "38505518"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Session Border Controller",
          "text": "37925016"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Enterprise Communications Broker product of Oracle Communications (component: Routing (OpenSSH)).  Supported versions that are affected are 4.1.0-4.2.0 and  5.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise Communications Broker executes to compromise Oracle Enterprise Communications Broker.  While the vulnerability is in Oracle Enterprise Communications Broker, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Enterprise Communications Broker accessible data. CVSS 3.1 Base Score 3.8 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Session Border Controller product of Oracle Communications (component: Sysadmin (OpenSSH)).  Supported versions that are affected are 4.1.0, 9.0.0, 9.2.0-9.3.0 and  10.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Session Border Controller executes to compromise Oracle Communications Session Border Controller.  While the vulnerability is in Oracle Communications Session Border Controller, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Session Border Controller accessible data. CVSS 3.1 Base Score 3.8 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10750V-10.0.0",
          "P-10750V-4.1.0",
          "P-10750V-9.2.0-9.3.0",
          "P-10758V-5.0.0",
          "P-10758V-4.1.0-4.2.0",
          "P-10750V-9.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10758V-5.0.0",
            "P-10758V-4.1.0-4.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105853.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10750V-10.0.0",
            "P-10750V-4.1.0",
            "P-10750V-9.2.0-9.3.0",
            "P-10750V-9.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105851.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 3.8,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-10750V-10.0.0",
            "P-10750V-4.1.0",
            "P-10750V-9.2.0-9.3.0",
            "P-10758V-5.0.0",
            "P-10758V-4.1.0-4.2.0",
            "P-10750V-9.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-32988",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
          "text": "38206360"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Security (GnuTLS)).  Supported versions that are affected are 7.7.0-7.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management as well as  unauthorized update, insert or delete access to some of Oracle Communications Unified Inventory Management accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4516V-7.7.0-7.8.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.7.0-7.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105322.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-32989",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
          "text": "38206360"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Security (GnuTLS)).  Supported versions that are affected are 7.7.0-7.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management as well as  unauthorized update, insert or delete access to some of Oracle Communications Unified Inventory Management accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4516V-7.7.0-7.8.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.7.0-7.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105322.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-32990",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
          "text": "38206360"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Security (GnuTLS)).  Supported versions that are affected are 7.7.0-7.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management as well as  unauthorized update, insert or delete access to some of Oracle Communications Unified Inventory Management accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4516V-7.7.0-7.8.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.7.0-7.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105322.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            "P-4516V-7.7.0-7.8.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-3573",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Hyperion Data Relationship Management",
          "text": "38161538"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Web Client - Unicode (jQuery)).   The supported version that is affected is 11.2.22.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data as well as  unauthorized read access to a subset of Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4375V-11.2.22.0.000"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4375V-11.2.22.0.000"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2775466.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4375V-11.2.22.0.000"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-3576",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "38144333"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Core (Kerberos)).  Supported versions that are affected are 24.2.0-24.2.1, 24.3.0, 25.1.100 and  25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Network Analytics Data Director accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14547V-24.2.0-24.2.1",
          "P-14547V-24.3.0",
          "P-14547V-25.1.200",
          "P-14547V-25.1.100"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-24.2.0-24.2.1",
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105450.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14547V-24.2.0-24.2.1",
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-14547V-24.3.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-41249",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Behavior Detection Platform",
          "text": "38517505"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
          "text": "38517503"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition",
          "text": "38517511"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Platform (Spring Framework)).  Supported versions that are affected are 8.0.8.1, 8.1.2.9 and  8.1.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Behavior Detection Platform accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform (Spring Framework)).  Supported versions that are affected are 8.0.7.9, 8.0.8.7 and  8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition product of Oracle Financial Services Applications (component: Platform (Spring Framework)).   The supported version that is affected is 8.0.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5680V-8.1.2.5",
          "P-13789V-8.0.8",
          "P-9190V-8.1.2.9",
          "P-9190V-8.0.8.1",
          "P-5680V-8.0.7.9",
          "P-5680V-8.0.8.7",
          "P-9190V-8.1.2.10"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9190V-8.1.2.9",
            "P-9190V-8.0.8.1",
            "P-9190V-8.1.2.10"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105116.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.7.9",
            "P-5680V-8.0.8.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104221.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13789V-8.0.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105187.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5680V-8.1.2.5",
            "P-13789V-8.0.8",
            "P-9190V-8.1.2.9",
            "P-9190V-8.0.8.1",
            "P-5680V-8.0.7.9",
            "P-5680V-8.0.8.7",
            "P-9190V-8.1.2.10"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-4138",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core DBTier",
          "text": "38183439"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38183449"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
          "text": "38183437"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38183448"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "38183447"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Workbench",
          "text": "38183431"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
          "text": "38183441"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
          "text": "38183446"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
          "text": "38183444"
        },
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "38183466"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Python)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Python)).  Supported versions that are affected are 24.2.7-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Policy.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (Python)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core DBTier accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core DBTier accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core DBTier.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Python)).  Supported versions that are affected are 24.2.7-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Binding Support Function accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Binding Support Function.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (Python)).  Supported versions that are affected are 8.0.0-8.0.43. Easily exploitable vulnerability allows unauthenticated attacker with network access via MySQL Workbench to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Workbench accessible data as well as  unauthorized access to critical data or complete access to all MySQL Workbench accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Workbench.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: ATS Framework (Python)).   The supported version that is affected is 9.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Diameter Signaling Router accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Diameter Signaling Router accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Diameter Signaling Router.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Porting (Python)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the RDBMS (Python) component of Oracle Database Server.  Supported versions that are affected are 21.3-21.19 and  23.4-23.9. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with logon to the infrastructure where RDBMS (Python) executes to compromise RDBMS (Python).  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of RDBMS (Python).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Python)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: ATS Framework (Python)).  Supported versions that are affected are 24.2.0, 24.2.1, 24.3.0, 25.1.100 and  25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Network Analytics Data Director accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Network Analytics Data Director accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Network Analytics Data Director.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14547V-25.1.200",
          "P-14277V-24.2.7-25.1.200",
          "P-5(RDBMS)V-21.3-21.19",
          "P-14547V-25.1.100",
          "P-14547V-24.2.0",
          "P-14974V-25.1.200",
          "P-14597V-6.1.0-6.1.1",
          "P-5(RDBMS)V-23.4-23.9",
          "P-14547V-24.2.1",
          "P-14547V-24.3.0",
          "P-14130V-25.1.200",
          "P-4627V-8.0.0-8.0.43",
          "P-10899V-9.1.0.0.0",
          "P-14121V-24.2.7-25.1.200",
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14130V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105448.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-24.2.7-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105404.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14974V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105407.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14121V-24.2.7-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105418.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4627V-8.0.0-8.0.43"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10899V-9.1.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105378.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106893.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(RDBMS)V-21.3-21.19",
            "P-5(RDBMS)V-23.4-23.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-14547V-24.2.0",
            "P-14547V-24.2.1",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105450.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-43211",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38167315"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (WebKitGTK)).  Supported versions that are affected are Oracle Java SE: 8u461-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u461-b50"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u461-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104405.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-43212",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38167315"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (WebKitGTK)).  Supported versions that are affected are Oracle Java SE: 8u461-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u461-b50"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u461-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104405.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-43216",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38167315"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (WebKitGTK)).  Supported versions that are affected are Oracle Java SE: 8u461-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u461-b50"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u461-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104405.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-43227",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38167315"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (WebKitGTK)).  Supported versions that are affected are Oracle Java SE: 8u461-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u461-b50"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u461-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104405.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-43228",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38167315"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (WebKitGTK)).  Supported versions that are affected are Oracle Java SE: 8u461-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u461-b50"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u461-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104405.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-43240",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38167315"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (WebKitGTK)).  Supported versions that are affected are Oracle Java SE: 8u461-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u461-b50"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u461-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104405.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-43265",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38167315"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (WebKitGTK)).  Supported versions that are affected are Oracle Java SE: 8u461-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u461-b50"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u461-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104405.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-4330",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core DBTier",
          "text": "38183439"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38183449"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
          "text": "38183437"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38183448"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "38183447"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Workbench",
          "text": "38183431"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
          "text": "38183441"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
          "text": "38183446"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
          "text": "38183444"
        },
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "38183466"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Python)).  Supported versions that are affected are 24.2.7-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Binding Support Function accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Binding Support Function.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (Python)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core DBTier accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core DBTier accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core DBTier.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Python)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (Python)).  Supported versions that are affected are 8.0.0-8.0.43. Easily exploitable vulnerability allows unauthenticated attacker with network access via MySQL Workbench to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Workbench accessible data as well as  unauthorized access to critical data or complete access to all MySQL Workbench accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Workbench.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Python)).  Supported versions that are affected are 24.2.7-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Policy.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: ATS Framework (Python)).   The supported version that is affected is 9.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Diameter Signaling Router accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Diameter Signaling Router accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Diameter Signaling Router.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: ATS Framework (Python)).  Supported versions that are affected are 24.2.0, 24.2.1, 24.3.0, 25.1.100 and  25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Network Analytics Data Director accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Network Analytics Data Director accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Network Analytics Data Director.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Python)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the RDBMS (Python) component of Oracle Database Server.  Supported versions that are affected are 21.3-21.19 and  23.4-23.9. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with logon to the infrastructure where RDBMS (Python) executes to compromise RDBMS (Python).  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of RDBMS (Python).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Porting (Python)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14547V-25.1.200",
          "P-14277V-24.2.7-25.1.200",
          "P-14547V-25.1.100",
          "P-5(RDBMS)V-21.3-21.19",
          "P-14547V-24.2.0",
          "P-14974V-25.1.200",
          "P-14597V-6.1.0-6.1.1",
          "P-14547V-24.2.1",
          "P-14547V-24.3.0",
          "P-5(RDBMS)V-23.4-23.9",
          "P-14130V-25.1.200",
          "P-4627V-8.0.0-8.0.43",
          "P-10899V-9.1.0.0.0",
          "P-14121V-24.2.7-25.1.200",
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14121V-24.2.7-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105418.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14974V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105407.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14130V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105448.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4627V-8.0.0-8.0.43"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-24.2.7-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105404.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10899V-9.1.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105378.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-14547V-24.2.0",
            "P-14547V-24.2.1",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105450.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(RDBMS)V-21.3-21.19",
            "P-5(RDBMS)V-23.4-23.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106893.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-4373",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
          "text": "38315760"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Configuration (glibc)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Certificate Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Certificate Management. CVSS 3.1 Base Score 4.8 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14868V-25.1.200"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14868V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105451.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14868V-25.1.200"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-4435",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core DBTier",
          "text": "38183439"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38183449"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
          "text": "38183437"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38183448"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "38183447"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Workbench",
          "text": "38183431"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
          "text": "38183441"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
          "text": "38183446"
        },
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "38183466"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
          "text": "38183444"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (Python)).  Supported versions that are affected are 8.0.0-8.0.43. Easily exploitable vulnerability allows unauthenticated attacker with network access via MySQL Workbench to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Workbench accessible data as well as  unauthorized access to critical data or complete access to all MySQL Workbench accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Workbench.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Python)).  Supported versions that are affected are 24.2.7-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Binding Support Function accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Binding Support Function.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (Python)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core DBTier accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core DBTier accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core DBTier.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Python)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Porting (Python)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: ATS Framework (Python)).   The supported version that is affected is 9.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Diameter Signaling Router accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Diameter Signaling Router accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Diameter Signaling Router.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: ATS Framework (Python)).  Supported versions that are affected are 24.2.0, 24.2.1, 24.3.0, 25.1.100 and  25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Network Analytics Data Director accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Network Analytics Data Director accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Network Analytics Data Director.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Python)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the RDBMS (Python) component of Oracle Database Server.  Supported versions that are affected are 21.3-21.19 and  23.4-23.9. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with logon to the infrastructure where RDBMS (Python) executes to compromise RDBMS (Python).  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of RDBMS (Python).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Python)).  Supported versions that are affected are 24.2.7-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Policy.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14547V-25.1.200",
          "P-14547V-25.1.100",
          "P-5(RDBMS)V-21.3-21.19",
          "P-14277V-24.2.7-25.1.200",
          "P-14547V-24.2.0",
          "P-14974V-25.1.200",
          "P-14597V-6.1.0-6.1.1",
          "P-14547V-24.2.1",
          "P-14547V-24.3.0",
          "P-5(RDBMS)V-23.4-23.9",
          "P-14130V-25.1.200",
          "P-4627V-8.0.0-8.0.43",
          "P-10899V-9.1.0.0.0",
          "P-14121V-24.2.7-25.1.200",
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4627V-8.0.0-8.0.43"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14121V-24.2.7-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105418.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14974V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105407.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14130V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105448.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106893.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10899V-9.1.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105378.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-14547V-24.2.0",
            "P-14547V-24.2.1",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105450.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(RDBMS)V-21.3-21.19",
            "P-5(RDBMS)V-23.4-23.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-24.2.7-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105404.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-4517",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core DBTier",
          "text": "38183439"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38183449"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
          "text": "38183437"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38183448"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "38183447"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Workbench",
          "text": "38183431"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
          "text": "38183441"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
          "text": "38183446"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
          "text": "38183444"
        },
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "38183466"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (Python)).  Supported versions that are affected are 8.0.0-8.0.43. Easily exploitable vulnerability allows unauthenticated attacker with network access via MySQL Workbench to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Workbench accessible data as well as  unauthorized access to critical data or complete access to all MySQL Workbench accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Workbench. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Python)).  Supported versions that are affected are 24.2.7-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Binding Support Function accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (Python)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core DBTier accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core DBTier accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core DBTier. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Python)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Python)).  Supported versions that are affected are 24.2.7-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: ATS Framework (Python)).   The supported version that is affected is 9.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Diameter Signaling Router accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Diameter Signaling Router accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Porting (Python)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: ATS Framework (Python)).  Supported versions that are affected are 24.2.0, 24.2.1, 24.3.0, 25.1.100 and  25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Network Analytics Data Director accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Network Analytics Data Director accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Network Analytics Data Director. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Python)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the RDBMS (Python) component of Oracle Database Server.  Supported versions that are affected are 21.3-21.19 and  23.4-23.9. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with logon to the infrastructure where RDBMS (Python) executes to compromise RDBMS (Python).  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of RDBMS (Python). CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14547V-25.1.200",
          "P-14277V-24.2.7-25.1.200",
          "P-14547V-25.1.100",
          "P-5(RDBMS)V-21.3-21.19",
          "P-14547V-24.2.0",
          "P-14974V-25.1.200",
          "P-14597V-6.1.0-6.1.1",
          "P-14547V-24.2.1",
          "P-14547V-24.3.0",
          "P-5(RDBMS)V-23.4-23.9",
          "P-14130V-25.1.200",
          "P-4627V-8.0.0-8.0.43",
          "P-10899V-9.1.0.0.0",
          "P-14121V-24.2.7-25.1.200",
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4627V-8.0.0-8.0.43"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14121V-24.2.7-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105418.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14974V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105407.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14130V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105448.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-24.2.7-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105404.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10899V-9.1.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105378.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106893.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-14547V-24.2.0",
            "P-14547V-24.2.1",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105450.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(RDBMS)V-21.3-21.19",
            "P-5(RDBMS)V-23.4-23.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.4,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14547V-25.1.200",
            "P-14277V-24.2.7-25.1.200",
            "P-14547V-25.1.100",
            "P-14547V-24.2.0",
            "P-14974V-25.1.200",
            "P-14547V-24.2.1",
            "P-14547V-24.3.0",
            "P-14130V-25.1.200",
            "P-4627V-8.0.0-8.0.43",
            "P-10899V-9.1.0.0.0",
            "P-14121V-24.2.7-25.1.200",
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 6.7,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.1.0-6.1.1"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-5(RDBMS)V-21.3-21.19",
            "P-5(RDBMS)V-23.4-23.9"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-4575",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "38172368"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
          "text": "38168445"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Configuration (OpenSSL)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Certificate Management accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security, Porting, Cloud Deployment Architecture (OpenSSL)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.61",
          "P-14868V-25.1.200",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14868V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105451.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106893.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-47273",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-8478(Shell: Core Client)V-8.4.3-8.4.6",
            "P-8478(Shell: Core Client)V-9.1.0-9.4.0",
            "P-8478(Shell: Core Client)V-8.0.40-8.0.43"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Shell",
          "text": "38343861"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client (Python setuptools)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-8478(Shell: Core Client)V-8.4.3-8.4.6",
          "P-8478(Shell: Core Client)V-8.0.40-8.0.43",
          "P-8478(Shell: Core Client)V-9.1.0-9.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Shell: Core Client)V-8.4.3-8.4.6",
            "P-8478(Shell: Core Client)V-9.1.0-9.4.0",
            "P-8478(Shell: Core Client)V-8.0.40-8.0.43"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-8478(Shell: Core Client)V-8.4.3-8.4.6",
            "P-8478(Shell: Core Client)V-9.1.0-9.4.0",
            "P-8478(Shell: Core Client)V-8.0.40-8.0.43"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-8478(Shell: Core Client)V-8.4.3-8.4.6",
            "P-8478(Shell: Core Client)V-9.1.0-9.4.0",
            "P-8478(Shell: Core Client)V-8.0.40-8.0.43"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-4802",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
          "text": "38111256"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
          "text": "38308151"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (FreeType)).  Supported versions that are affected are 24.2.7-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Binding Support Function executes to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (glibc)).  Supported versions that are affected are 24.2.7-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Policy executes to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14121V-24.2.7-25.1.200",
          "P-14277V-24.2.7-25.1.200"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14121V-24.2.7-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105418.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-24.2.7-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105404.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14277V-24.2.7-25.1.200",
            "P-14121V-24.2.7-25.1.200"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-48734",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-2241V-2.5.0.1.15",
            "P-2241V-2.4.0.1.31",
            "P-14277V-24.2.7-25.1.200",
            "P-2241V-2.6.0.1.8",
            "P-10945V-12.2.0.4.0",
            "P-14015V-19.1.0.0.0-19.1.0.0.12",
            "P-2241V-2.6.0.2.3",
            "P-2241V-2.5.0.2.9"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Console",
          "text": "38012237"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Studio",
          "text": "38012314"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Insurance Policy Administration J2EE",
          "text": "38012347"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Stream Analytics",
          "text": "38012446"
        },
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "38012435"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
          "text": "38012236"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
          "text": "38012405"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Hospitality Cruise Shipboard Property Management (SPMS)",
          "text": "38012327"
        },
        {
          "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
          "text": "38012186"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Price Management",
          "text": "38012383"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Documaker",
          "text": "38012272"
        },
        {
          "system_name": "Oracle Bug ID of Retail Predictive Application Server",
          "text": "38012381"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Hyperion Infrastructure Technology",
          "text": "38012278"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Hyperion Planning",
          "text": "38012332"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
          "text": "38012243"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38012265"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Hyperion Calculation Manager",
          "text": "38012331"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Invoice Matching",
          "text": "38012375"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Solaris Cluster",
          "text": "38012396"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Utilities Network Management System",
          "text": "38012409"
        },
        {
          "system_name": "Oracle Bug ID of Oracle JDeveloper",
          "text": "38412388"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Configuration (Apache Commons BeanUtils)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Apache Commons BeanUtils)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Apache Commons BeanUtils)).   The supported version that is affected is 6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 6.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Documaker product of Oracle Insurance Applications (component: EWPS (Apache Commons BeanUtils)).  Supported versions that are affected are 12.7.2.4, 13.0.0.3 and  13.0.1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Documaker.  Successful attacks of this vulnerability can result in takeover of Oracle Documaker. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration (Apache Commons BeanUtils)).   The supported version that is affected is 11.2.22.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle GoldenGate Studio product of Oracle GoldenGate (component: GoldenGate Studio (Apache Commons BeanUtils)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management (SPMS) product of Oracle Hospitality Applications (component: Next-Gen SPMS (Apache Commons BeanUtils)).   The supported version that is affected is 23.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Cruise Shipboard Property Management (SPMS).  Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Cruise Shipboard Property Management (SPMS). CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security (Apache Commons BeanUtils)).   The supported version that is affected is 11.2.22.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Calculation Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Planning product of Oracle Hyperion (component: Security (Apache Commons BeanUtils)).   The supported version that is affected is 11.2.22.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Planning.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Planning. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Insurance Policy Administration J2EE product of Oracle Insurance Applications (component: Third Party (Apache Commons BeanUtils)).  Supported versions that are affected are 11.3.1-12.0.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Insurance Policy Administration J2EE.  Successful attacks of this vulnerability can result in takeover of Oracle Insurance Policy Administration J2EE. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Apache Commons BeanUtils)).  Supported versions that are affected are 24.2.7-25.1.200. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Portal Security (Apache Commons BeanUtils)).  Supported versions that are affected are 9.2.0.0-9.2.9.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Invoice Matching product of Oracle Retail Applications (component: Security (Apache Commons BeanUtils)).  Supported versions that are affected are 15.0.3.1 and  16.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Invoice Matching.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Invoice Matching. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF, ADF Faces (Apache Commons BeanUtils)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle JDeveloper.  Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle GoldenGate Stream Analytics product of Oracle GoldenGate (component: General Issues (Apache Commons BeanUtils)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal (Apache Commons BeanUtils)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Core (Apache Commons BeanUtils)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: Security (Apache Commons BeanUtils)).  Supported versions that are affected are 4.3.0.5.0, 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0, 4.4.0.3.0, 4.4.0.4.0, 4.5.0.0.0, 4.5.0.1.1, 4.5.0.1.3, 4.5.0.2.0, 24.2.0.0.0, 24.3.0.0.0, 25.4 and  25.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Utilities Application Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Application Framework. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Solaris Cluster product of Oracle Systems (component: Core (Apache Commons BeanUtils)).   The supported version that is affected is 4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Solaris Cluster.  Successful attacks of this vulnerability can result in takeover of Oracle Solaris Cluster. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Retail Predictive Application Server product of Oracle Retail Applications (component: Fusion Client (Apache Commons BeanUtils)).  Supported versions that are affected are 15.0.3 and  16.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Retail Predictive Application Server.  Successful attacks of this vulnerability can result in takeover of Retail Predictive Application Server. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Price Management product of Oracle Retail Applications (component: Security (Apache Commons BeanUtils)).  Supported versions that are affected are 15.0.3.1 and  16.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Price Management.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Price Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5477V-13.0.0.3",
          "P-10005V-4",
          "P-5477V-13.0.1.1",
          "P-2245V-4.3.0.6.0",
          "P-14250V-25.1.200",
          "P-2245V-4.4.0.0.0",
          "P-2245V-4.4.0.2.0",
          "P-2245V-4.4.0.3.0",
          "P-2245V-4.4.0.4.0",
          "P-1824V-15.0.3.1",
          "P-5279V-11.3.1-12.0.5",
          "P-1823V-15.0.3",
          "P-2245V-4.3.0.5.0",
          "P-14121V-24.2.7-25.1.200",
          "P-2245V-25.4",
          "P-4402V-11.2.22.0.000",
          "P-14597V-6.1.1",
          "P-4781V-9.2.0.0-9.2.9.4",
          "P-2245V-24.3.0.0.0",
          "P-2245V-4.5.0.1.1",
          "P-2245V-4.5.0.2.0",
          "P-5685V-11.2.22.0.000",
          "P-2245V-4.5.0.0.0",
          "P-1823V-16.0.3",
          "P-4392V-11.2.22.0.000",
          "P-1810V-16.0.3",
          "P-11607V-23.2.5",
          "P-1824V-16.0.3",
          "P-2245V-4.5.0.1.3",
          "P-2245V-25.10",
          "P-5477V-12.7.2.4",
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-1810V-15.0.3.1",
          "P-807V-12.2.1.4.0",
          "P-5085V-8.62",
          "P-2245V-24.2.0.0.0"
        ],
        "known_not_affected": [
          "P-2241V-2.5.0.1.15",
          "P-2241V-2.4.0.1.31",
          "P-14277V-24.2.7-25.1.200",
          "P-2241V-2.6.0.1.8",
          "P-10945V-12.2.0.4.0",
          "P-14015V-19.1.0.0.0-19.1.0.0.12",
          "P-2241V-2.6.0.2.3",
          "P-2241V-2.5.0.2.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14250V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105453.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-24.2.7-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105404.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5477V-13.0.0.3",
            "P-5477V-13.0.1.1",
            "P-5279V-11.3.1-12.0.5",
            "P-5477V-12.7.2.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3107101.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5685V-11.2.22.0.000",
            "P-4402V-11.2.22.0.000",
            "P-4392V-11.2.22.0.000"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2775466.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10945V-12.2.0.4.0",
            "P-14015V-19.1.0.0.0-19.1.0.0.12"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11607V-23.2.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106506.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14121V-24.2.7-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105418.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4781V-9.2.0.0-9.2.9.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106891.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1824V-15.0.3.1",
            "P-1823V-15.0.3",
            "P-1823V-16.0.3",
            "P-1810V-16.0.3",
            "P-1810V-15.0.3.1",
            "P-1824V-16.0.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104399.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-807V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105435.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106893.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2241V-2.6.0.1.8",
            "P-2245V-24.3.0.0.0",
            "P-2245V-4.5.0.1.1",
            "P-2245V-4.5.0.2.0",
            "P-2241V-2.6.0.2.3",
            "P-2245V-4.3.0.6.0",
            "P-2245V-4.5.0.0.0",
            "P-2245V-4.4.0.0.0",
            "P-2245V-4.4.0.2.0",
            "P-2241V-2.5.0.2.9",
            "P-2245V-4.4.0.3.0",
            "P-2245V-4.4.0.4.0",
            "P-2241V-2.5.0.1.15",
            "P-2241V-2.4.0.1.31",
            "P-2245V-4.3.0.5.0",
            "P-2245V-4.5.0.1.3",
            "P-2245V-25.4",
            "P-2245V-25.10",
            "P-2245V-24.2.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105252.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10005V-4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106603.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-5477V-13.0.0.3",
            "P-10005V-4",
            "P-5477V-13.0.1.1",
            "P-2245V-4.3.0.6.0",
            "P-14250V-25.1.200",
            "P-2245V-4.4.0.0.0",
            "P-2245V-4.4.0.2.0",
            "P-2245V-4.4.0.3.0",
            "P-2245V-4.4.0.4.0",
            "P-1824V-15.0.3.1",
            "P-5279V-11.3.1-12.0.5",
            "P-1823V-15.0.3",
            "P-2245V-4.3.0.5.0",
            "P-14121V-24.2.7-25.1.200",
            "P-2245V-25.4",
            "P-4402V-11.2.22.0.000",
            "P-4781V-9.2.0.0-9.2.9.4",
            "P-2245V-24.3.0.0.0",
            "P-2245V-4.5.0.1.1",
            "P-2245V-4.5.0.2.0",
            "P-5685V-11.2.22.0.000",
            "P-2245V-4.5.0.0.0",
            "P-1823V-16.0.3",
            "P-4392V-11.2.22.0.000",
            "P-1810V-16.0.3",
            "P-11607V-23.2.5",
            "P-1824V-16.0.3",
            "P-2245V-4.5.0.1.3",
            "P-2245V-25.10",
            "P-5477V-12.7.2.4",
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-1810V-15.0.3.1",
            "P-807V-12.2.1.4.0",
            "P-5085V-8.62",
            "P-2245V-24.2.0.0.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-2241V-2.5.0.1.15",
            "P-2241V-2.4.0.1.31",
            "P-14277V-24.2.7-25.1.200",
            "P-2241V-2.6.0.1.8",
            "P-10945V-12.2.0.4.0",
            "P-14015V-19.1.0.0.0-19.1.0.0.12",
            "P-2241V-2.6.0.2.3",
            "P-2241V-2.5.0.2.9"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 6.8,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.1.1"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-2241V-2.5.0.1.15",
            "P-2241V-2.4.0.1.31",
            "P-14277V-24.2.7-25.1.200",
            "P-2241V-2.6.0.1.8",
            "P-10945V-12.2.0.4.0",
            "P-14015V-19.1.0.0.0-19.1.0.0.12",
            "P-2241V-2.6.0.2.3",
            "P-2241V-2.5.0.2.9"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-4877",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Workbench",
          "text": "38263939"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
          "text": "38263979"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Security (libssh)).  Supported versions that are affected are 7.7.0 and  7.8.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Inventory Management accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Inventory Management accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (libssh)).  Supported versions that are affected are 8.0.0-8.0.43. Easily exploitable vulnerability allows low privileged attacker with network access via MySQL Workbench to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Workbench accessible data as well as  unauthorized read access to a subset of MySQL Workbench accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4627V-8.0.0-8.0.43",
          "P-4516V-7.7.0",
          "P-4516V-7.8.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.7.0",
            "P-4516V-7.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105322.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4627V-8.0.0-8.0.43"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-4878",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Workbench",
          "text": "38263939"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
          "text": "38263979"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Security (libssh)).  Supported versions that are affected are 7.7.0 and  7.8.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Inventory Management accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Inventory Management accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (libssh)).  Supported versions that are affected are 8.0.0-8.0.43. Easily exploitable vulnerability allows low privileged attacker with network access via MySQL Workbench to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Workbench accessible data as well as  unauthorized read access to a subset of MySQL Workbench accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4627V-8.0.0-8.0.43",
          "P-4516V-7.7.0",
          "P-4516V-7.8.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.7.0",
            "P-4516V-7.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105322.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4627V-8.0.0-8.0.43"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-48795",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Commerce Platform",
          "text": "38295206"
        },
        {
          "system_name": "Oracle Bug ID of Oracle WebCenter Forms Recognition",
          "text": "38237603"
        },
        {
          "system_name": "Oracle Bug ID of Oracle BI Publisher",
          "text": "38237571"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebCenter Forms Recognition product of Oracle Fusion Middleware (component: ALE Learnset Manager (Apache CXF)).   The supported version that is affected is 14.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Forms Recognition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebCenter Forms Recognition accessible data as well as  unauthorized read access to a subset of Oracle WebCenter Forms Recognition accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Forms Recognition. CVSS 3.1 Base Score 5.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API (Apache CXF)).  Supported versions that are affected are 7.6.0.0.0 and  8.2.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data as well as  unauthorized read access to a subset of Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 5.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Endeca Integration (Apache CXF)).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Commerce Platform.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Commerce Platform accessible data as well as  unauthorized read access to a subset of Oracle Commerce Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Platform. CVSS 3.1 Base Score 4.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9348V-11.4.0",
          "P-5746V-14.1.1.0.0",
          "P-1479V-8.2.0.0.0",
          "P-1479V-7.6.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5746V-14.1.1.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105435.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1479V-7.6.0.0.0",
            "P-1479V-8.2.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105456.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9348V-11.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106894.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.6,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "P-1479V-7.6.0.0.0",
            "P-5746V-14.1.1.0.0",
            "P-1479V-8.2.0.0.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 4.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "P-9348V-11.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-48924",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-5760V-23.4-23.9",
            "P-4379V-21.7.3.0.0"
          ]
        },
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-13600V-25.1.2",
            "P-13600V-24.2.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Model Management and Governance",
          "text": "38420977"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
          "text": "38420958"
        },
        {
          "system_name": "Oracle Bug ID of Oracle WebCenter Forms Recognition",
          "text": "38421105"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Spatial Studio",
          "text": "38420853"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
          "text": "38420998"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Merchandising System",
          "text": "38421009"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Enterprise Data Quality",
          "text": "38420892"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
          "text": "38421002"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
          "text": "38421264"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
          "text": "38421023"
        },
        {
          "system_name": "Oracle Bug ID of Primavera Gateway",
          "text": "38421050"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Convergence",
          "text": "38421271"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
          "text": "38421030"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
          "text": "38421272"
        },
        {
          "system_name": "Oracle Bug ID of Primavera Unifier",
          "text": "38287119"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38345608"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
          "text": "38237119"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Integrity",
          "text": "38328349"
        },
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise CS Financial Aid",
          "text": "38459876"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Hospitality Cruise Shipboard Property Management (SPMS)",
          "text": "38228215"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Service Backbone",
          "text": "38421018"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
          "text": "38270554"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Behavior Detection Platform",
          "text": "38420964"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters",
          "text": "38326187"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
          "text": "38420965"
        },
        {
          "system_name": "Oracle Bug ID of Oracle WebLogic Server",
          "text": "38205530"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Healthcare Data Repository",
          "text": "38421134"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Offline Mediation Controller",
          "text": "38421277"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Order and Service Management",
          "text": "38421278"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Healthcare Master Person Index",
          "text": "38421136"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Messaging Server",
          "text": "38421274"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Calendar Server",
          "text": "38421034"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Sales Audit",
          "text": "38421181"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition",
          "text": "38421041"
        },
        {
          "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
          "text": "38420909"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Essbase",
          "text": "38258747"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Apache Commons Lang)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management (SPMS) product of Oracle Hospitality Applications (component: Next-Gen SPMS (Apache Commons Lang)).   The supported version that is affected is 23.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Cruise Shipboard Property Management (SPMS).  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hospitality Cruise Shipboard Property Management (SPMS). CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications Applications (component: Solution Designer (Apache Commons Lang)).  Supported versions that are affected are 8.0.0.5.0, 8.1.0.4.0 and  8.2.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Service Catalog and Design. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle Essbase (component: Security and Provisioning (Apache Commons Lang)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Security (Apache Commons Lang)).  Supported versions that are affected are 7.5.0-7.5.1 and  7.6.0-7.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform (Apache Commons Lang)).  Supported versions that are affected are 20.12.0-20.12.16, 21.12.0-21.12.17, 22.12.0-22.12.15, 23.12.0-23.12.15 and  24.12.0-24.12.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Primavera Unifier. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: Java Delivery (Apache Commons Lang)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Integrity product of Oracle Communications Applications (component: Cartridges (Apache Commons Lang)).  Supported versions that are affected are 7.3.6, 7.4.0 and  7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Integrity.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Network Integrity. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Microservices (Apache Commons Lang)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle Spatial Studio (component: Install issues (Apache Commons Lang)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Enterprise Data Quality product of Oracle Fusion Middleware (component: General (Apache Commons Lang)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Data Quality.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Data Quality. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portal, Analytics and REST (Apache Commons Lang)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform (Apache Commons Lang)).  Supported versions that are affected are 8.0.7.9, 8.0.8.7 and  8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Financial Services Analytical Applications Infrastructure. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Third Party (Apache Commons Lang)).  Supported versions that are affected are 8.0.8.1, 8.1.2.9 and  8.1.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Financial Services Behavior Detection Platform. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Apache Commons Lang)).   The supported version that is affected is 8.1.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Financial Services Compliance Studio. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Apache Commons Lang)).  Supported versions that are affected are 8.1.2.7 and  8.1.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Model Management and Governance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Financial Services Model Management and Governance. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration Bugs (Apache Commons Lang)).  Supported versions that are affected are 14.1.3.2, 15.0.3.1, 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Financial Integration. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Apache Commons Lang)).  Supported versions that are affected are 14.1.3.2, 15.0.3.1, 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Integration Bus. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Merchandising System product of Oracle Retail Applications (component: Foundation (Apache Commons Lang)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Merchandising System.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Merchandising System. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (Apache Commons Lang)).  Supported versions that are affected are 14.1.3.2, 15.0.3.1, 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Service Backbone. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Apache Commons Lang)).  Supported versions that are affected are 20.0.5, 21.0.4, 22.0.2, 23.0.2, 24.0.1 and  25.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Tools And Frameworks, Content Acquisition System, Platform Services (Apache Commons Lang)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search. CVSS 3.1 Base Score 2.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Calendar Server product of Oracle Communications Applications (component: Administration (Apache Commons Lang)).   The supported version that is affected is 8.0.0.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Calendar Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Calendar Server. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition product of Oracle Financial Services Applications (component: Platform (Apache Commons Lang)).   The supported version that is affected is 8.0.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Primavera Gateway product of Oracle Construction and Engineering (component: Admin (Apache Commons Lang)).  Supported versions that are affected are 20.12.0-20.12.17 and  21.12.0-21.12.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Gateway.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Primavera Gateway. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebCenter Forms Recognition product of Oracle Fusion Middleware (component: ALE Learnset Manager (Apache Commons Lang)).   The supported version that is affected is 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Forms Recognition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Forms Recognition. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Healthcare Data Repository product of Oracle HealthCare Applications (component: FHIR Server (Apache Commons Lang)).   The supported version that is affected is 8.2.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Data Repository.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Healthcare Data Repository. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Healthcare Master Person Index product of Oracle HealthCare Applications (component: Master Index Data Manager (Apache Commons Lang)).  Supported versions that are affected are 5.0.0.0-5.0.9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Master Person Index.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Healthcare Master Person Index. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Sales Audit product of Oracle Retail Applications (component: Security (Apache Commons Lang)).  Supported versions that are affected are 15.0.3.1, 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Sales Audit.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Sales Audit. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Signaling (Apache Commons Lang)).  Supported versions that are affected are 24.2.5 and  25.1.202. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Convergence product of Oracle Communications Applications (component: Configuration (Apache Commons Lang)).   The supported version that is affected is 3.0.3.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Convergence.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Convergence. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Automated Test Suite (Apache Commons Lang)).   The supported version that is affected is 9.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Messaging Server product of Oracle Communications Applications (component: Security (Apache Tika)).   The supported version that is affected is 8.1.0.28. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Messaging Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Messaging Server. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Offline Mediation Controller product of Oracle Communications Applications (component: Install (Swagger UI)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0 and  15.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Offline Mediation Controller.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Offline Mediation Controller. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security (Apache Commons Lang)).  Supported versions that are affected are 7.4.0, 7.4.1 and  7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Order and Service Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Order and Service Management. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: FM Need Analysis Calculator (Apache Commons Lang)).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Financial Aid.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise CS Financial Aid. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10867V-15.0.3.1",
          "P-10722V-15.0.3.1",
          "P-13789V-8.0.8",
          "P-1807V-19.0.1",
          "P-2270V-7.4.0",
          "P-2270V-7.4.1",
          "P-9190V-8.1.2.10",
          "P-11513V-20.0.5",
          "P-4491V-7.5.0",
          "P-9161V-8.2.0.5",
          "P-9190V-8.0.8.1",
          "P-4491V-7.3.6",
          "P-1834V-16.0.3",
          "P-5242V-12.2.1.4.0",
          "P-9633(Tools And Frameworks, Content Acquisition System, Platform Services)V-11.4.0",
          "P-9464V-12.2.1.4.0",
          "P-1807V-14.1.3.2",
          "P-14276V-8.1.2.7",
          "P-8575V-5.0.0.0-5.0.9.2",
          "P-11513V-22.0.2",
          "P-9190V-8.1.2.9",
          "P-2269V-15.0.1.0.0",
          "P-14597V-6.1.0-6.1.1",
          "P-9464V-14.1.2.0.0",
          "P-11607V-23.2.5",
          "P-10354V-24.12.0-24.12.9",
          "P-10354V-23.12.0-23.12.15",
          "P-5680V-8.1.2.5",
          "P-14118(Signaling)V-24.2.5",
          "P-10867V-16.0.3",
          "P-2283V-8.0.0.5.0",
          "P-4516V-7.6.0-7.8.0",
          "P-1807V-15.0.3.1",
          "P-10354V-21.12.0-21.12.17",
          "P-10605V-20.12.0-20.12.17",
          "P-5680V-8.0.8.7",
          "P-11513V-21.0.4",
          "P-1816V-19.0.1",
          "P-2269V-15.1.0.0.0",
          "P-4516V-7.5.0-7.5.1",
          "P-8496V-8.1.0.28",
          "P-10722V-19.0.1",
          "P-11513V-25.0.0",
          "P-14118(Signaling)V-25.1.202",
          "P-2270V-7.5.0",
          "P-1816V-16.0.3",
          "P-1696V-12.2.1.4.0",
          "P-8494V-8.0.0.7.0",
          "P-5178V-9.2",
          "P-4491V-7.4.0",
          "P-14392V-8.1.2.8",
          "P-11513V-24.0.1",
          "P-8501V-3.0.3.3.0",
          "P-2269V-15.0.0.0.0",
          "P-11513V-23.0.2",
          "P-5746V-14.1.1.0.0",
          "P-14276V-8.1.3.2",
          "P-10867V-19.0.1",
          "P-2283V-8.1.0.4.0",
          "P-1834V-15.0.3.1",
          "P-10867V-14.1.3.2",
          "P-10722V-14.1.3.2",
          "P-10722V-16.0.3",
          "P-1807V-16.0.3",
          "P-10354V-20.12.0-20.12.16",
          "P-10354V-22.12.0-22.12.15",
          "P-1834V-19.0.1",
          "P-10605V-21.12.0-21.12.15",
          "P-2283V-8.2.0.1.0",
          "P-5680V-8.0.7.9",
          "P-10899V-9.0.0.0.0"
        ],
        "known_not_affected": [
          "P-4379V-21.7.3.0.0",
          "P-13600V-24.2.0",
          "P-5760V-23.4-23.9",
          "P-13600V-25.1.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5242V-12.2.1.4.0",
            "P-9464V-12.2.1.4.0",
            "P-1696V-12.2.1.4.0",
            "P-5746V-14.1.1.0.0",
            "P-9464V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105435.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11607V-23.2.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106506.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2283V-8.0.0.5.0",
            "P-2283V-8.2.0.1.0",
            "P-2283V-8.1.0.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105310.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5760V-23.4-23.9",
            "P-13600V-25.1.2",
            "P-4379V-21.7.3.0.0",
            "P-13600V-24.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.6.0-7.8.0",
            "P-4516V-7.5.0-7.5.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105322.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10354V-20.12.0-20.12.16",
            "P-10354V-22.12.0-22.12.15",
            "P-10354V-23.12.0-23.12.15",
            "P-10605V-21.12.0-21.12.15",
            "P-10354V-21.12.0-21.12.17",
            "P-10605V-20.12.0-20.12.17",
            "P-10354V-24.12.0-24.12.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106664.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4491V-7.4.0",
            "P-4491V-7.5.0",
            "P-4491V-7.3.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105309.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.7.9",
            "P-5680V-8.0.8.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104221.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9190V-8.1.2.9",
            "P-9190V-8.0.8.1",
            "P-9190V-8.1.2.10"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105116.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14392V-8.1.2.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106412.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14276V-8.1.2.7",
            "P-14276V-8.1.3.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106757.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10867V-15.0.3.1",
            "P-10722V-15.0.3.1",
            "P-10722V-19.0.1",
            "P-1807V-19.0.1",
            "P-11513V-25.0.0",
            "P-11513V-22.0.2",
            "P-1834V-15.0.3.1",
            "P-10867V-14.1.3.2",
            "P-1816V-16.0.3",
            "P-10722V-14.1.3.2",
            "P-10722V-16.0.3",
            "P-11513V-20.0.5",
            "P-1807V-16.0.3",
            "P-10867V-16.0.3",
            "P-1834V-19.0.1",
            "P-1807V-15.0.3.1",
            "P-11513V-24.0.1",
            "P-11513V-23.0.2",
            "P-1834V-16.0.3",
            "P-1807V-14.1.3.2",
            "P-10867V-19.0.1",
            "P-11513V-21.0.4",
            "P-1816V-19.0.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104399.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9633(Tools And Frameworks, Content Acquisition System, Platform Services)V-11.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106894.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8496V-8.1.0.28",
            "P-8501V-3.0.3.3.0",
            "P-8494V-8.0.0.7.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105321.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13789V-8.0.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105187.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8575V-5.0.0.0-5.0.9.2",
            "P-9161V-8.2.0.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106837.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14118(Signaling)V-24.2.5",
            "P-14118(Signaling)V-25.1.202"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3107682.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10899V-9.0.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105378.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2269V-15.0.1.0.0",
            "P-2269V-15.0.0.0.0",
            "P-2269V-15.1.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105311.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2270V-7.4.0",
            "P-2270V-7.4.1",
            "P-2270V-7.5.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105308.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5178V-9.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106893.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-10867V-15.0.3.1",
            "P-10722V-15.0.3.1",
            "P-13789V-8.0.8",
            "P-1807V-19.0.1",
            "P-2270V-7.4.0",
            "P-2270V-7.4.1",
            "P-9190V-8.1.2.10",
            "P-11513V-20.0.5",
            "P-4491V-7.5.0",
            "P-9161V-8.2.0.5",
            "P-9190V-8.0.8.1",
            "P-4491V-7.3.6",
            "P-1834V-16.0.3",
            "P-5242V-12.2.1.4.0",
            "P-9464V-12.2.1.4.0",
            "P-1807V-14.1.3.2",
            "P-14276V-8.1.2.7",
            "P-8575V-5.0.0.0-5.0.9.2",
            "P-11513V-22.0.2",
            "P-9190V-8.1.2.9",
            "P-2269V-15.0.1.0.0",
            "P-14597V-6.1.0-6.1.1",
            "P-9464V-14.1.2.0.0",
            "P-11607V-23.2.5",
            "P-10354V-24.12.0-24.12.9",
            "P-10354V-23.12.0-23.12.15",
            "P-5680V-8.1.2.5",
            "P-14118(Signaling)V-24.2.5",
            "P-10867V-16.0.3",
            "P-2283V-8.0.0.5.0",
            "P-4516V-7.6.0-7.8.0",
            "P-1807V-15.0.3.1",
            "P-10354V-21.12.0-21.12.17",
            "P-10605V-20.12.0-20.12.17",
            "P-5680V-8.0.8.7",
            "P-11513V-21.0.4",
            "P-1816V-19.0.1",
            "P-2269V-15.1.0.0.0",
            "P-4516V-7.5.0-7.5.1",
            "P-8496V-8.1.0.28",
            "P-10722V-19.0.1",
            "P-11513V-25.0.0",
            "P-14118(Signaling)V-25.1.202",
            "P-2270V-7.5.0",
            "P-1816V-16.0.3",
            "P-1696V-12.2.1.4.0",
            "P-8494V-8.0.0.7.0",
            "P-5178V-9.2",
            "P-4491V-7.4.0",
            "P-14392V-8.1.2.8",
            "P-11513V-24.0.1",
            "P-8501V-3.0.3.3.0",
            "P-2269V-15.0.0.0.0",
            "P-11513V-23.0.2",
            "P-5746V-14.1.1.0.0",
            "P-14276V-8.1.3.2",
            "P-10867V-19.0.1",
            "P-2283V-8.1.0.4.0",
            "P-1834V-15.0.3.1",
            "P-10867V-14.1.3.2",
            "P-10722V-14.1.3.2",
            "P-10722V-16.0.3",
            "P-1807V-16.0.3",
            "P-10354V-20.12.0-20.12.16",
            "P-10354V-22.12.0-22.12.15",
            "P-1834V-19.0.1",
            "P-10605V-21.12.0-21.12.15",
            "P-2283V-8.2.0.1.0",
            "P-5680V-8.0.7.9",
            "P-10899V-9.0.0.0.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-13600V-25.1.2",
            "P-4379V-21.7.3.0.0",
            "P-13600V-24.2.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5760V-23.4-23.9"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 2.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-9633(Tools And Frameworks, Content Acquisition System, Platform Services)V-11.4.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-5760V-23.4-23.9",
            "P-4379V-21.7.3.0.0"
          ]
        },
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-13600V-25.1.2",
            "P-13600V-24.2.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-48976",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition",
          "text": "38200212"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Transportation Management",
          "text": "38200278"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Fusion Middleware MapViewer",
          "text": "38200252"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Hyperion Calculation Manager",
          "text": "38189957"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
          "text": "38189936"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
          "text": "38183595"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Stream Analytics",
          "text": "38201505"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Documaker",
          "text": "38189956"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Contacts Server",
          "text": "38189939"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
          "text": "38189937"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
          "text": "38189938"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
          "text": "38200280"
        },
        {
          "system_name": "Oracle Bug ID of Primavera Unifier",
          "text": "38200300"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Merchandising System",
          "text": "38200262"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Application Testing Suite",
          "text": "38183584"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Calendar Server",
          "text": "38189925"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "38189945"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
          "text": "38183600"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications EAGLE Element Management System",
          "text": "38189942"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Insurance Policy Administration J2EE",
          "text": "38200249"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Commerce Platform",
          "text": "38317688"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Convergence",
          "text": "38189940"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Model Management and Governance",
          "text": "38189984"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
          "text": "38189963"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Branch",
          "text": "38183607"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
          "text": "38200270"
        },
        {
          "system_name": "Oracle Bug ID of Oracle REST Data Services",
          "text": "38194276"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Application Testing Suite product of Oracle Enterprise Manager (component: Load Testing for Web Apps (Apache Commons FileUpload)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Testing Suite.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Application Testing Suite. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework (Apache Commons FileUpload)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Platform. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security (Apache Commons FileUpload)).  Supported versions that are affected are 7.6.0.0.0, 8.2.0.0.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports (Apache Commons FileUpload)).  Supported versions that are affected are 14.5.0.0.0-14.8.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Branch.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Branch. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Calendar Server product of Oracle Communications Applications (component: Core (Apache Commons FileUpload)).   The supported version that is affected is 8.0.0.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Calendar Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Calendar Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Automated Test Suite (Apache Commons FileUpload)).  Supported versions that are affected are 24.2.5 and  25.1.201. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Automated Test Suite Framework (Apache Commons FileUpload)).  Supported versions that are affected are 25.1.200 and  25.2.100. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Automated Test Suite Framework (Apache Commons FileUpload)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Contacts Server product of Oracle Communications Applications (component: Core (Apache Commons FileUpload)).   The supported version that is affected is 8.0.0.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Contacts Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Contacts Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Convergence product of Oracle Communications Applications (component: Core (Apache Commons FileUpload)).   The supported version that is affected is 3.0.3.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Convergence.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Convergence. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications EAGLE Element Management System product of Oracle Communications (component: Security (Apache Commons FileUpload)).   The supported version that is affected is 47.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Element Management System.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications EAGLE Element Management System. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Automated Test Suite (Apache Commons FileUpload)).  Supported versions that are affected are 24.2.0-24.2.1, 24.3.0, 25.1.100 and  25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Analytics Data Director. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Documaker product of Oracle Insurance Applications (component: Docupresentment (Apache Commons FileUpload)).  Supported versions that are affected are 12.7.2.4, 13.0.0.3 and  13.0.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Documaker.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Documaker. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security (Apache Commons FileUpload)).   The supported version that is affected is 11.2.22.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Calculation Manager. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform (Apache Commons FileUpload)).  Supported versions that are affected are 8.0.7.9, 8.0.8.7 and  8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Analytical Applications Infrastructure. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Apache Commons FileUpload)).  Supported versions that are affected are 8.1.2.7 and  8.1.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Model Management and Governance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Model Management and Governance. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in Oracle REST Data Services (component: Core (Apache Commons FileUpload)).   The supported version that is affected is 25.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle REST Data Services.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle REST Data Services. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition product of Oracle Financial Services Applications (component: Platform (Apache Commons FileUpload)).   The supported version that is affected is 8.0.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Insurance Policy Administration J2EE product of Oracle Insurance Applications (component: Architecture (Apache Commons FileUpload)).  Supported versions that are affected are 11.3.1-12.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration J2EE.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Insurance Policy Administration J2EE. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Fusion Middleware MapViewer product of Oracle Fusion Middleware (component: Install (Apache Commons FileUpload)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Fusion Middleware MapViewer.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Fusion Middleware MapViewer. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Merchandising System product of Oracle Retail Applications (component: Foundation (Apache Commons FileUpload)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Merchandising System.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Merchandising System. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Apache Commons FileUpload)).  Supported versions that are affected are 20.0.5, 21.0.4, 22.0.2, 23.0.2 and  24.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Install (Apache Commons FileUpload)).   The supported version that is affected is 6.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Transportation Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Transportation Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: Security (Apache Commons FileUpload)).  Supported versions that are affected are 4.3.0.5.0, 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0, 4.4.0.3.0, 4.4.0.4.0, 4.5.0.0.0, 4.5.0.1.1, 4.5.0.1.3, 4.5.0.2.0, 24.2.0.0.0, 24.3.0.0.0, 25.4 and  25.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Application Framework.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Application Framework. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Document Management (Apache Commons FileUpload)).  Supported versions that are affected are 20.12.0-20.12.16, 21.12.0-21.12.17, 22.12.0-22.12.15, 23.12.0-23.12.15 and  24.12.0-24.12.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Primavera Unifier. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle GoldenGate Stream Analytics product of Oracle GoldenGate (component: General (Apache Commons FileUpload)).  Supported versions that are affected are 19.1.0.0.0-19.1.0.0.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate Stream Analytics.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GoldenGate Stream Analytics. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Thirdparty Patch (Apache Commons FileUpload)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Middleware Common Libraries and Tools. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5477V-13.0.1.1",
          "P-13789V-8.0.8",
          "P-8501V-3.0.3.4.0",
          "P-2025V-8.2.0.0.0",
          "P-14547V-24.3.0",
          "P-4622V-14.1.1.0.0",
          "P-8494V-8.0.0.8.0",
          "P-2245V-4.3.0.6.0",
          "P-11513V-20.0.5",
          "P-2245V-4.4.0.3.0",
          "P-4622V-14.1.2.0.0",
          "P-5279V-11.3.1-12.0.5",
          "P-9456V-25.2.1",
          "P-9348V-11.4.0",
          "P-14547V-24.2.0-24.2.1",
          "P-14276V-8.1.2.7",
          "P-11125V-47.0",
          "P-14117V-25.1.200",
          "P-10696V-8.0.0.9.0",
          "P-14547V-25.1.100",
          "P-11513V-22.0.2",
          "P-2245V-24.3.0.0.0",
          "P-1215V-12.2.1.4.0",
          "P-2245V-4.5.0.2.0",
          "P-2245V-4.5.0.0.0",
          "P-10354V-24.12.0-24.12.9",
          "P-14123V-25.1.201",
          "P-5680V-8.1.2.5",
          "P-10354V-23.12.0-23.12.15",
          "P-10354V-21.12.0-21.12.17",
          "P-14015V-19.1.0.0.0-19.1.0.0.12",
          "P-2245V-25.10",
          "P-5477V-12.7.2.4",
          "P-5680V-8.0.8.7",
          "P-11513V-21.0.4",
          "P-1816V-19.0.1",
          "P-5477V-13.0.0.3",
          "P-2025V-7.6.0.0.0",
          "P-1816V-16.0.3",
          "P-2245V-4.4.0.0.0",
          "P-14123V-24.2.5",
          "P-2245V-4.4.0.2.0",
          "P-2245V-4.4.0.4.0",
          "P-14117V-25.2.100",
          "P-2245V-4.3.0.5.0",
          "P-11513V-24.0.1",
          "P-11513V-23.0.2",
          "P-2245V-25.4",
          "P-14119V-25.1.200",
          "P-14276V-8.1.3.2",
          "P-1991V-6.5.3",
          "P-4622V-12.2.1.4.0",
          "P-2025V-12.2.1.4.0",
          "P-14547V-25.1.200",
          "P-4647V-14.1.2.0.0",
          "P-2245V-4.5.0.1.1",
          "P-5685V-11.2.22.0.000",
          "P-10354V-20.12.0-20.12.16",
          "P-10354V-22.12.0-22.12.15",
          "P-2245V-4.5.0.1.3",
          "P-4647V-12.2.1.4.0",
          "P-5680V-8.0.7.9",
          "P-14324V-14.5.0.0.0-14.8.0.0.0",
          "P-2245V-24.2.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4622V-12.2.1.4.0",
            "P-4622V-14.1.2.0.0",
            "P-4622V-14.1.1.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102566.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9348V-11.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106894.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2025V-12.2.1.4.0",
            "P-2025V-7.6.0.0.0",
            "P-2025V-8.2.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105456.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14324V-14.5.0.0.0-14.8.0.0.0"
          ],
          "url": "https://support.oracle.com"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10696V-8.0.0.9.0",
            "P-8501V-3.0.3.4.0",
            "P-8494V-8.0.0.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105321.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14123V-24.2.5",
            "P-14123V-25.1.201"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105449.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14117V-25.2.100",
            "P-14117V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105421.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14119V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105405.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11125V-47.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105423.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-24.2.0-24.2.1",
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105450.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5477V-13.0.0.3",
            "P-5477V-13.0.1.1",
            "P-5279V-11.3.1-12.0.5",
            "P-5477V-12.7.2.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3107101.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5685V-11.2.22.0.000"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2775466.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.7.9",
            "P-5680V-8.0.8.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104221.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14276V-8.1.2.7",
            "P-14276V-8.1.3.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106757.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9456V-25.2.1",
            "P-14015V-19.1.0.0.0-19.1.0.0.12"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13789V-8.0.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105187.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4647V-14.1.2.0.0",
            "P-1215V-12.2.1.4.0",
            "P-4647V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105435.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11513V-22.0.2",
            "P-11513V-24.0.1",
            "P-11513V-23.0.2",
            "P-1816V-16.0.3",
            "P-11513V-21.0.4",
            "P-1816V-19.0.1",
            "P-11513V-20.0.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104399.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1991V-6.5.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106892.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2245V-24.3.0.0.0",
            "P-2245V-4.5.0.1.1",
            "P-2245V-4.5.0.2.0",
            "P-2245V-4.3.0.6.0",
            "P-2245V-4.5.0.0.0",
            "P-2245V-4.4.0.0.0",
            "P-2245V-4.4.0.2.0",
            "P-2245V-4.4.0.3.0",
            "P-2245V-4.4.0.4.0",
            "P-2245V-4.3.0.5.0",
            "P-2245V-4.5.0.1.3",
            "P-2245V-25.4",
            "P-2245V-25.10",
            "P-2245V-24.2.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105252.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10354V-20.12.0-20.12.16",
            "P-10354V-22.12.0-22.12.15",
            "P-10354V-23.12.0-23.12.15",
            "P-10354V-21.12.0-21.12.17",
            "P-10354V-24.12.0-24.12.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106664.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-5477V-13.0.1.1",
            "P-13789V-8.0.8",
            "P-8501V-3.0.3.4.0",
            "P-2025V-8.2.0.0.0",
            "P-14547V-24.3.0",
            "P-4622V-14.1.1.0.0",
            "P-8494V-8.0.0.8.0",
            "P-2245V-4.3.0.6.0",
            "P-11513V-20.0.5",
            "P-2245V-4.4.0.3.0",
            "P-4622V-14.1.2.0.0",
            "P-5279V-11.3.1-12.0.5",
            "P-9348V-11.4.0",
            "P-14547V-24.2.0-24.2.1",
            "P-14276V-8.1.2.7",
            "P-11125V-47.0",
            "P-14117V-25.1.200",
            "P-10696V-8.0.0.9.0",
            "P-14547V-25.1.100",
            "P-11513V-22.0.2",
            "P-2245V-24.3.0.0.0",
            "P-1215V-12.2.1.4.0",
            "P-2245V-4.5.0.2.0",
            "P-2245V-4.5.0.0.0",
            "P-10354V-24.12.0-24.12.9",
            "P-14123V-25.1.201",
            "P-5680V-8.1.2.5",
            "P-10354V-23.12.0-23.12.15",
            "P-10354V-21.12.0-21.12.17",
            "P-2245V-25.10",
            "P-5477V-12.7.2.4",
            "P-5680V-8.0.8.7",
            "P-11513V-21.0.4",
            "P-1816V-19.0.1",
            "P-5477V-13.0.0.3",
            "P-2025V-7.6.0.0.0",
            "P-1816V-16.0.3",
            "P-2245V-4.4.0.0.0",
            "P-14123V-24.2.5",
            "P-2245V-4.4.0.2.0",
            "P-2245V-4.4.0.4.0",
            "P-14117V-25.2.100",
            "P-2245V-4.3.0.5.0",
            "P-11513V-24.0.1",
            "P-11513V-23.0.2",
            "P-2245V-25.4",
            "P-14119V-25.1.200",
            "P-14276V-8.1.3.2",
            "P-1991V-6.5.3",
            "P-4622V-12.2.1.4.0",
            "P-2025V-12.2.1.4.0",
            "P-14547V-25.1.200",
            "P-4647V-14.1.2.0.0",
            "P-2245V-4.5.0.1.1",
            "P-5685V-11.2.22.0.000",
            "P-10354V-20.12.0-20.12.16",
            "P-10354V-22.12.0-22.12.15",
            "P-2245V-4.5.0.1.3",
            "P-4647V-12.2.1.4.0",
            "P-5680V-8.0.7.9",
            "P-14324V-14.5.0.0.0-14.8.0.0.0",
            "P-2245V-24.2.0.0.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-9456V-25.2.1"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14015V-19.1.0.0.0-19.1.0.0.12"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-48988",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Siebel CRM End User",
          "text": "38092672"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
          "text": "38313397"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: User Interface (Apache Tomcat)).  Supported versions that are affected are Prior to 25.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM End User.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM End User. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Apache Tomcat)).   The supported version that is affected is 24.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9011V-Prior to 25.10",
          "P-11513V-24.0.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9011V-Prior to 25.10"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106900.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11513V-24.0.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104399.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-9011V-Prior to 25.10"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-48989",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-5(Database)V-21.3-21.19",
            "P-5(Database)V-19.3-19.28"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38311920"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Hospitality Cruise Shipboard Property Management (SPMS)",
          "text": "38313394"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Xstore Office",
          "text": "38351021"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Model Management and Governance",
          "text": "38313392"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38313388"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
          "text": "38313397"
        },
        {
          "system_name": "Oracle Bug ID of Management Cloud Engine",
          "text": "38313367"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
          "text": "38313379"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Database (Apache Tomcat) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Management Cloud Engine product of Oracle Communications (component: BEServer (Apache Tomcat)).   The supported version that is affected is 25.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Management Cloud Engine.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Management Cloud Engine. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Tools And Frameworks, Content Acquisition System, Platform Services (Apache Tomcat)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP/2 to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Apache Tomcat)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP/2 to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 4.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Apache Tomcat)).  Supported versions that are affected are 8.1.2.7 and  8.1.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Financial Services Model Management and Governance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Model Management and Governance. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management (SPMS) product of Oracle Hospitality Applications (component: Next-Gen SPMS (Apache Tomcat)).   The supported version that is affected is 23.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Hospitality Cruise Shipboard Property Management (SPMS).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Cruise Shipboard Property Management (SPMS). CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security (Apache Tomcat)).  Supported versions that are affected are 20.0.5, 21.0.4, 22.0.2, 23.0.2, 24.0.1 and  25.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Retail Xstore Office.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Office. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Apache Tomcat)).   The supported version that is affected is 24.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14276V-8.1.2.7",
          "P-11560V-24.0.1",
          "P-11560V-20.0.5",
          "P-14597V-6.1.0-6.1.1",
          "P-11607V-23.2.5",
          "P-11560V-25.0.0",
          "P-11560V-23.0.2",
          "P-11560V-21.0.4",
          "P-11513V-24.0.1",
          "P-9633(Tools And Frameworks, Content Acquisition System, Platform Services)V-11.4.0",
          "P-14252V-25.1.0.0.0",
          "P-11560V-22.0.2",
          "P-14276V-8.1.3.2"
        ],
        "known_not_affected": [
          "P-5(Database)V-21.3-21.19",
          "P-5(Database)V-19.3-19.28"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(Database)V-21.3-21.19",
            "P-5(Database)V-19.3-19.28"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14252V-25.1.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105403.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9633(Tools And Frameworks, Content Acquisition System, Platform Services)V-11.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106894.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14276V-8.1.2.7",
            "P-14276V-8.1.3.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106757.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11607V-23.2.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106506.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11560V-24.0.1",
            "P-11560V-23.0.2",
            "P-11560V-21.0.4",
            "P-11513V-24.0.1",
            "P-11560V-20.0.5",
            "P-11560V-22.0.2",
            "P-11560V-25.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104399.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(Database)V-21.3-21.19",
            "P-5(Database)V-19.3-19.28"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14276V-8.1.2.7",
            "P-11560V-24.0.1",
            "P-11560V-23.0.2",
            "P-11560V-21.0.4",
            "P-11513V-24.0.1",
            "P-11560V-20.0.5",
            "P-14252V-25.1.0.0.0",
            "P-11560V-22.0.2",
            "P-14276V-8.1.3.2",
            "P-11607V-23.2.5",
            "P-11560V-25.0.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-9633(Tools And Frameworks, Content Acquisition System, Platform Services)V-11.4.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 4.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.1.0-6.1.1"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-5(Database)V-21.3-21.19",
            "P-5(Database)V-19.3-19.28"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-49124",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Siebel CRM End User",
          "text": "38092672"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
          "text": "38313397"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: User Interface (Apache Tomcat)).  Supported versions that are affected are Prior to 25.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM End User.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM End User.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Apache Tomcat)).   The supported version that is affected is 24.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9011V-Prior to 25.10",
          "P-11513V-24.0.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9011V-Prior to 25.10"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106900.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11513V-24.0.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104399.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-49125",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Siebel CRM End User",
          "text": "38092672"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
          "text": "38313397"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: User Interface (Apache Tomcat)).  Supported versions that are affected are Prior to 25.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM End User.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM End User.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Apache Tomcat)).   The supported version that is affected is 24.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9011V-Prior to 25.10",
          "P-11513V-24.0.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9011V-Prior to 25.10"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106900.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11513V-24.0.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104399.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-49128",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Enterprise Manager Base Platform",
          "text": "38040768"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Security Framework (jackson-databind)).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Enterprise Manager Base Platform executes to compromise Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 4.0 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1370V-13.5",
          "P-1370V-24.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1370V-24.1",
            "P-1370V-13.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102566.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.0,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1370V-24.1",
            "P-1370V-13.5"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-4949",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "37997476"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the SQLcl (jgit) component of Oracle Database Server.  Supported versions that are affected are 23.4-23.9. Difficult to exploit vulnerability allows low privileged attacker having Valid account privilege with network access via HTTP to compromise SQLcl (jgit).  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all SQLcl (jgit) accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5(SQLcl)V-23.4-23.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(SQLcl)V-23.4-23.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(SQLcl)V-23.4-23.9"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-49794",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
          "text": "38338331"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Cluster",
          "text": "38338289"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
          "text": "38338322"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
          "text": "38338333"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Workbench",
          "text": "38338301"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Console",
          "text": "38338323"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Converged Charging System",
          "text": "38338335"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core DBTier",
          "text": "38338325"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
          "text": "38430893"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
          "text": "38338327"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
          "text": "38315800"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
          "text": "38338328"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General (libxml2)).  Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and  9.0.0-9.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Cluster accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (libxml2)).  Supported versions that are affected are 8.0.0-8.0.43. Easily exploitable vulnerability allows unauthenticated attacker with network access via MySQL Workbench to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Workbench accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Workbench.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (libxml2)).  Supported versions that are affected are 24.2.7-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Install (libxml2)).  Supported versions that are affected are 24.2.5 and  25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Console accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Console.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Install (libxml2)).   The supported version that is affected is 25.1.201. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Signaling (libxml2)).  Supported versions that are affected are 24.2.5 and  25.1.202. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Repository Function accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (libxml2)).  Supported versions that are affected are 25.1.100-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (libxml2)).  Supported versions that are affected are 24.2.7-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Signaling (libxml2)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Unified Data Repository accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Unified Data Repository.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Converged Charging System product of Oracle Communications Applications (component: Security (libxml2)).  Supported versions that are affected are 2.0.0.0.0-2.0.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Converged Charging System.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Converged Charging System accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Converged Charging System.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Configuration (libxml2)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Certificate Management executes to compromise Oracle Communications Cloud Native Core Certificate Management.  While the vulnerability is in Oracle Communications Cloud Native Core Certificate Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Certificate Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Certificate Management.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (libxml2)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core DBTier accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core DBTier.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8479V-8.4.0-8.4.6",
          "P-14277V-24.2.7-25.1.200",
          "P-8479V-8.0.0-8.0.43",
          "P-14974V-25.1.200",
          "P-14118(Signaling)V-25.1.202",
          "P-14250V-25.1.200",
          "P-14565V-2.0.0.0.0-2.0.0.1.0",
          "P-14123V-25.1.201",
          "P-14118(Signaling)V-24.2.5",
          "P-14130V-25.1.100-25.1.200",
          "P-4627V-8.0.0-8.0.43",
          "P-14868V-25.1.200",
          "P-8479V-9.0.0-9.4.0",
          "P-14121V-24.2.7-25.1.200",
          "P-14250V-24.2.5",
          "P-14119V-25.1.200"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8479V-8.4.0-8.4.6",
            "P-4627V-8.0.0-8.0.43",
            "P-8479V-8.0.0-8.0.43",
            "P-8479V-9.0.0-9.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14121V-24.2.7-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105418.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14250V-25.1.200",
            "P-14250V-24.2.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105453.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14123V-25.1.201"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105449.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14118(Signaling)V-24.2.5",
            "P-14118(Signaling)V-25.1.202"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3107682.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14130V-25.1.100-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105448.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-24.2.7-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105404.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14119V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105405.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14565V-2.0.0.0.0-2.0.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105318.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14868V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105451.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14974V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105407.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-49795",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
          "text": "38338331"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Cluster",
          "text": "38338289"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
          "text": "38338322"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
          "text": "38338333"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Workbench",
          "text": "38338301"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Console",
          "text": "38338323"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Converged Charging System",
          "text": "38338335"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core DBTier",
          "text": "38338325"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
          "text": "38338327"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
          "text": "38338328"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Converged Charging System product of Oracle Communications Applications (component: Security (libxml2)).  Supported versions that are affected are 2.0.0.0.0-2.0.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Converged Charging System.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Converged Charging System accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Converged Charging System.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General (libxml2)).  Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and  9.0.0-9.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Cluster accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (libxml2)).  Supported versions that are affected are 8.0.0-8.0.43. Easily exploitable vulnerability allows unauthenticated attacker with network access via MySQL Workbench to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Workbench accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Workbench.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (libxml2)).  Supported versions that are affected are 24.2.7-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Install (libxml2)).  Supported versions that are affected are 24.2.5 and  25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Console accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Console.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (libxml2)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core DBTier accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core DBTier.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Signaling (libxml2)).  Supported versions that are affected are 24.2.5 and  25.1.202. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Repository Function accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (libxml2)).  Supported versions that are affected are 25.1.100-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (libxml2)).  Supported versions that are affected are 24.2.7-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Signaling (libxml2)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Unified Data Repository accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Unified Data Repository.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8479V-8.4.0-8.4.6",
          "P-14277V-24.2.7-25.1.200",
          "P-8479V-8.0.0-8.0.43",
          "P-14974V-25.1.200",
          "P-14118(Signaling)V-25.1.202",
          "P-14250V-25.1.200",
          "P-14565V-2.0.0.0.0-2.0.0.1.0",
          "P-14118(Signaling)V-24.2.5",
          "P-14130V-25.1.100-25.1.200",
          "P-4627V-8.0.0-8.0.43",
          "P-8479V-9.0.0-9.4.0",
          "P-14121V-24.2.7-25.1.200",
          "P-14250V-24.2.5",
          "P-14119V-25.1.200"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14565V-2.0.0.0.0-2.0.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105318.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8479V-8.4.0-8.4.6",
            "P-4627V-8.0.0-8.0.43",
            "P-8479V-8.0.0-8.0.43",
            "P-8479V-9.0.0-9.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14121V-24.2.7-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105418.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14250V-25.1.200",
            "P-14250V-24.2.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105453.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14974V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105407.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14118(Signaling)V-24.2.5",
            "P-14118(Signaling)V-25.1.202"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3107682.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14130V-25.1.100-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105448.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-24.2.7-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105404.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14119V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105405.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-49796",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Cluster",
          "text": "38338289"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
          "text": "38338322"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
          "text": "38338333"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Workbench",
          "text": "38338301"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Console",
          "text": "38338323"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Converged Charging System",
          "text": "38338335"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core DBTier",
          "text": "38338325"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
          "text": "38315800"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
          "text": "38338338"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
          "text": "38338327"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
          "text": "38338328"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
          "text": "38338331"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
          "text": "38430893"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Configuration (libxml2)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Certificate Management executes to compromise Oracle Communications Cloud Native Core Certificate Management.  While the vulnerability is in Oracle Communications Cloud Native Core Certificate Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Certificate Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Certificate Management.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General (libxml2)).  Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and  9.0.0-9.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Cluster accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (libxml2)).  Supported versions that are affected are 8.0.0-8.0.43. Easily exploitable vulnerability allows unauthenticated attacker with network access via MySQL Workbench to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Workbench accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Workbench. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (libxml2)).  Supported versions that are affected are 24.2.7-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Install (libxml2)).  Supported versions that are affected are 24.2.5 and  25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Console accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (libxml2)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core DBTier accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core DBTier. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Install (libxml2)).   The supported version that is affected is 25.1.201. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (libxml2)).  Supported versions that are affected are 25.1.100-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (libxml2)).  Supported versions that are affected are 24.2.7-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Signaling (libxml2)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Unified Data Repository accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Converged Charging System product of Oracle Communications Applications (component: Security (libxml2)).  Supported versions that are affected are 2.0.0.0.0-2.0.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Converged Charging System.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Converged Charging System accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Converged Charging System. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Security (libxml2)).  Supported versions that are affected are 7.7.0-7.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Inventory Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Signaling (libxml2)).  Supported versions that are affected are 24.2.5 and  25.1.202. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Repository Function accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8479V-8.4.0-8.4.6",
          "P-14277V-24.2.7-25.1.200",
          "P-8479V-8.0.0-8.0.43",
          "P-14974V-25.1.200",
          "P-14118(Signaling)V-25.1.202",
          "P-14250V-25.1.200",
          "P-14565V-2.0.0.0.0-2.0.0.1.0",
          "P-14123V-25.1.201",
          "P-14130V-25.1.100-25.1.200",
          "P-4516V-7.7.0-7.8.0",
          "P-14118(Signaling)V-24.2.5",
          "P-4627V-8.0.0-8.0.43",
          "P-14868V-25.1.200",
          "P-8479V-9.0.0-9.4.0",
          "P-14121V-24.2.7-25.1.200",
          "P-14250V-24.2.5",
          "P-14119V-25.1.200"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14868V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105451.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8479V-8.4.0-8.4.6",
            "P-4627V-8.0.0-8.0.43",
            "P-8479V-8.0.0-8.0.43",
            "P-8479V-9.0.0-9.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14121V-24.2.7-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105418.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14250V-25.1.200",
            "P-14250V-24.2.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105453.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14974V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105407.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14123V-25.1.201"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105449.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14130V-25.1.100-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105448.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-24.2.7-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105404.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14119V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105405.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14565V-2.0.0.0.0-2.0.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105318.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.7.0-7.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105322.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14118(Signaling)V-24.2.5",
            "P-14118(Signaling)V-25.1.202"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3107682.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8479V-8.4.0-8.4.6",
            "P-14277V-24.2.7-25.1.200",
            "P-8479V-8.0.0-8.0.43",
            "P-14974V-25.1.200",
            "P-14118(Signaling)V-25.1.202",
            "P-14250V-25.1.200",
            "P-14565V-2.0.0.0.0-2.0.0.1.0",
            "P-14123V-25.1.201",
            "P-14130V-25.1.100-25.1.200",
            "P-4516V-7.7.0-7.8.0",
            "P-14118(Signaling)V-24.2.5",
            "P-4627V-8.0.0-8.0.43",
            "P-8479V-9.0.0-9.4.0",
            "P-14121V-24.2.7-25.1.200",
            "P-14250V-24.2.5",
            "P-14119V-25.1.200"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50059",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38021373"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the GraalVM Multilingual Engine component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
          "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
            "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
            "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50063",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38021373"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the GraalVM Multilingual Engine component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
          "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
            "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
            "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50065",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38021373"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the GraalVM Multilingual Engine component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
          "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
            "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
            "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50074",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Revenue Management and Billing",
          "text": "37760462"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Security Management System).  Supported versions that are affected are 2.9.0.0.0-7.2.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Financial Services Revenue Management and Billing.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Revenue Management and Billing accessible data. CVSS 3.1 Base Score 4.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5322V-2.9.0.0.0-7.2.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5322V-2.9.0.0.0-7.2.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104564.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5322V-2.9.0.0.0-7.2.0.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50075",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Revenue Management and Billing",
          "text": "37797203"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Security Management System).  Supported versions that are affected are 2.9.0.0.0-7.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Revenue Management and Billing.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Revenue Management and Billing accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5322V-2.9.0.0.0-7.2.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5322V-2.9.0.0.0-7.2.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104564.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5322V-2.9.0.0.0-7.2.0.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50106",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38021373"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the GraalVM Multilingual Engine component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
          "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
            "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(GraalVM Multilingual Engine)V-21.3-21.19",
            "P-5(GraalVM Multilingual Engine)V-23.4-23.9"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50181",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "38132422"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Porting (urllib3)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106893.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50182",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "38132422"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Porting (urllib3)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106893.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-5115",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
          "text": "38419978"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
          "text": "38419986"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
          "text": "38419965"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
          "text": "38448596"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
          "text": "38420542"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
          "text": "38529039"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
          "text": "38419963"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Signaling (Jenkins)).  Supported versions that are affected are 24.2.5 and  25.1.202. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Alarms, KPI, and Measurements (Eclipse Jetty)).  Supported versions that are affected are 24.2.7-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Eclipse Jetty)).   The supported version that is affected is 8.1.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Compliance Studio. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Security (Eclipse Jetty)).  Supported versions that are affected are 7.5.0-7.5.1 and  7.6.0-7.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Eclipse Jetty)).  Supported versions that are affected are 24.2.7-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Eclipse Jetty)).  Supported versions that are affected are 24.2.7-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Configuration (Eclipse Jetty)).  Supported versions that are affected are 24.2.7-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14118(Signaling)V-24.2.5",
          "P-14392V-8.1.2.8",
          "P-4516V-7.6.0-7.8.0",
          "P-14277(Alarms, KPI, and Measurements)V-24.2.7-25.1.200",
          "P-14277(Configuration)V-24.2.7-25.1.200",
          "P-14118(Signaling)V-25.1.202",
          "P-14121(Install)V-24.2.7-25.1.200",
          "P-14121(Alarms, KPI, and Measurements)V-24.2.7-25.1.200",
          "P-4516V-7.5.0-7.5.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14118(Signaling)V-24.2.5",
            "P-14118(Signaling)V-25.1.202"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3107682.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14121(Install)V-24.2.7-25.1.200",
            "P-14121(Alarms, KPI, and Measurements)V-24.2.7-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105418.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14392V-8.1.2.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106412.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.6.0-7.8.0",
            "P-4516V-7.5.0-7.5.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105322.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277(Alarms, KPI, and Measurements)V-24.2.7-25.1.200",
            "P-14277(Configuration)V-24.2.7-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105404.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14118(Signaling)V-24.2.5",
            "P-14392V-8.1.2.8",
            "P-4516V-7.6.0-7.8.0",
            "P-14277(Alarms, KPI, and Measurements)V-24.2.7-25.1.200",
            "P-14277(Configuration)V-24.2.7-25.1.200",
            "P-14118(Signaling)V-25.1.202",
            "P-14121(Install)V-24.2.7-25.1.200",
            "P-14121(Alarms, KPI, and Measurements)V-24.2.7-25.1.200",
            "P-4516V-7.5.0-7.5.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-52434",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-5(Database)V-21.3-21.19",
            "P-5(Database)V-19.3-19.28"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38311920"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
          "text": "38313397"
        },
        {
          "system_name": "Oracle Bug ID of Graph Server and Client",
          "text": "38231746"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Graph Server and Client product of Oracle Graph Server and Client (component: Install (Apache Tomcat)).  Supported versions that are affected are 24.4.3 and  25.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Graph Server and Client.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Graph Server and Client.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Database (Apache Tomcat) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Apache Tomcat)).   The supported version that is affected is 24.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14069V-24.4.3",
          "P-11513V-24.0.1",
          "P-14069V-25.3.0"
        ],
        "known_not_affected": [
          "P-5(Database)V-21.3-21.19",
          "P-5(Database)V-19.3-19.28"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14069V-24.4.3",
            "P-5(Database)V-21.3-21.19",
            "P-5(Database)V-19.3-19.28",
            "P-14069V-25.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11513V-24.0.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104399.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(Database)V-21.3-21.19",
            "P-5(Database)V-19.3-19.28"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-5(Database)V-21.3-21.19",
            "P-5(Database)V-19.3-19.28"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-52520",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-5(Database)V-21.3-21.19",
            "P-5(Database)V-19.3-19.28"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38311920"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
          "text": "38313397"
        },
        {
          "system_name": "Oracle Bug ID of Graph Server and Client",
          "text": "38231746"
        },
        {
          "system_name": "Oracle Bug ID of Management Cloud Engine",
          "text": "38313367"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Graph Server and Client product of Oracle Graph Server and Client (component: Install (Apache Tomcat)).  Supported versions that are affected are 24.4.3 and  25.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Graph Server and Client.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Graph Server and Client. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Database (Apache Tomcat) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Management Cloud Engine product of Oracle Communications (component: BEServer (Apache Tomcat)).   The supported version that is affected is 25.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Management Cloud Engine.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Management Cloud Engine.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Apache Tomcat)).   The supported version that is affected is 24.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14069V-24.4.3",
          "P-14252V-25.1.0.0.0",
          "P-11513V-24.0.1",
          "P-14069V-25.3.0"
        ],
        "known_not_affected": [
          "P-5(Database)V-21.3-21.19",
          "P-5(Database)V-19.3-19.28"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14069V-24.4.3",
            "P-5(Database)V-21.3-21.19",
            "P-5(Database)V-19.3-19.28",
            "P-14069V-25.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14252V-25.1.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105403.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11513V-24.0.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104399.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14069V-24.4.3",
            "P-14069V-25.3.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(Database)V-21.3-21.19",
            "P-5(Database)V-19.3-19.28"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-5(Database)V-21.3-21.19",
            "P-5(Database)V-19.3-19.28"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-52999",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38350751"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Microservices (jackson-core)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 6.2 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.0-6.1.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.2,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.1.0-6.1.1"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "tu3n4nh"
          ]
        }
      ],
      "cve": "CVE-2025-53034",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
          "text": "37422001"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform).  Supported versions that are affected are 8.0.7.9, 8.0.8.7 and  8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Analytical Applications Infrastructure accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5680V-8.1.2.5",
          "P-5680V-8.0.7.9",
          "P-5680V-8.0.8.7"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.7.9",
            "P-5680V-8.0.8.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104221.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.7.9",
            "P-5680V-8.0.8.7"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Le Quoc Bao"
          ],
          "organization": "HPT Vietnam Corporation"
        },
        {
          "names": [
            "Nguyen Kim Sang"
          ],
          "organization": "HPT Vietnam Corporation"
        }
      ],
      "cve": "CVE-2025-53035",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
          "text": "37444473"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform).  Supported versions that are affected are 8.0.7.9, 8.0.8.7 and  8.1.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5680V-8.1.2.5",
          "P-5680V-8.0.7.9",
          "P-5680V-8.0.8.7"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.7.9",
            "P-5680V-8.0.8.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104221.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.7.9",
            "P-5680V-8.0.8.7"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Nguyen Tuong Huy"
          ],
          "organization": "HDBank"
        }
      ],
      "cve": "CVE-2025-53036",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
          "text": "37613774"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform).  Supported versions that are affected are 8.0.7.9, 8.0.8.7 and  8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  While the vulnerability is in Oracle Financial Services Analytical Applications Infrastructure, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5680V-8.1.2.5",
          "P-5680V-8.0.7.9",
          "P-5680V-8.0.8.7"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.7.9",
            "P-5680V-8.0.8.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104221.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.6,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.7.9",
            "P-5680V-8.0.8.7"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Nguyen Tuong Huy"
          ],
          "organization": "HDBank"
        }
      ],
      "cve": "CVE-2025-53037",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
          "text": "37619203"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform).  Supported versions that are affected are 8.0.7.9, 8.0.8.7 and  8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Analytical Applications Infrastructure. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5680V-8.1.2.5",
          "P-5680V-8.0.7.9",
          "P-5680V-8.0.8.7"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.7.9",
            "P-5680V-8.0.8.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104221.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.7.9",
            "P-5680V-8.0.8.7"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53040",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "35451459"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and  9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Optimizer)V-8.4.0-8.4.6",
          "P-8478(Server: Optimizer)V-8.0.0-8.0.43",
          "P-8478(Server: Optimizer)V-9.0.0-9.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Optimizer)V-8.4.0-8.4.6",
            "P-8478(Server: Optimizer)V-8.0.0-8.0.43",
            "P-8478(Server: Optimizer)V-9.0.0-9.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Optimizer)V-8.4.0-8.4.6",
            "P-8478(Server: Optimizer)V-8.0.0-8.0.43",
            "P-8478(Server: Optimizer)V-9.0.0-9.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53041",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle iStore",
          "text": "36589745"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart).  Supported versions that are affected are 12.2.5-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iStore, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle iStore accessible data as well as  unauthorized read access to a subset of Oracle iStore accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-384V-12.2.5-12.2.14"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-384V-12.2.5-12.2.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2484000.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-384V-12.2.5-12.2.14"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53042",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "36684370"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and  9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Optimizer)V-8.4.0-8.4.6",
          "P-8478(Server: Optimizer)V-8.0.0-8.0.43",
          "P-8478(Server: Optimizer)V-9.0.0-9.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Optimizer)V-8.4.0-8.4.6",
            "P-8478(Server: Optimizer)V-8.0.0-8.0.43",
            "P-8478(Server: Optimizer)V-9.0.0-9.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Optimizer)V-8.4.0-8.4.6",
            "P-8478(Server: Optimizer)V-8.0.0-8.0.43",
            "P-8478(Server: Optimizer)V-9.0.0-9.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53043",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Product Hub",
          "text": "36759794"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog).  Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Product Hub accessible data as well as  unauthorized access to critical data or complete access to all Oracle Product Hub accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1313V-12.2.3-12.2.14"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1313V-12.2.3-12.2.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2484000.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1313V-12.2.3-12.2.14"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53044",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "36768046"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and  9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(InnoDB)V-9.0.0-9.4.0",
          "P-8478(InnoDB)V-8.4.0-8.4.6",
          "P-8478(InnoDB)V-8.0.0-8.0.43"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(InnoDB)V-9.0.0-9.4.0",
            "P-8478(InnoDB)V-8.4.0-8.4.6",
            "P-8478(InnoDB)V-8.0.0-8.0.43"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(InnoDB)V-9.0.0-9.4.0",
            "P-8478(InnoDB)V-8.4.0-8.4.6",
            "P-8478(InnoDB)V-8.0.0-8.0.43"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53045",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "36867372"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and  9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(InnoDB)V-9.0.0-9.4.0",
          "P-8478(InnoDB)V-8.4.0-8.4.6",
          "P-8478(InnoDB)V-8.0.0-8.0.43"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(InnoDB)V-9.0.0-9.4.0",
            "P-8478(InnoDB)V-8.4.0-8.4.6",
            "P-8478(InnoDB)V-8.0.0-8.0.43"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(InnoDB)V-9.0.0-9.4.0",
            "P-8478(InnoDB)V-8.4.0-8.4.6",
            "P-8478(InnoDB)V-8.0.0-8.0.43"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53046",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle ZFS Storage Appliance Kit",
          "text": "36772260"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Analytics).   The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10026V-8.8"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10026V-8.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106603.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10026V-8.8"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53047",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "36913519"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Portable Clusterware component of Oracle Database Server.  Supported versions that are affected are 19.3-19.28, 21.3-21.19 and  23.4-23.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via Bonjour to compromise Portable Clusterware.  While the vulnerability is in Portable Clusterware, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Portable Clusterware accessible data. CVSS 3.1 Base Score 5.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5(Portable Clusterware)V-19.3-19.28",
          "P-5(Portable Clusterware)V-23.4-23.9",
          "P-5(Portable Clusterware)V-21.3-21.19"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(Portable Clusterware)V-19.3-19.28",
            "P-5(Portable Clusterware)V-23.4-23.9",
            "P-5(Portable Clusterware)V-21.3-21.19"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.8,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(Portable Clusterware)V-19.3-19.28",
            "P-5(Portable Clusterware)V-23.4-23.9",
            "P-5(Portable Clusterware)V-21.3-21.19"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53048",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "37099664"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Rich Text Editor).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106893.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53049",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
          "text": "37202061"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web Administration).  Supported versions that are affected are 7.6.0.0.0 and  8.2.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2025V-7.6.0.0.0",
          "P-2025V-8.2.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2025V-7.6.0.0.0",
            "P-2025V-8.2.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105456.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.4,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-2025V-7.6.0.0.0",
            "P-2025V-8.2.0.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53050",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "37286347"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Performance Monitor).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106893.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Emad Al-Mousa"
          ]
        }
      ],
      "cve": "CVE-2025-53051",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "37450640"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the RDBMS Functional Index component of Oracle Database Server.  Supported versions that are affected are 23.4-23.9. Easily exploitable vulnerability allows high privileged attacker having SYSDBA privilege with network access via Oracle Net to compromise RDBMS Functional Index.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of RDBMS Functional Index accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5(RDBMS Functional Index)V-23.4-23.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(RDBMS Functional Index)V-23.4-23.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 2.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(RDBMS Functional Index)V-23.4-23.9"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Kush Jijania"
          ]
        }
      ],
      "cve": "CVE-2025-53052",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Workflow",
          "text": "37450688"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer).  Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Workflow.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Workflow, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Workflow accessible data as well as  unauthorized read access to a subset of Oracle Workflow accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-174V-12.2.3-12.2.14"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-174V-12.2.3-12.2.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2484000.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-174V-12.2.3-12.2.14"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53053",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "37590580"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML).  Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and  9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: DML)V-8.4.0-8.4.6",
          "P-8478(Server: DML)V-9.0.0-9.4.0",
          "P-8478(Server: DML)V-8.0.0-8.0.43"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: DML)V-8.4.0-8.4.6",
            "P-8478(Server: DML)V-9.0.0-9.4.0",
            "P-8478(Server: DML)V-8.0.0-8.0.43"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: DML)V-8.4.0-8.4.6",
            "P-8478(Server: DML)V-9.0.0-9.4.0",
            "P-8478(Server: DML)V-8.0.0-8.0.43"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53054",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "37602657"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and  9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(InnoDB)V-9.0.0-9.4.0",
          "P-8478(InnoDB)V-8.4.0-8.4.6",
          "P-8478(InnoDB)V-8.0.0-8.0.43"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(InnoDB)V-9.0.0-9.4.0",
            "P-8478(InnoDB)V-8.4.0-8.4.6",
            "P-8478(InnoDB)V-8.0.0-8.0.43"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(InnoDB)V-9.0.0-9.4.0",
            "P-8478(InnoDB)V-8.4.0-8.4.6",
            "P-8478(InnoDB)V-8.0.0-8.0.43"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53055",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "37627506"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106893.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Kush Jijania"
          ]
        }
      ],
      "cve": "CVE-2025-53056",
      "ids": [
        {
          "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
          "text": "37646578"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Object and Environment Tech).  Supported versions that are affected are 9.2.0.0-9.2.9.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as  unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4781V-9.2.0.0-9.2.9.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4781V-9.2.0.0-9.2.9.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106891.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4781V-9.2.0.0-9.2.9.4"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Jinfeng Guo"
          ]
        }
      ],
      "cve": "CVE-2025-53057",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "37658670"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security).  Supported versions that are affected are Oracle Java SE: 8u461, 8u461-perf, 11.0.28, 17.0.16, 21.0.8, 25; Oracle GraalVM for JDK: 17.0.16 and  21.0.8; Oracle GraalVM Enterprise Edition: 21.3.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data.  Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u461",
          "P-856V-21.0.8",
          "P-856V-25",
          "P-13497V-21.3.15",
          "P-13497V-21.0.8",
          "P-856V-11.0.28",
          "P-13497V-17.0.16",
          "P-856V-17.0.16",
          "P-856V-8u461-perf"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u461",
            "P-856V-21.0.8",
            "P-856V-25",
            "P-13497V-21.3.15",
            "P-13497V-21.0.8",
            "P-856V-11.0.28",
            "P-13497V-17.0.16",
            "P-856V-17.0.16",
            "P-856V-8u461-perf"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104405.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-856V-8u461",
            "P-856V-21.0.8",
            "P-856V-25",
            "P-13497V-21.3.15",
            "P-13497V-21.0.8",
            "P-856V-11.0.28",
            "P-13497V-17.0.16",
            "P-856V-17.0.16",
            "P-856V-8u461-perf"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53058",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Applications Manager",
          "text": "37670054"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Application Logging Interfaces).  Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Manager.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Applications Manager accessible data as well as  unauthorized read access to a subset of Oracle Applications Manager accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-99V-12.2.3-12.2.14"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-99V-12.2.3-12.2.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2484000.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-99V-12.2.3-12.2.14"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53059",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "37686827"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 4.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106893.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53060",
      "ids": [
        {
          "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
          "text": "37722783"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC).  Supported versions that are affected are 9.2.0.0-9.2.9.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as  unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4781V-9.2.0.0-9.2.9.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4781V-9.2.0.0-9.2.9.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106891.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4781V-9.2.0.0-9.2.9.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53061",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "37784107"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  While the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106893.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53062",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "37792010"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and  9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(InnoDB)V-9.0.0-9.4.0",
          "P-8478(InnoDB)V-8.4.0-8.4.6",
          "P-8478(InnoDB)V-8.0.0-8.0.43"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(InnoDB)V-9.0.0-9.4.0",
            "P-8478(InnoDB)V-8.4.0-8.4.6",
            "P-8478(InnoDB)V-8.0.0-8.0.43"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(InnoDB)V-9.0.0-9.4.0",
            "P-8478(InnoDB)V-8.4.0-8.4.6",
            "P-8478(InnoDB)V-8.0.0-8.0.43"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Arjun Basnet"
          ]
        }
      ],
      "cve": "CVE-2025-53063",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "37835374"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106893.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53064",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Applications Framework",
          "text": "37839113"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization).  Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1472V-12.2.3-12.2.14"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1472V-12.2.3-12.2.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2484000.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1472V-12.2.3-12.2.14"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53065",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "37842989"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106893.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Darius Bohni"
          ],
          "organization": "442 Security GmbH"
        }
      ],
      "cve": "CVE-2025-53066",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "37846132"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP).  Supported versions that are affected are Oracle Java SE: 8u461, 8u461-perf, 11.0.28, 17.0.16, 21.0.8, 25; Oracle GraalVM for JDK: 17.0.16 and  21.0.8; Oracle GraalVM Enterprise Edition: 21.3.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data.  Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u461",
          "P-856V-21.0.8",
          "P-856V-25",
          "P-13497V-21.3.15",
          "P-13497V-21.0.8",
          "P-856V-11.0.28",
          "P-13497V-17.0.16",
          "P-856V-17.0.16",
          "P-856V-8u461-perf"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u461",
            "P-856V-21.0.8",
            "P-856V-25",
            "P-13497V-21.3.15",
            "P-13497V-21.0.8",
            "P-856V-11.0.28",
            "P-13497V-17.0.16",
            "P-856V-17.0.16",
            "P-856V-8u461-perf"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104405.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-856V-8u461",
            "P-856V-21.0.8",
            "P-856V-25",
            "P-13497V-21.3.15",
            "P-13497V-21.0.8",
            "P-856V-11.0.28",
            "P-13497V-17.0.16",
            "P-856V-17.0.16",
            "P-856V-8u461-perf"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "yx"
          ]
        }
      ],
      "cve": "CVE-2025-53067",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "37847144"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Optimizer)V-9.0.0-9.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Optimizer)V-9.0.0-9.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Optimizer)V-9.0.0-9.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53068",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Solaris",
          "text": "37847800"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel).   The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris.  While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10006V-11"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10006V-11"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106603.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10006V-11"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "yx"
          ]
        }
      ],
      "cve": "CVE-2025-53069",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "38001000"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services).  Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and  9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Components Services)V-9.0.0-9.4.0",
          "P-8478(Server: Components Services)V-8.4.0-8.4.6",
          "P-8478(Server: Components Services)V-8.0.0-8.0.43"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Components Services)V-8.4.0-8.4.6",
            "P-8478(Server: Components Services)V-8.0.0-8.0.43",
            "P-8478(Server: Components Services)V-9.0.0-9.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Components Services)V-8.4.0-8.4.6",
            "P-8478(Server: Components Services)V-8.0.0-8.0.43",
            "P-8478(Server: Components Services)V-9.0.0-9.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53070",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Solaris",
          "text": "38029063"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem).   The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Solaris, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10006V-11"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10006V-11"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106603.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10006V-11"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53071",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Applications Framework",
          "text": "38034331"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Upload Attachments).  Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-208V-12.2.3-12.2.14"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-208V-12.2.3-12.2.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2484000.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-208V-12.2.3-12.2.14"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Maxime Escourbiac"
          ],
          "organization": "Michelin CERT"
        },
        {
          "names": [
            "Yassine Bengana"
          ],
          "organization": "Michelin CERT"
        }
      ],
      "cve": "CVE-2025-53072",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Marketing",
          "text": "38510956"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration).  Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing.  Successful attacks of this vulnerability can result in takeover of Oracle Marketing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-229V-12.2.3-12.2.14"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-229V-12.2.3-12.2.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2484000.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-229V-12.2.3-12.2.14"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-5318",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Workbench",
          "text": "38263939"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
          "text": "38263979"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (libssh)).  Supported versions that are affected are 8.0.0-8.0.43. Easily exploitable vulnerability allows low privileged attacker with network access via MySQL Workbench to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Workbench accessible data as well as  unauthorized read access to a subset of MySQL Workbench accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Security (libssh)).  Supported versions that are affected are 7.7.0 and  7.8.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Inventory Management accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Inventory Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4627V-8.0.0-8.0.43",
          "P-4516V-7.7.0",
          "P-4516V-7.8.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4627V-8.0.0-8.0.43"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.7.0",
            "P-4516V-7.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105322.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4627V-8.0.0-8.0.43",
            "P-4516V-7.7.0",
            "P-4516V-7.8.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53506",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-5(Database)V-21.3-21.19",
            "P-5(Database)V-19.3-19.28"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38311920"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
          "text": "38313397"
        },
        {
          "system_name": "Oracle Bug ID of Graph Server and Client",
          "text": "38231746"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Apache Tomcat)).   The supported version that is affected is 24.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Graph Server and Client product of Oracle Graph Server and Client (component: Install (Apache Tomcat)).  Supported versions that are affected are 24.4.3 and  25.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Graph Server and Client.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Graph Server and Client.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Database (Apache Tomcat) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14069V-24.4.3",
          "P-11513V-24.0.1",
          "P-14069V-25.3.0"
        ],
        "known_not_affected": [
          "P-5(Database)V-21.3-21.19",
          "P-5(Database)V-19.3-19.28"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11513V-24.0.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104399.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14069V-24.4.3",
            "P-5(Database)V-21.3-21.19",
            "P-5(Database)V-19.3-19.28",
            "P-14069V-25.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(Database)V-21.3-21.19",
            "P-5(Database)V-19.3-19.28"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-5(Database)V-21.3-21.19",
            "P-5(Database)V-19.3-19.28"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-5351",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Workbench",
          "text": "38263939"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
          "text": "38263979"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Security (libssh)).  Supported versions that are affected are 7.7.0 and  7.8.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Inventory Management accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Inventory Management accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (libssh)).  Supported versions that are affected are 8.0.0-8.0.43. Easily exploitable vulnerability allows low privileged attacker with network access via MySQL Workbench to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Workbench accessible data as well as  unauthorized read access to a subset of MySQL Workbench accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4627V-8.0.0-8.0.43",
          "P-4516V-7.7.0",
          "P-4516V-7.8.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.7.0",
            "P-4516V-7.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105322.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4627V-8.0.0-8.0.43"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-53547",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Function Cloud Native Environment",
          "text": "38313069"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: Configuration (Helm)).  Supported versions that are affected are 25.1.100 and  25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Network Function Cloud Native Environment executes to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Cloud Native Core Network Function Cloud Native Environment, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Function Cloud Native Environment. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14125V-25.1.100",
          "P-14125V-25.1.200"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14125V-25.1.100",
            "P-14125V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105380.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.6,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14125V-25.1.100",
            "P-14125V-25.1.200"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53643",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
          "text": "38392865"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Developer Infrastructure (AIOHTTP)).  Supported versions that are affected are 5.2 and  6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Operations Monitor accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10761V-6.0",
          "P-10761V-5.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10761V-6.0",
            "P-10761V-5.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105430.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-10761V-6.0",
            "P-10761V-5.2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-5372",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Workbench",
          "text": "38263939"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
          "text": "38263979"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (libssh)).  Supported versions that are affected are 8.0.0-8.0.43. Easily exploitable vulnerability allows low privileged attacker with network access via MySQL Workbench to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Workbench accessible data as well as  unauthorized read access to a subset of MySQL Workbench accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Security (libssh)).  Supported versions that are affected are 7.7.0 and  7.8.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Inventory Management accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Inventory Management accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4627V-8.0.0-8.0.43",
          "P-4516V-7.7.0",
          "P-4516V-7.8.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4627V-8.0.0-8.0.43"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.7.0",
            "P-4516V-7.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105322.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-53816",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Outside In Technology",
          "text": "38246107"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Core (7-Zip)).  Supported versions that are affected are 8.5.7 and  8.5.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Outside In Technology.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2276V-8.5.8",
          "P-2276V-8.5.7"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2276V-8.5.8",
            "P-2276V-8.5.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105435.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-2276V-8.5.8",
            "P-2276V-8.5.7"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53864",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters",
          "text": "38421418"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Essbase",
          "text": "38295152"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
          "text": "38453099"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38351187"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
          "text": "38270555"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: Java Delivery (Nimbus JOSE+JWT)).  Supported versions that are affected are 23.4-23.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GoldenGate Big Data and Application Adapters.  While the vulnerability is in Oracle GoldenGate Big Data and Application Adapters, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GoldenGate Big Data and Application Adapters. CVSS 3.1 Base Score 5.8 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Microservices (Nimbus JOSE+JWT)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  While the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 5.8 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in Oracle Essbase (component: Security and Provisioning (Nimbus JOSE+JWT)).   The supported version that is affected is 21.7.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Essbase.  While the vulnerability is in Oracle Essbase, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Essbase. CVSS 3.1 Base Score 5.8 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Security (Nimbus JOSE+JWT)).  Supported versions that are affected are 7.5.1 and  7.6.0-7.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  While the vulnerability is in Oracle Communications Unified Inventory Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 5.8 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: Security (Nimbus JOSE+JWT)).  Supported versions that are affected are 4.3.0.5.0, 4.4.0.0.0, 4.4.0.2.0, 4.4.0.3.0, 4.4.0.4.0, 4.5.0.0.0, 4.5.0.1.1, 4.5.0.1.3, 4.5.0.2.0, 24.2.0.0.0, 24.3.0.0.0, 25.4 and  25.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Application Framework.  While the vulnerability is in Oracle Utilities Application Framework, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Utilities Application Framework. CVSS 3.1 Base Score 5.8 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5760V-23.4-23.9",
          "P-2245V-24.3.0.0.0",
          "P-14597V-6.1.0-6.1.1",
          "P-2245V-4.5.0.1.1",
          "P-2245V-4.5.0.2.0",
          "P-2245V-4.5.0.0.0",
          "P-4516V-7.5.1",
          "P-2245V-4.4.0.0.0",
          "P-2245V-4.4.0.2.0",
          "P-2245V-4.4.0.3.0",
          "P-2245V-4.4.0.4.0",
          "P-4516V-7.6.0-7.8.0",
          "P-2245V-4.3.0.5.0",
          "P-2245V-4.5.0.1.3",
          "P-2245V-25.4",
          "P-4379V-21.7.3.0.0",
          "P-2245V-25.10",
          "P-2245V-24.2.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5760V-23.4-23.9",
            "P-4379V-21.7.3.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.6.0-7.8.0",
            "P-4516V-7.5.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105322.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2245V-24.3.0.0.0",
            "P-2245V-4.5.0.1.1",
            "P-2245V-4.5.0.2.0",
            "P-2245V-4.5.0.0.0",
            "P-2245V-4.4.0.0.0",
            "P-2245V-4.4.0.2.0",
            "P-2245V-4.4.0.3.0",
            "P-2245V-4.4.0.4.0",
            "P-2245V-4.3.0.5.0",
            "P-2245V-4.5.0.1.3",
            "P-2245V-25.4",
            "P-2245V-25.10",
            "P-2245V-24.2.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105252.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.8,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-5760V-23.4-23.9",
            "P-2245V-24.3.0.0.0",
            "P-14597V-6.1.0-6.1.1",
            "P-2245V-4.5.0.1.1",
            "P-2245V-4.5.0.2.0",
            "P-2245V-4.5.0.0.0",
            "P-4516V-7.5.1",
            "P-2245V-4.4.0.0.0",
            "P-2245V-4.4.0.2.0",
            "P-2245V-4.4.0.3.0",
            "P-2245V-4.4.0.4.0",
            "P-4516V-7.6.0-7.8.0",
            "P-2245V-4.3.0.5.0",
            "P-2245V-4.5.0.1.3",
            "P-2245V-25.4",
            "P-4379V-21.7.3.0.0",
            "P-2245V-25.10",
            "P-2245V-24.2.0.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-5399",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-4379V-21.7.3.0.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Cluster",
          "text": "38202204"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38225777"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Essbase",
          "text": "38219465"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Enterprise Backup",
          "text": "38219427"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General (curl)).  Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and  9.0.0-9.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Enterprise Backup product of Oracle MySQL (component: Enterprise Backup (curl)).  Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise MySQL Enterprise Backup.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Enterprise Backup. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle Essbase (component: Build (curl)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 4.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8479V-8.4.0-8.4.6",
          "P-4629V-8.4.0-8.4.5",
          "P-4629V-8.0.0-8.0.42",
          "P-8479V-8.0.0-8.0.43",
          "P-8479V-9.0.0-9.4.0",
          "P-4629V-9.0.0-9.3.0",
          "P-14597V-6.1.0-6.1.1"
        ],
        "known_not_affected": [
          "P-4379V-21.7.3.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8479V-8.4.0-8.4.6",
            "P-4629V-8.4.0-8.4.5",
            "P-4629V-8.0.0-8.0.42",
            "P-8479V-8.0.0-8.0.43",
            "P-8479V-9.0.0-9.4.0",
            "P-4629V-9.0.0-9.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4379V-21.7.3.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8479V-8.4.0-8.4.6",
            "P-4629V-8.4.0-8.4.5",
            "P-4629V-8.0.0-8.0.42",
            "P-8479V-8.0.0-8.0.43",
            "P-8479V-9.0.0-9.4.0",
            "P-4629V-9.0.0-9.3.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4379V-21.7.3.0.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 4.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.1.0-6.1.1"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-4379V-21.7.3.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-54090",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-1522V-19.1.0.1.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38232096"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Automated Test Suite",
          "text": "38232087"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Secure Backup",
          "text": "38232113"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
          "text": "38232090"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
          "text": "38232092"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
          "text": "38232091"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: ATS Framework (Apache HTTP Server)).  Supported versions that are affected are 24.2.6 and  25.1.202. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Automated Test Suite accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Automated Test Suite accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Automated Test Suite. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Automated Test Suite (Apache HTTP Server)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle Secure Backup (component: Oracle Secure Backup (Apache HTTP Server)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (Apache HTTP Server)).  Supported versions that are affected are 25.1.200 and  25.2.100. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Service Communication Proxy accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Service Communication Proxy accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Automated Test Suite Framework (Apache HTTP Server)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Unified Data Repository accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Unified Data Repository accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Apache HTTP Server)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14488V-25.1.202",
          "P-14117V-25.2.100",
          "P-14117V-25.1.200",
          "P-14123V-25.1.200",
          "P-14597V-6.1.0-6.1.1",
          "P-14119V-25.1.200",
          "P-14488V-24.2.6"
        ],
        "known_not_affected": [
          "P-1522V-19.1.0.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14488V-25.1.202",
            "P-14488V-24.2.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105433.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14123V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105449.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1522V-19.1.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14117V-25.2.100",
            "P-14117V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105421.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14119V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105405.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14488V-25.1.202",
            "P-14117V-25.2.100",
            "P-14117V-25.1.200",
            "P-14123V-25.1.200",
            "P-14597V-6.1.0-6.1.1",
            "P-14119V-25.1.200",
            "P-14488V-24.2.6"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1522V-19.1.0.1.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-1522V-19.1.0.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-5449",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Workbench",
          "text": "38263939"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
          "text": "38263979"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (libssh)).  Supported versions that are affected are 8.0.0-8.0.43. Easily exploitable vulnerability allows low privileged attacker with network access via MySQL Workbench to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Workbench accessible data as well as  unauthorized read access to a subset of MySQL Workbench accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Security (libssh)).  Supported versions that are affected are 7.7.0 and  7.8.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Inventory Management accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Inventory Management accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4627V-8.0.0-8.0.43",
          "P-4516V-7.7.0",
          "P-4516V-7.8.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4627V-8.0.0-8.0.43"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.7.0",
            "P-4516V-7.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105322.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-55163",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-5758V-23.1.0.0.0-23.4.0.0.0",
            "P-5760V-23.4-23.9",
            "P-14015V-19.1.0.0.0-19.1.0.0.12",
            "P-1870V-22.1.1.1.0-22.1.1.35.0",
            "P-1870V-18.1.4.1.0-18.1.4.53.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Coherence",
          "text": "38312713"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
          "text": "38312724"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
          "text": "38312736"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Order and Service Management",
          "text": "38312733"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
          "text": "38312723"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Stream Analytics",
          "text": "38312789"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Pricing Design Center",
          "text": "38312734"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
          "text": "38312717"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
          "text": "38312739"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
          "text": "38312715"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
          "text": "38312726"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Billing and Revenue Management",
          "text": "38312716"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Veridata",
          "text": "38312749"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Converged Charging System",
          "text": "38312727"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
          "text": "38312771"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Hospitality Cruise Shipboard Property Management (SPMS)",
          "text": "38312750"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Charging and Control",
          "text": "38312731"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Branch",
          "text": "38312688"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Offline Mediation Controller",
          "text": "38312732"
        },
        {
          "system_name": "Oracle Bug ID of Oracle TimesTen In-Memory Database",
          "text": "38312784"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters",
          "text": "38366950"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Netty)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Netty)).  Supported versions that are affected are 24.2.7-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Security (Netty)).  Supported versions that are affected are 12.0.0.4.0-15.0.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Tools And Frameworks (Netty)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP/2 to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Third Party (Netty)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports (Netty)).  Supported versions that are affected are 14.5.0.0.0-14.8.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Banking Branch.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Branch. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Netty)).  Supported versions that are affected are 24.2.7-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: Java Delivery (Netty)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle GoldenGate Stream Analytics product of Oracle GoldenGate (component: General Issues (Netty)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle TimesTen In-Memory Database (component: TimesTen Grid (Netty)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Netty)).  Supported versions that are affected are 22.0.2, 23.0.2 and  24.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management (SPMS) product of Oracle Hospitality Applications (component: Next-Gen SPMS (Netty)).   The supported version that is affected is 23.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Hospitality Cruise Shipboard Property Management (SPMS).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Cruise Shipboard Property Management (SPMS). CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle GoldenGate Veridata product of Oracle GoldenGate (component: Other issues (Netty)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Security (Netty)).  Supported versions that are affected are 7.7.0-7.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications Applications (component: Solution Designer (Netty)).  Supported versions that are affected are 8.0.0.5.0 and  8.1.0.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications Applications (component: REST Services Manager (Netty)).  Supported versions that are affected are 12.0.0.4.0-12.0.0.8.0 and  15.0.0.0.0-15.0.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Pricing Design Center.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Pricing Design Center. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security (Netty)).   The supported version that is affected is 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Order and Service Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Order and Service Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Offline Mediation Controller product of Oracle Communications Applications (component: Installation (Netty)).  Supported versions that are affected are 15.0.0.0.0-15.0.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Offline Mediation Controller.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Offline Mediation Controller. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Charging and Control product of Oracle Communications Applications (component: REST (Netty)).  Supported versions that are affected are 12.0.6.0.0 and  15.0.0.0.0-15.0.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Network Charging and Control.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Charging and Control. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Converged Charging System product of Oracle Communications Applications (component: Installation (Netty)).  Supported versions that are affected are 2.0.0.0.0 and  2.0.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Converged Charging System.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Converged Charging System. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Signaling (Netty)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9437V-15.0.0.0.0-15.0.1.0.0",
          "P-2270V-7.5.0",
          "P-2545V-14.1.1.0.0",
          "P-14130V-25.1.200",
          "P-2269V-15.0.0.0.0-15.0.1.0.0",
          "P-11513V-24.0.1",
          "P-4623V-15.0.0.0.0-15.0.1.0.0",
          "P-14121V-24.2.7-25.1.200",
          "P-11513V-23.0.2",
          "P-2545V-14.1.2.0.0",
          "P-14119V-25.1.200",
          "P-2283V-8.1.0.4.0",
          "P-2545V-12.2.1.4.0",
          "P-14277V-24.2.7-25.1.200",
          "P-11513V-22.0.2",
          "P-4623V-12.0.6.0.0",
          "P-14565V-2.0.0.1.0",
          "P-11607V-23.2.5",
          "P-9437V-12.0.0.4.0-12.0.0.8.0",
          "P-4516V-7.7.0-7.8.0",
          "P-2136(Security)V-12.0.0.4.0-15.0.1.0.0",
          "P-2283V-8.0.0.5.0",
          "P-14565V-2.0.0.0.0",
          "P-9633(Tools And Frameworks)V-11.4.0",
          "P-14324V-14.5.0.0.0-14.8.0.0.0"
        ],
        "known_not_affected": [
          "P-14015V-19.1.0.0.0-19.1.0.0.12",
          "P-5758V-23.1.0.0.0-23.4.0.0.0",
          "P-5760V-23.4-23.9",
          "P-1870V-22.1.1.1.0-22.1.1.35.0",
          "P-1870V-18.1.4.1.0-18.1.4.53.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14130V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105448.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14121V-24.2.7-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105418.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2136(Security)V-12.0.0.4.0-15.0.1.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105317.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9633(Tools And Frameworks)V-11.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106894.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2545V-12.2.1.4.0",
            "P-2545V-14.1.1.0.0",
            "P-2545V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105435.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14324V-14.5.0.0.0-14.8.0.0.0"
          ],
          "url": "https://support.oracle.com"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-24.2.7-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105404.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5758V-23.1.0.0.0-23.4.0.0.0",
            "P-5760V-23.4-23.9",
            "P-14015V-19.1.0.0.0-19.1.0.0.12",
            "P-1870V-22.1.1.1.0-22.1.1.35.0",
            "P-1870V-18.1.4.1.0-18.1.4.53.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11513V-22.0.2",
            "P-11513V-24.0.1",
            "P-11513V-23.0.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104399.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11607V-23.2.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106506.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.7.0-7.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105322.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2283V-8.0.0.5.0",
            "P-2283V-8.1.0.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105310.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9437V-15.0.0.0.0-15.0.1.0.0",
            "P-9437V-12.0.0.4.0-12.0.0.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3107602.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2270V-7.5.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105308.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2269V-15.0.0.0.0-15.0.1.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105311.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4623V-12.0.6.0.0",
            "P-4623V-15.0.0.0.0-15.0.1.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105320.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14565V-2.0.0.0.0",
            "P-14565V-2.0.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105318.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14119V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105405.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-9437V-15.0.0.0.0-15.0.1.0.0",
            "P-2545V-12.2.1.4.0",
            "P-14277V-24.2.7-25.1.200",
            "P-11513V-22.0.2",
            "P-4623V-12.0.6.0.0",
            "P-2270V-7.5.0",
            "P-14565V-2.0.0.1.0",
            "P-2545V-14.1.1.0.0",
            "P-11607V-23.2.5",
            "P-9437V-12.0.0.4.0-12.0.0.8.0",
            "P-14130V-25.1.200",
            "P-4516V-7.7.0-7.8.0",
            "P-2136(Security)V-12.0.0.4.0-15.0.1.0.0",
            "P-2283V-8.0.0.5.0",
            "P-2269V-15.0.0.0.0-15.0.1.0.0",
            "P-11513V-24.0.1",
            "P-14565V-2.0.0.0.0",
            "P-4623V-15.0.0.0.0-15.0.1.0.0",
            "P-14121V-24.2.7-25.1.200",
            "P-11513V-23.0.2",
            "P-2545V-14.1.2.0.0",
            "P-14119V-25.1.200",
            "P-14324V-14.5.0.0.0-14.8.0.0.0",
            "P-2283V-8.1.0.4.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-9633(Tools And Frameworks)V-11.4.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5760V-23.4-23.9"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14015V-19.1.0.0.0-19.1.0.0.12"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5758V-23.1.0.0.0-23.4.0.0.0",
            "P-1870V-22.1.1.1.0-22.1.1.35.0",
            "P-1870V-18.1.4.1.0-18.1.4.53.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-5758V-23.1.0.0.0-23.4.0.0.0",
            "P-5760V-23.4-23.9",
            "P-14015V-19.1.0.0.0-19.1.0.0.12",
            "P-1870V-22.1.1.1.0-22.1.1.35.0",
            "P-1870V-18.1.4.1.0-18.1.4.53.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-55212",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
          "text": "38362869"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Developer Infrastructure (ImageMagick)).  Supported versions that are affected are 5.1, 5.2 and  6.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Operations Monitor.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10761V-5.1",
          "P-10761V-6.0",
          "P-10761V-5.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10761V-5.1",
            "P-10761V-6.0",
            "P-10761V-5.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105430.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-55298",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
          "text": "38362869"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Developer Infrastructure (ImageMagick)).  Supported versions that are affected are 5.1, 5.2 and  6.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Operations Monitor.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10761V-5.1",
          "P-10761V-6.0",
          "P-10761V-5.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10761V-5.1",
            "P-10761V-6.0",
            "P-10761V-5.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105430.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-57803",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
          "text": "38362869"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Developer Infrastructure (ImageMagick)).  Supported versions that are affected are 5.1, 5.2 and  6.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Operations Monitor. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10761V-5.1",
          "P-10761V-6.0",
          "P-10761V-5.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10761V-5.1",
            "P-10761V-6.0",
            "P-10761V-5.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105430.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10761V-5.1",
            "P-10761V-6.0",
            "P-10761V-5.2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-58057",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
          "text": "38529036"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Configuration (Netty)).  Supported versions that are affected are 24.2.7-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14277V-24.2.7-25.1.200"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-24.2.7-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105404.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14277V-24.2.7-25.1.200"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-5878",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-4379V-21.7.3.0.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Essbase",
          "text": "38280269"
        },
        {
          "system_name": "Oracle Bug ID of Primavera Unifier",
          "text": "38292384"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform (Enterprise Security API for Java (Legacy))).  Supported versions that are affected are 20.12.0-20.12.16, 21.12.0-21.12.17, 22.12.0-22.12.15, 23.12.0-23.12.15 and  24.12.0-24.12.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera Unifier accessible data as well as  unauthorized read access to a subset of Primavera Unifier accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Primavera Unifier. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle Essbase (component: Security and Provisioning (Enterprise Security API)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10354V-20.12.0-20.12.16",
          "P-10354V-22.12.0-22.12.15",
          "P-10354V-23.12.0-23.12.15",
          "P-10354V-21.12.0-21.12.17",
          "P-10354V-24.12.0-24.12.9"
        ],
        "known_not_affected": [
          "P-4379V-21.7.3.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10354V-20.12.0-20.12.16",
            "P-10354V-22.12.0-22.12.15",
            "P-10354V-23.12.0-23.12.15",
            "P-10354V-21.12.0-21.12.17",
            "P-10354V-24.12.0-24.12.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106664.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4379V-21.7.3.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "P-10354V-20.12.0-20.12.16",
            "P-10354V-22.12.0-22.12.15",
            "P-10354V-23.12.0-23.12.15",
            "P-10354V-21.12.0-21.12.17",
            "P-10354V-24.12.0-24.12.9"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4379V-21.7.3.0.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-4379V-21.7.3.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-5889",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "38109293"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38396049"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Microservices (brace-expansion)).  Supported versions that are affected are 6.1.0-6.1.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 3.1 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Platform (brace-expansion)).  Supported versions that are affected are 24.2.0-24.2.1, 24.3.0, 25.1.100 and  25.1.200. Difficult to exploit vulnerability allows low privileged attacker with network access via RMI to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Network Analytics Data Director. CVSS 3.1 Base Score 3.1 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14547V-24.2.0-24.2.1",
          "P-14597V-6.1.0-6.1.1",
          "P-14547V-24.3.0",
          "P-14547V-25.1.200",
          "P-14547V-25.1.100"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-24.2.0-24.2.1",
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105450.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 3.1,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14547V-24.2.0-24.2.1",
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-14597V-6.1.0-6.1.1",
            "P-14547V-24.3.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-59375",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-5(Database)V-21.3-21.19",
            "P-5(Database)V-19.3-19.28",
            "P-5(Database)V-23.4-23.9"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition",
          "text": "38452616"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38452604"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Behavior Detection Platform",
          "text": "38452615"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
          "text": "38452603"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Database (Perl) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Third Party (LibExpat)).  Supported versions that are affected are 8.0.8.1, 8.1.2.9 and  8.1.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Behavior Detection Platform. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition product of Oracle Financial Services Applications (component: Platform (LibExpat)).   The supported version that is affected is 8.0.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Security (LibExpat)).  Supported versions that are affected are 7.7.0-7.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4516V-7.7.0-7.8.0",
          "P-13789V-8.0.8",
          "P-9190V-8.1.2.10",
          "P-9190V-8.1.2.9",
          "P-9190V-8.0.8.1"
        ],
        "known_not_affected": [
          "P-5(Database)V-21.3-21.19",
          "P-5(Database)V-23.4-23.9",
          "P-5(Database)V-19.3-19.28"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(Database)V-21.3-21.19",
            "P-5(Database)V-19.3-19.28",
            "P-5(Database)V-23.4-23.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9190V-8.1.2.9",
            "P-9190V-8.0.8.1",
            "P-9190V-8.1.2.10"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105116.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13789V-8.0.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105187.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.7.0-7.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105322.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(Database)V-21.3-21.19",
            "P-5(Database)V-19.3-19.28",
            "P-5(Database)V-23.4-23.9"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-4516V-7.7.0-7.8.0",
            "P-13789V-8.0.8",
            "P-9190V-8.1.2.9",
            "P-9190V-8.0.8.1",
            "P-9190V-8.1.2.10"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-5(Database)V-21.3-21.19",
            "P-5(Database)V-19.3-19.28",
            "P-5(Database)V-23.4-23.9"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-59474",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
          "text": "38448596"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Signaling (Jenkins)).  Supported versions that are affected are 24.2.5 and  25.1.202. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14118(Signaling)V-24.2.5",
          "P-14118(Signaling)V-25.1.202"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14118(Signaling)V-24.2.5",
            "P-14118(Signaling)V-25.1.202"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3107682.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-59475",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
          "text": "38448596"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Signaling (Jenkins)).  Supported versions that are affected are 24.2.5 and  25.1.202. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14118(Signaling)V-24.2.5",
          "P-14118(Signaling)V-25.1.202"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14118(Signaling)V-24.2.5",
            "P-14118(Signaling)V-25.1.202"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3107682.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-59476",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
          "text": "38448596"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Signaling (Jenkins)).  Supported versions that are affected are 24.2.5 and  25.1.202. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14118(Signaling)V-24.2.5",
          "P-14118(Signaling)V-25.1.202"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14118(Signaling)V-24.2.5",
            "P-14118(Signaling)V-25.1.202"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3107682.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-5987",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Workbench",
          "text": "38263939"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
          "text": "38263979"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Security (libssh)).  Supported versions that are affected are 7.7.0 and  7.8.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Inventory Management accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Inventory Management accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (libssh)).  Supported versions that are affected are 8.0.0-8.0.43. Easily exploitable vulnerability allows low privileged attacker with network access via MySQL Workbench to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Workbench accessible data as well as  unauthorized read access to a subset of MySQL Workbench accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4627V-8.0.0-8.0.43",
          "P-4516V-7.7.0",
          "P-4516V-7.8.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.7.0",
            "P-4516V-7.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105322.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4627V-8.0.0-8.0.43"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-6021",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
          "text": "38315800"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Configuration (libxml2)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Certificate Management executes to compromise Oracle Communications Cloud Native Core Certificate Management.  While the vulnerability is in Oracle Communications Cloud Native Core Certificate Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Certificate Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Certificate Management.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14868V-25.1.200"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14868V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105451.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-61748",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38044235"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).  Supported versions that are affected are Oracle Java SE: 21.0.8 and  25; Oracle GraalVM for JDK: 21.0.8; Oracle GraalVM Enterprise Edition: 21.3.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data.  Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-21.0.8",
          "P-856V-25",
          "P-13497V-21.3.15",
          "P-13497V-21.0.8"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-21.0.8",
            "P-856V-25",
            "P-13497V-21.3.15",
            "P-13497V-21.0.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104405.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-856V-21.0.8",
            "P-856V-25",
            "P-13497V-21.3.15",
            "P-13497V-21.0.8"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Emad Al-Mousa"
          ]
        }
      ],
      "cve": "CVE-2025-61749",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38044922"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Unified Audit component of Oracle Database Server.  Supported versions that are affected are 23.4-23.9. Easily exploitable vulnerability allows high privileged attacker having DBA privilege with network access via Oracle Net to compromise Unified Audit.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Unified Audit accessible data. CVSS 3.1 Base Score 2.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5(Unified Audit)V-23.4-23.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(Unified Audit)V-23.4-23.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 2.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(Unified Audit)V-23.4-23.9"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-61750",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "38057878"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Query).  Supported versions that are affected are 8.61 and  8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.61",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106893.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5085V-8.61",
            "P-5085V-8.62"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Spike Reply Cyber Security Team"
          ]
        }
      ],
      "cve": "CVE-2025-61751",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
          "text": "37285555"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform).  Supported versions that are affected are 8.0.7.9, 8.0.8.7 and  8.1.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Analytical Applications Infrastructure accessible data as well as  unauthorized access to critical data or complete access to all Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5680V-8.1.2.5",
          "P-5680V-8.0.7.9",
          "P-5680V-8.0.8.7"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.7.9",
            "P-5680V-8.0.8.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104221.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.7.9",
            "P-5680V-8.0.8.7"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-61752",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle WebLogic Server",
          "text": "38237316"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 14.1.1.0.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5242V-14.1.1.0.0",
          "P-5242V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5242V-14.1.1.0.0",
            "P-5242V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105435.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-5242V-14.1.1.0.0",
            "P-5242V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-61753",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Scripting",
          "text": "38145576"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous).  Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Scripting, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Scripting accessible data as well as  unauthorized read access to a subset of Oracle Scripting accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-433V-12.2.3-12.2.14"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-433V-12.2.3-12.2.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2484000.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-433V-12.2.3-12.2.14"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-61754",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle BI Publisher",
          "text": "38199705"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API).  Supported versions that are affected are 7.6.0.0.0 and  8.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1479V-8.2.0.0.0",
          "P-1479V-7.6.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1479V-7.6.0.0.0",
            "P-1479V-8.2.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105456.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1479V-7.6.0.0.0",
            "P-1479V-8.2.0.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-61755",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle GraalVM for JDK",
          "text": "38246517"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Compiler).  Supported versions that are affected are Oracle GraalVM for JDK: 17.0.16 and  21.0.8. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GraalVM for JDK.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle GraalVM for JDK accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13497V-21.0.8",
          "P-13497V-17.0.16"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13497V-21.0.8",
            "P-13497V-17.0.16"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104405.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-13497V-21.0.8",
            "P-13497V-17.0.16"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Nguyen Tuong Huy"
          ],
          "organization": "HDBank"
        }
      ],
      "cve": "CVE-2025-61756",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
          "text": "38168853"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: System Configuration).  Supported versions that are affected are 8.0.7.9, 8.0.8.7 and  8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Analytical Applications Infrastructure. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5680V-8.1.2.5",
          "P-5680V-8.0.7.9",
          "P-5680V-8.0.8.7"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.7.9",
            "P-5680V-8.0.8.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104221.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.7.9",
            "P-5680V-8.0.8.7"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Adam Kues"
          ],
          "organization": "Assetnote"
        },
        {
          "names": [
            "Shubham Shah"
          ],
          "organization": "Assetnote"
        }
      ],
      "cve": "CVE-2025-61757",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Identity Manager",
          "text": "38264329"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager.  Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1980V-12.2.1.4.0",
          "P-1980V-14.1.2.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1980V-14.1.2.1.0",
            "P-1980V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105435.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-1980V-14.1.2.1.0",
            "P-1980V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-61758",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise FIN IT Asset Management",
          "text": "38275061"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise FIN IT Asset Management product of Oracle PeopleSoft (component: IT Asset Management).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN IT Asset Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN IT Asset Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5000V-9.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5000V-9.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106893.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5000V-9.2"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Prison Break (Gangmin Kim, Sangbin Kim, Hanseo Kim, Sangwon Oh, Sanghoon Lee, Wonjoon Hwang) working with Trend Micro Zero Day Initiative"
          ]
        }
      ],
      "cve": "CVE-2025-61759",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "38285134"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are 7.1.12 and  7.2.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.2.2",
          "P-8370V-7.1.12"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.2.2",
            "P-8370V-7.1.12"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106491.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.2.2",
            "P-8370V-7.1.12"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Andrey Chizhov"
          ]
        },
        {
          "names": [
            "Pavel Blinnikov"
          ]
        }
      ],
      "cve": "CVE-2025-61760",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "38317402"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are 7.1.12 and  7.2.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.2.2",
          "P-8370V-7.1.12"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.2.2",
            "P-8370V-7.1.12"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106491.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.2.2",
            "P-8370V-7.1.12"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-61761",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise FIN Maintenance Management",
          "text": "38324512"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise FIN Maintenance Management product of Oracle PeopleSoft (component: Work Order Management).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Maintenance Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN Maintenance Management accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise FIN Maintenance Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5001V-9.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5001V-9.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106893.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5001V-9.2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-61762",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise FIN Payables",
          "text": "38324562"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise FIN Payables product of Oracle PeopleSoft (component: Payables).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Payables.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN Payables accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise FIN Payables accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise FIN Payables. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5008V-9.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5008V-9.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106893.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "P-5008V-9.2"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Chan Yiu Tsoi"
          ],
          "organization": "Maximus Consulting (HK) Ltd"
        }
      ],
      "cve": "CVE-2025-61763",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Essbase",
          "text": "38371423"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Essbase (component: Essbase Web Platform).   The supported version that is affected is 21.7.3.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Essbase.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Essbase accessible data as well as  unauthorized access to critical data or complete access to all Oracle Essbase accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4379V-21.7.3.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4379V-21.7.3.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4379V-21.7.3.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-61764",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle WebLogic Server",
          "text": "38171394"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5242V-12.2.1.4.0",
          "P-5242V-14.1.2.0.0",
          "P-5242V-14.1.1.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5242V-14.1.1.0.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105435.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5242V-14.1.1.0.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-61881",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38245292"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Java VM component of Oracle Database Server.  Supported versions that are affected are 19.3-19.28, 21.3-21.19 and  23.4-23.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Java VM.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Java VM accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5(Java VM)V-19.3-19.28",
          "P-5(Java VM)V-23.4-23.9",
          "P-5(Java VM)V-21.3-21.19"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(Java VM)V-19.3-19.28",
            "P-5(Java VM)V-23.4-23.9",
            "P-5(Java VM)V-21.3-21.19"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(Java VM)V-19.3-19.28",
            "P-5(Java VM)V-23.4-23.9",
            "P-5(Java VM)V-21.3-21.19"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-61885",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Life Sciences InForm",
          "text": "34492271"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Life Sciences InForm product of Oracle Health Sciences Applications (component: Web Server).   The supported version that is affected is 7.0.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Life Sciences InForm.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Life Sciences InForm accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9636V-7.0.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9636V-7.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3107167.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9636V-7.0.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-62287",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Life Sciences InForm",
          "text": "35645867"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Life Sciences InForm product of Oracle Health Sciences Applications (component: Web Server).   The supported version that is affected is 7.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Life Sciences InForm.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Life Sciences InForm, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Life Sciences InForm accessible data as well as  unauthorized read access to a subset of Oracle Life Sciences InForm accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9636V-7.0.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9636V-7.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3107167.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9636V-7.0.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-62288",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Health Sciences Data Management Workbench",
          "text": "37213342"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Health Sciences Data Management Workbench product of Oracle Health Sciences Applications (component: Logger).  Supported versions that are affected are 3.4.0.1.3 and  3.4.1.0.10. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Health Sciences Data Management Workbench.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Health Sciences Data Management Workbench accessible data. CVSS 3.1 Base Score 4.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9581V-3.4.0.1.3",
          "P-9581V-3.4.1.0.10"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9581V-3.4.0.1.3",
            "P-9581V-3.4.1.0.10"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3107167.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9581V-3.4.0.1.3",
            "P-9581V-3.4.1.0.10"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-62289",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle ZFS Storage Appliance Kit",
          "text": "36836501"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Filesystems).   The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10026V-8.8"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10026V-8.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106603.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10026V-8.8"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-62290",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle ZFS Storage Appliance Kit",
          "text": "36837407"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage).   The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit.  Successful attacks of this vulnerability can result in takeover of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10026V-8.8"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10026V-8.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106603.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10026V-8.8"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-62475",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle ZFS Storage Appliance Kit",
          "text": "37705837"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core).   The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10026V-8.8"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10026V-8.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106603.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10026V-8.8"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-62476",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle ZFS Storage Appliance Kit",
          "text": "37928215"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Remote Replication).   The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10026V-8.8"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10026V-8.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106603.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10026V-8.8"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-62477",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle ZFS Storage Appliance Kit",
          "text": "37928251"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Remote Replication).   The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10026V-8.8"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10026V-8.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106603.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10026V-8.8"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-62478",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle ZFS Storage Appliance Kit",
          "text": "37928394"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Object Store).   The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10026V-8.8"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10026V-8.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106603.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10026V-8.8"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-62479",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle ZFS Storage Appliance Kit",
          "text": "37951407"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage).   The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score 2.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10026V-8.8"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10026V-8.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106603.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 2.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-10026V-8.8"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-62480",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle ZFS Storage Appliance Kit",
          "text": "37951806"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Naming Subsystem).   The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score 2.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10026V-8.8"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10026V-8.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106603.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 2.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-10026V-8.8"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Maxime Escourbiac"
          ],
          "organization": "Michelin CERT"
        },
        {
          "names": [
            "Yassine Bengana"
          ],
          "organization": "Michelin CERT"
        }
      ],
      "cve": "CVE-2025-62481",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Marketing",
          "text": "38510969"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration).  Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing.  Successful attacks of this vulnerability can result in takeover of Oracle Marketing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-229V-12.2.3-12.2.14"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-229V-12.2.3-12.2.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2484000.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-229V-12.2.3-12.2.14"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Kentaro Kawane"
          ],
          "organization": "GMO Cybersecurity by Ierae"
        }
      ],
      "cve": "CVE-2025-62587",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "38507331"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are 7.1.12 and  7.2.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.2.2",
          "P-8370V-7.1.12"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.2.2",
            "P-8370V-7.1.12"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106491.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.2.2",
            "P-8370V-7.1.12"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "VMBreakers (GANGMIN KIM, SANGBIN KIM, Un3xploitable) working with Trend Micro Zero Day Initiative"
          ]
        }
      ],
      "cve": "CVE-2025-62588",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "38507896"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are 7.1.12 and  7.2.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.2.2",
          "P-8370V-7.1.12"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.2.2",
            "P-8370V-7.1.12"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106491.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.2.2",
            "P-8370V-7.1.12"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "VMBreakers (GANGMIN KIM, SANGBIN KIM, Un3xploitable) working with Trend Micro Zero Day Initiative"
          ]
        }
      ],
      "cve": "CVE-2025-62589",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "38507937"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are 7.1.12 and  7.2.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.2.2",
          "P-8370V-7.1.12"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.2.2",
            "P-8370V-7.1.12"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106491.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.2.2",
            "P-8370V-7.1.12"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "VMBreakers (GANGMIN KIM, SANGBIN KIM, Un3xploitable) working with Trend Micro Zero Day Initiative"
          ]
        }
      ],
      "cve": "CVE-2025-62590",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "38507957"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are 7.1.12 and  7.2.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.2.2",
          "P-8370V-7.1.12"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.2.2",
            "P-8370V-7.1.12"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106491.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.2.2",
            "P-8370V-7.1.12"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "VMBreakers (GANGMIN KIM, SANGBIN KIM, Un3xploitable) working with Trend Micro Zero Day Initiative"
          ]
        }
      ],
      "cve": "CVE-2025-62591",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "38507823"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are 7.1.12 and  7.2.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.2.2",
          "P-8370V-7.1.12"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.2.2",
            "P-8370V-7.1.12"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106491.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.0,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.2.2",
            "P-8370V-7.1.12"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Andrey Chizhov"
          ]
        },
        {
          "names": [
            "Pavel Blinnikov"
          ]
        }
      ],
      "cve": "CVE-2025-62592",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "38535132"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are 7.1.12 and  7.2.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.2.2",
          "P-8370V-7.1.12"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.2.2",
            "P-8370V-7.1.12"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106491.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.0,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.2.2",
            "P-8370V-7.1.12"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "VMBreakers (GANGMIN KIM, SANGBIN KIM, Un3xploitable) working with Trend Micro Zero Day Initiative"
          ]
        }
      ],
      "cve": "CVE-2025-62641",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "38507947"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are 7.1.12 and  7.2.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.2.2",
          "P-8370V-7.1.12"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.2.2",
            "P-8370V-7.1.12"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106491.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.2.2",
            "P-8370V-7.1.12"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-6395",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
          "text": "38206360"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Security (GnuTLS)).  Supported versions that are affected are 7.7.0-7.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management as well as  unauthorized update, insert or delete access to some of Oracle Communications Unified Inventory Management accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4516V-7.7.0-7.8.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.7.0-7.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105322.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-6491",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-1522V-19.1.0.1.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Secure Backup",
          "text": "38268922"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle Secure Backup (component: Oracle Secure Backup (PHP)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-1522V-19.1.0.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1522V-19.1.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1522V-19.1.0.1.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-1522V-19.1.0.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-6558",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38167315"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (WebKitGTK)).  Supported versions that are affected are Oracle Java SE: 8u461-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u461-b50"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u461-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3104405.1"
        }
      ]
    },
    {
      "cve": "CVE-2025-6965",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Converged Charging System",
          "text": "38201004"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Workbench",
          "text": "38200993"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Convergent Charging Controller",
          "text": "38201005"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
          "text": "38201024"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
          "text": "38201002"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
          "text": "38201003"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Charging and Control",
          "text": "38201011"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38201012"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "38201010"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
          "text": "38315823"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Messaging Server",
          "text": "38201008"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Automated Test Suite Framework (SQLite)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Converged Charging System product of Oracle Communications Applications (component: Installation (SQLite)).  Supported versions that are affected are 2.0.0.0.0-2.0.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Converged Charging System.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Converged Charging System. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Configuration (SQLite)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Certificate Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Messaging Server product of Oracle Communications Applications (component: Security (SQLite)).   The supported version that is affected is 8.1.0.28. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Messaging Server.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Messaging Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Core (SQLite)).  Supported versions that are affected are 24.2.0-24.2.1, 24.3.0, 25.1.100 and  25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Network Analytics Data Director. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Charging and Control product of Oracle Communications Applications (component: Data Access Pack (SQLite)).  Supported versions that are affected are 12.0.1.0.0-12.0.6.0.0, 15.0.0.0.0-15.0.1.0.0 and  15.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Charging and Control.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Network Charging and Control. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (SQLite)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (SQLite)).   The supported version that is affected is 8.1.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Compliance Studio. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (SQLite)).  Supported versions that are affected are 24.2.7-25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (SQLite)).  Supported versions that are affected are 8.0.0-8.0.43. Easily exploitable vulnerability allows unauthenticated attacker with network access via MySQL Workbench to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in takeover of MySQL Workbench. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications Applications (component: Data Access Pack (SQLite)).  Supported versions that are affected are 12.0.1.0.0-12.0.6.0.0, 15.0.0.0.0-15.0.1.0.0 and  15.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Convergent Charging Controller.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Convergent Charging Controller. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8496V-8.1.0.28",
          "P-14547V-24.2.0-24.2.1",
          "P-12985V-12.0.1.0.0-12.0.6.0.0",
          "P-12985V-15.1.0.0.0",
          "P-12985V-15.0.0.0.0-15.0.1.0.0",
          "P-14547V-25.1.200",
          "P-14547V-25.1.100",
          "P-14277V-24.2.7-25.1.200",
          "P-4623V-15.1.0.0.0",
          "P-14597V-6.1.0-6.1.1",
          "P-14547V-24.3.0",
          "P-14565V-2.0.0.0.0-2.0.0.1.0",
          "P-14392V-8.1.2.8",
          "P-4627V-8.0.0-8.0.43",
          "P-14868V-25.1.200",
          "P-4623V-15.0.0.0.0-15.0.1.0.0",
          "P-14119V-25.1.200",
          "P-4623V-12.0.1.0.0-12.0.6.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14119V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105405.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14565V-2.0.0.0.0-2.0.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105318.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14868V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105451.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8496V-8.1.0.28"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105321.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-24.2.0-24.2.1",
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105450.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-12985V-12.0.1.0.0-12.0.6.0.0",
            "P-12985V-15.1.0.0.0",
            "P-12985V-15.0.0.0.0-15.0.1.0.0",
            "P-4623V-15.1.0.0.0",
            "P-4623V-15.0.0.0.0-15.0.1.0.0",
            "P-4623V-12.0.1.0.0-12.0.6.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105320.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14392V-8.1.2.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3106412.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-24.2.7-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105404.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4627V-8.0.0-8.0.43"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105343.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8496V-8.1.0.28",
            "P-14547V-24.2.0-24.2.1",
            "P-12985V-12.0.1.0.0-12.0.6.0.0",
            "P-12985V-15.1.0.0.0",
            "P-12985V-15.0.0.0.0-15.0.1.0.0",
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-14277V-24.2.7-25.1.200",
            "P-4623V-15.1.0.0.0",
            "P-14597V-6.1.0-6.1.1",
            "P-14547V-24.3.0",
            "P-14565V-2.0.0.0.0-2.0.0.1.0",
            "P-14392V-8.1.2.8",
            "P-4627V-8.0.0-8.0.43",
            "P-14868V-25.1.200",
            "P-4623V-15.0.0.0.0-15.0.1.0.0",
            "P-14119V-25.1.200",
            "P-4623V-12.0.1.0.0-12.0.6.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-7339",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38396151"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Microservices (on-headers)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 3.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.0-6.1.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 3.4,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.1.0-6.1.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-7425",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
          "text": "38315800"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Configuration (libxml2)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Certificate Management executes to compromise Oracle Communications Cloud Native Core Certificate Management.  While the vulnerability is in Oracle Communications Cloud Native Core Certificate Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Certificate Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Certificate Management. CVSS 3.1 Base Score 7.8 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14868V-25.1.200"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14868V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105451.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14868V-25.1.200"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-7962",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Console",
          "text": "38430405"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Configuration (Jakarta Mail)).  Supported versions that are affected are 24.2.5 and  25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Console accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14250V-24.2.5",
          "P-14250V-25.1.200"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14250V-25.1.200",
            "P-14250V-24.2.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105453.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14250V-25.1.200",
            "P-14250V-24.2.5"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-8058",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Session Border Controller",
          "text": "38362590"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
          "text": "38362581"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Enterprise Communications Broker",
          "text": "38505502"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Converged Charging System",
          "text": "38362583"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Enterprise Operations Monitor",
          "text": "38362562"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
          "text": "38362574"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
          "text": "38430938"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
          "text": "38362585"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38362587"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
          "text": "38362577"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
          "text": "38362589"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
          "text": "38362578"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Enterprise Operations Monitor product of Oracle Communications (component: Infrastructure (glibc)).  Supported versions that are affected are 5.1, 5.2 and  6.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise Operations Monitor executes to compromise Oracle Enterprise Operations Monitor.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Enterprise Operations Monitor accessible data as well as  unauthorized read access to a subset of Oracle Enterprise Operations Monitor accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Operations Monitor. CVSS 3.1 Base Score 4.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (glibc)).  Supported versions that are affected are 24.2.7-25.1.200. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Binding Support Function executes to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Binding Support Function accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Binding Support Function accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 4.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Enterprise Communications Broker product of Oracle Communications (component: Routing (glibc)).  Supported versions that are affected are 4.1.0 and  4.2.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise Communications Broker executes to compromise Oracle Enterprise Communications Broker.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Enterprise Communications Broker accessible data as well as  unauthorized read access to a subset of Oracle Enterprise Communications Broker accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Communications Broker. CVSS 3.1 Base Score 4.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Install (glibc)).   The supported version that is affected is 25.1.201. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Security Edge Protection Proxy executes to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 4.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Session Border Controller product of Oracle Communications (component: Routing (glibc)).  Supported versions that are affected are 9.3.0 and  10.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Session Border Controller executes to compromise Oracle Communications Session Border Controller.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Session Border Controller accessible data as well as  unauthorized read access to a subset of Oracle Communications Session Border Controller accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Session Border Controller. CVSS 3.1 Base Score 4.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Security Component (glibc)).  Supported versions that are affected are 7.7.0-7.8.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Unified Inventory Management executes to compromise Oracle Communications Unified Inventory Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Inventory Management accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Inventory Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 4.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (glibc)).   The supported version that is affected is 25.1.200. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Network Slice Selection Function executes to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Network Slice Selection Function accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Network Slice Selection Function accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function. CVSS 3.1 Base Score 4.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (glibc)).  Supported versions that are affected are 24.2.7-25.1.200. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Policy executes to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Policy accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Policy accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 4.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Signaling (glibc)).  Supported versions that are affected are 25.1.200 and  25.2.100. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Service Communication Proxy executes to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Service Communication Proxy accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Service Communication Proxy accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 4.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Converged Charging System product of Oracle Communications Applications (component: Installation (glibc)).  Supported versions that are affected are 2.0.0.0.0-2.0.0.1.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Converged Charging System executes to compromise Oracle Communications Converged Charging System.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Converged Charging System accessible data as well as  unauthorized read access to a subset of Oracle Communications Converged Charging System accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Converged Charging System. CVSS 3.1 Base Score 4.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: ATS Framework (glibc)).   The supported version that is affected is 9.1.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Diameter Signaling Router executes to compromise Oracle Communications Diameter Signaling Router.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Diameter Signaling Router accessible data as well as  unauthorized read access to a subset of Oracle Communications Diameter Signaling Router accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 4.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (glibc)).  Supported versions that are affected are 6.1.0-6.1.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 4.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10750V-10.0.0",
          "P-10762V-5.2",
          "P-10758V-4.2.0",
          "P-14117V-25.1.200",
          "P-10762V-5.1",
          "P-10762V-6.0",
          "P-10758V-4.1.0",
          "P-14277V-24.2.7-25.1.200",
          "P-14597V-6.1.0-6.1.1",
          "P-10750V-9.3.0",
          "P-14565V-2.0.0.0.0-2.0.0.1.0",
          "P-14123V-25.1.201",
          "P-4516V-7.7.0-7.8.0",
          "P-14130V-25.1.200",
          "P-14117V-25.2.100",
          "P-10899V-9.1.0.0.0",
          "P-14121V-24.2.7-25.1.200"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10762V-5.2",
            "P-10762V-5.1",
            "P-10762V-6.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105434.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14121V-24.2.7-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105418.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10758V-4.2.0",
            "P-10758V-4.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105853.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14123V-25.1.201"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105449.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10750V-10.0.0",
            "P-10750V-9.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105851.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.7.0-7.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105322.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14130V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105448.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-24.2.7-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105404.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14117V-25.2.100",
            "P-14117V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105421.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14565V-2.0.0.0.0-2.0.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105318.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10899V-9.1.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105378.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105296.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.2,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "P-10750V-10.0.0",
            "P-10762V-5.2",
            "P-10758V-4.2.0",
            "P-14117V-25.1.200",
            "P-10762V-5.1",
            "P-10762V-6.0",
            "P-10758V-4.1.0",
            "P-14277V-24.2.7-25.1.200",
            "P-14597V-6.1.0-6.1.1",
            "P-10750V-9.3.0",
            "P-14565V-2.0.0.0.0-2.0.0.1.0",
            "P-14123V-25.1.201",
            "P-4516V-7.7.0-7.8.0",
            "P-14130V-25.1.200",
            "P-14117V-25.2.100",
            "P-10899V-9.1.0.0.0",
            "P-14121V-24.2.7-25.1.200"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-8885",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters",
          "text": "38367611"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: Java Delivery (Bouncy Castle Java FIPS)).  Supported versions that are affected are 21.3-21.19 and  23.4-23.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle GoldenGate Big Data and Application Adapters.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GoldenGate Big Data and Application Adapters. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5760V-21.3-21.19",
          "P-5760V-23.4-23.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5760V-23.4-23.9",
            "P-5760V-21.3-21.19"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-5760V-23.4-23.9",
            "P-5760V-21.3-21.19"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-8916",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Essbase",
          "text": "38372558"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Global Lifecycle Management NextGen OUI Framework",
          "text": "38416318"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management",
          "text": "38315852"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters",
          "text": "38367181"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Configuration (Bouncy Castle Java Library)).   The supported version that is affected is 25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Certificate Management. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in Oracle Essbase (component: Security and Provisioning (Bouncy Castle Java Library)).   The supported version that is affected is 21.7.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Essbase.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Essbase. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: Java Delivery (Bouncy Castle Java Library)).  Supported versions that are affected are 23.4-23.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle GoldenGate Big Data and Application Adapters.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GoldenGate Big Data and Application Adapters. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Bouncy Castle Java Library)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Global Lifecycle Management NextGen OUI Framework.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Global Lifecycle Management NextGen OUI Framework. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-12738V-14.1.2.0.0",
          "P-4379V-21.7.3.0.0",
          "P-5760V-23.4-23.9",
          "P-14868V-25.1.200",
          "P-12738V-12.2.1.4.0",
          "P-12738V-14.1.1.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14868V-25.1.200"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105451.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5760V-23.4-23.9",
            "P-4379V-21.7.3.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-12738V-14.1.2.0.0",
            "P-12738V-12.2.1.4.0",
            "P-12738V-14.1.1.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105435.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14868V-25.1.200",
            "P-4379V-21.7.3.0.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-5760V-23.4-23.9"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-12738V-14.1.2.0.0",
            "P-12738V-12.2.1.4.0",
            "P-12738V-14.1.1.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-9086",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-4379V-21.7.3.0.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
          "text": "38448051"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Essbase",
          "text": "38448057"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Security (curl)).  Supported versions that are affected are 7.7.0-7.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle Essbase (component: Essbase Web Platform (curl)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4516V-7.7.0-7.8.0"
        ],
        "known_not_affected": [
          "P-4379V-21.7.3.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.7.0-7.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3105322.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4379V-21.7.3.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-4516V-7.7.0-7.8.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4379V-21.7.3.0.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-4379V-21.7.3.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-9230",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-4379V-21.7.3.0.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Essbase",
          "text": "38511620"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle Essbase (component: Essbase Web Platform (OpenSSL)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-4379V-21.7.3.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4379V-21.7.3.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4379V-21.7.3.0.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-4379V-21.7.3.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-9232",
      "flags": [
        {
          "date": "2025-10-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-4379V-21.7.3.0.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Essbase",
          "text": "38511620"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle Essbase (component: Essbase Web Platform (OpenSSL)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-4379V-21.7.3.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4379V-21.7.3.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=3102899.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4379V-21.7.3.0.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-10-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-4379V-21.7.3.0.0"
          ]
        }
      ]
    }
  ]
}
View JSON API Download JSON