PatchSiren

Oracle CVE debriefs · Page 18

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-21954

The CVE-2026-21954 vulnerability affects Oracle Retail Xstore Point of Service version 21.0.3, allowing low-privileged attackers with network access via HTTP to compromise the product and gain unauthorized read access to a subset of accessible data. This medium-severity vulnerability, with a CVSS 3.1 Base Score of 4.3, can be exploited through common network attack vectors. Affected organizations should p [truncated]

MEDIUM Oracle CVE published 2026-05-06

CVE-2026-35253

CVE-2026-35253 is a medium-severity vulnerability in Oracle's Macoron Tool, published on 2026-05-06 and last modified on 2026-05-10. The NVD entry identifies version v0.22.0 as affected and describes an unauthenticated network-access attack over HTTP that can cause the tool to fail host address validation. The record was still listed as "Undergoing Analysis" in the provided source corpus at the time of th [truncated]

MEDIUM Oracle CVE published 2026-04-21

CVE-2026-35244

The CVE-2026-35244 vulnerability affects Oracle Hyperion Infrastructure Technology version 11.2.24.0.000, classified as an easily exploitable vulnerability allowing high-privileged attackers with network access via HTTP to compromise the system. Successful attacks require human interaction and can result in unauthorized creation, deletion, or modification access to critical data or all Oracle Hyperion Inf [truncated]

MEDIUM Oracle CVE published 2026-04-21

CVE-2026-34314

CVE-2026-34314 is a vulnerability in Oracle Financial Services Analytical Applications Infrastructure (Platform component) that Oracle and NVD describe as affecting supported versions 8.0.7.9, 8.0.8.7, and 8.1.2.5. The published impact is serious for data security: a low-privileged attacker with network access via HTTP may be able to compromise the application and create, delete, or modify critical data, [truncated]

Known exploited Oracle CVE published 2025-11-21

CVE-2025-61757

CVE-2025-61757 is a high-priority Oracle Fusion Middleware issue involving missing authentication for a critical function. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-11-21, so organizations should treat it as urgent and validate exposure immediately. The supplied source metadata points to Oracle guidance in the October 2025 critical patch update and to the NVD record for further detail.

Known exploited Oracle CVE published 2025-10-20

CVE-2025-61884

CVE-2025-61884 is a server-side request forgery (SSRF) vulnerability in Oracle E-Business Suite. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-10-20, which means the issue is confirmed to be under active exploitation. CISA also marks it as having known ransomware campaign use, making this a high-priority issue for defenders running Oracle E-Business Suite.

Known exploited Oracle CVE published 2025-10-06

CVE-2025-61882

CVE-2025-61882 is a CISA Known Exploited Vulnerabilities (KEV) entry affecting Oracle E-Business Suite. The supplied corpus identifies it as an unspecified vulnerability and states that it has known exploitation, including known ransomware campaign use. Because this vulnerability is already in CISA's KEV catalog, defenders should treat it as a high-priority remediation item and follow Oracle's mitigation [truncated]

Known exploited Oracle CVE published 2025-02-24

CVE-2024-20953

CVE-2024-20953 is an Oracle Agile Product Lifecycle Management (PLM) deserialization vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2025-02-24. Because it is in KEV, defenders should treat it as actively exploited and prioritize Oracle’s vendor guidance and any available mitigations.

Known exploited Oracle CVE published 2025-01-07

CVE-2020-2883

CVE-2020-2883 is a CISA Known Exploited Vulnerability affecting Oracle WebLogic Server. In the supplied KEV record, CISA added it on 2025-01-07 and set a remediation due date of 2025-01-28. The entry classifies the issue as an unspecified vulnerability and directs defenders to apply vendor mitigations or discontinue use of the product if mitigations are unavailable.

Known exploited Oracle CVE published 2024-11-21

CVE-2024-21287

CVE-2024-21287 is an Oracle Agile Product Lifecycle Management (PLM) incorrect authorization vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-11-21. Because it is listed in KEV, affected organizations should treat it as an active exposure and prioritize Oracle’s vendor guidance, mitigation, or replacement steps if patching is not available.

Known exploited Oracle CVE published 2024-09-18

CVE-2022-21445

CVE-2022-21445 affects Oracle ADF Faces and is listed by CISA in the Known Exploited Vulnerabilities catalog as of 2024-09-18. CISA’s guidance for this item is to apply vendor mitigations or discontinue use of the product if mitigations are unavailable. Because KEV inclusion indicates known exploitation, affected Oracle ADF Faces deployments should be treated as a remediation priority rather than a routin [truncated]

Known exploited Oracle CVE published 2024-09-18

CVE-2020-14644

CVE-2020-14644 is a CISA Known Exploited Vulnerability affecting Oracle WebLogic Server. Because CISA has added it to the KEV catalog, organizations running WebLogic Server should treat it as a priority remediation item and follow Oracle and CISA guidance without delay.

Known exploited Oracle CVE published 2024-06-03

CVE-2017-3506

CVE-2017-3506 is an Oracle WebLogic Server OS command injection vulnerability. CISA listed it in the Known Exploited Vulnerabilities catalog on 2024-06-03 and set a remediation due date of 2024-06-24, making this an urgent priority for WebLogic Server defenders.

Known exploited Oracle CVE published 2023-11-16

CVE-2020-2551

CVE-2020-2551 is an Oracle Fusion Middleware unspecified vulnerability that CISA has added to its Known Exploited Vulnerabilities catalog. Because CISA classifies it as known exploited, defenders should treat remediation as urgent even though the supplied corpus does not include technical details, affected versions, or CVSS scoring. CISA’s required action is to apply mitigations per vendor instructions or [truncated]

Known exploited Oracle CVE published 2023-05-12

CVE-2016-3427

CVE-2016-3427 is listed by CISA in the Known Exploited Vulnerabilities catalog for Oracle Java SE and JRockit. The public record does not provide a more specific technical breakdown, but it does direct defenders to apply updates per vendor instructions. In the supplied KEV record, CISA added the entry on 2023-05-12 and set a remediation due date of 2023-06-02.

Known exploited Oracle CVE published 2023-05-01

CVE-2023-21839

CVE-2023-21839 is an Oracle WebLogic Server vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. The public record supplied here does not provide technical specifics or a CVSS score, but it does require defenders to treat affected WebLogic Server deployments as a priority for remediation and to follow vendor update guidance.

Known exploited Oracle CVE published 2023-02-02

CVE-2022-21587

CVE-2022-21587 is an Oracle E-Business Suite vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2023-02-02, with a remediation due date of 2023-02-23. The supplied corpus does not include technical details about the flaw, affected versions, or exploitation mechanics, so the safest takeaway is operational: treat it as an actively exploited Oracle E-Business Suite issue and prio [truncated]

Known exploited Oracle CVE published 2022-11-28

CVE-2021-35587

CVE-2021-35587 is an Oracle Fusion Middleware vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-11-28. The supplied source material does not describe the exact weakness or impact, so the safest conclusion is that it is a confirmed exploitation risk requiring prompt patching per Oracle's guidance. Because CISA set a remediation due date of 2022-12-19, organizations should [truncated]

Known exploited Oracle CVE published 2022-09-08

CVE-2018-2628

CVE-2018-2628 is listed by CISA in the Known Exploited Vulnerabilities catalog for Oracle WebLogic Server, which makes it a high-priority defensive issue even though the supplied corpus labels the weakness only as an "unspecified vulnerability." CISA added the entry on 2022-09-08 and set a remediation due date of 2022-09-29. The source notes point to Oracle's April 2018 CPU advisory, but the corpus does n [truncated]

Known exploited Oracle CVE published 2022-05-25

CVE-2019-3010

CVE-2019-3010 is an Oracle Solaris privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-05-25. That KEV listing is the key signal here: it indicates the issue has been observed as exploited and should be treated as a high-priority remediation item. The supplied corpus does not include CVSS scoring, so operational urgency should be driven by the KEV stat [truncated]

Known exploited Oracle CVE published 2022-05-25

CVE-2013-2423

CVE-2013-2423 is listed by CISA as a Known Exploited Vulnerability affecting Oracle Java Runtime Environment (JRE). In the supplied corpus, CISA added it to the KEV catalog on 2022-05-25 and set a remediation due date of 2022-06-15, with guidance to apply updates per vendor instructions. Because the source corpus does not provide technical exploitation details or a CVSS score, this should be handled as a [truncated]

Known exploited Oracle CVE published 2022-05-25

CVE-2013-0431

CVE-2013-0431 is an Oracle Java Runtime Environment (JRE) sandbox bypass vulnerability. In the supplied record, CISA lists it in the Known Exploited Vulnerabilities catalog, with known ransomware campaign use noted. Because it appears in KEV, defenders should treat it as a priority remediation item and apply vendor updates per Oracle guidance.

Known exploited Oracle CVE published 2022-05-25

CVE-2013-0422

CVE-2013-0422 is listed in CISA’s Known Exploited Vulnerabilities catalog as an Oracle Java Runtime Environment (JRE) remote code execution issue. CISA added it on 2022-05-25 and set a remediation due date of 2022-06-15. The supplied source instructs defenders to apply updates per vendor instructions.

Known exploited Oracle CVE published 2022-05-25

CVE-2012-1710

CVE-2012-1710 is an Oracle Fusion Middleware vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The public record provided here does not include the specific flaw type or affected version range, but the KEV listing means defenders should treat it as actively exploited and prioritize remediation using Oracle's update guidance.

Known exploited Oracle CVE published 2022-05-25

CVE-2010-0840

CVE-2010-0840 is listed by CISA as a Known Exploited Vulnerability affecting Oracle Java Runtime Environment (JRE). The supplied source corpus does not provide technical exploitation details, but the KEV listing indicates active real-world abuse and makes this a high-priority patching item for environments that still run affected Java runtimes.

Known exploited Oracle CVE published 2022-03-28

CVE-2013-2465

CVE-2013-2465 is an Oracle Java SE vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. In the supplied source data, CISA marks it as known exploited and notes known ransomware campaign use, which makes this a defensive priority for any environment still running Oracle Java SE or Java-dependent legacy applications.

Known exploited Oracle CVE published 2022-03-28

CVE-2012-5076

CVE-2012-5076 is an Oracle Java SE sandbox bypass vulnerability that CISA has included in its Known Exploited Vulnerabilities catalog. For defenders, the main takeaway is operational: treat affected Java SE installations as high priority for patching and follow Oracle’s update guidance. CISA’s KEV entry indicates known exploitation, and the catalog directs organizations to apply updates per vendor instructions.

Known exploited Oracle CVE published 2022-03-28

CVE-2012-0518

CVE-2012-0518 is listed by CISA as a Known Exploited Vulnerability for Oracle Fusion Middleware. The public record in this corpus labels it only as an unspecified vulnerability, so the safest response is to treat it as a validated exploitation risk and follow Oracle’s update guidance without delay.

Known exploited Oracle CVE published 2022-03-25

CVE-2019-2616

CVE-2019-2616 affects Oracle BI Publisher (formerly XML Publisher) and is described as an unauthorized access vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-25, which means it should be treated as a known-exploited issue and prioritized for remediation. The supplied corpus does not provide deeper technical root-cause details, affected versions, or exploit conditions.

Known exploited Oracle CVE published 2022-03-03

CVE-2015-4902

CVE-2015-4902 is listed by CISA as an Oracle Java SE integrity check vulnerability and is included in the Known Exploited Vulnerabilities catalog. That designation means defenders should treat it as a confirmed exploitation risk and prioritize remediation on any affected systems that still rely on Oracle Java SE.