PatchSiren

Oracle CVE debriefs · Page 19

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited Oracle CVE published 2022-03-03

CVE-2015-2590

CVE-2015-2590 is a remote code execution vulnerability affecting Oracle Java SE and Java SE Embedded. CISA lists it in the Known Exploited Vulnerabilities catalog, which makes it a priority remediation item. The safest response is to follow Oracle's update guidance, reduce exposure where possible, and verify that affected Java installations are patched.

Known exploited Oracle CVE published 2022-03-03

CVE-2012-4681

CVE-2012-4681 is an Oracle Java SE Runtime Environment (JRE) arbitrary code execution vulnerability that CISA added to the Known Exploited Vulnerabilities (KEV) catalog on 2022-03-03. CISA’s entry also marks it as known for ransomware campaign use. The defensive takeaway is straightforward: this is an actively exploited Oracle Java SE issue, so exposed or still-supported Java deployments should be priorit [truncated]

Known exploited Oracle CVE published 2022-03-03

CVE-2012-1723

CVE-2012-1723 is an Oracle Java SE Runtime Environment (JRE) arbitrary code execution vulnerability that CISA lists in the Known Exploited Vulnerabilities catalog. Because it is marked as known exploited, with known ransomware campaign use, it should be treated as a high-priority remediation item wherever Oracle Java SE/JRE remains in use.

Known exploited Oracle CVE published 2022-03-03

CVE-2012-0507

CVE-2012-0507 is an Oracle Java SE Runtime Environment (JRE) arbitrary code execution vulnerability that CISA has added to its Known Exploited Vulnerabilities catalog. Because CISA lists it as known exploited and notes known ransomware campaign use, this should be treated as a high-priority remediation item for any environment that still relies on affected Oracle Java SE / JRE deployments. CISA’s catalog [truncated]

Known exploited Oracle CVE published 2022-03-03

CVE-2011-3544

CVE-2011-3544 is listed in CISA’s Known Exploited Vulnerabilities catalog for Oracle Java SE JDK and JRE, described there as an Oracle Java SE Runtime Environment (JRE) arbitrary code execution vulnerability. Because CISA marked it as known exploited, organizations should treat remediation as urgent and apply vendor updates per Oracle guidance. The KEV entry was added on 2022-03-03 with a due date of 2022-03-24.

Known exploited Oracle CVE published 2022-03-03

CVE-2008-3431

CVE-2008-3431 affects Oracle VirtualBox and is listed by CISA in the Known Exploited Vulnerabilities catalog, which means it has been identified as a vulnerability with known exploitation. The supplied corpus names the issue as an insufficient input validation vulnerability, but does not provide vendor advisory text, affected version range, or patch details. From a defensive standpoint, this is a priority [truncated]

Known exploited Oracle CVE published 2022-02-10

CVE-2017-10271

CVE-2017-10271 is a remote code execution vulnerability in Oracle WebLogic Server. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-02-10, marked it as known ransomware campaign use, and set a remediation due date of 2022-08-10. The supplied corpus does not include a vendor advisory or version-specific impact details, so remediation should follow Oracle’s update guidance and be priorit [truncated]

Known exploited Oracle CVE published 2022-01-18

CVE-2020-14864

CVE-2020-14864 is an Oracle Business Intelligence Enterprise Edition path traversal issue that CISA lists in its Known Exploited Vulnerabilities catalog. For defenders, the key signal is not just the vulnerability class, but the fact that it was added to KEV, which means CISA considered it known to be exploited and therefore urgent to address. Oracle BI EE environments should be treated as high-priority a [truncated]

Known exploited Oracle CVE published 2022-01-10

CVE-2019-2725

CVE-2019-2725 is an Oracle WebLogic Server injection vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because it is marked as known exploited, and the supplied enrichment also notes known ransomware campaign use, organizations running WebLogic Server should treat remediation as urgent and follow Oracle’s update guidance without delay.

Known exploited Oracle CVE published 2021-11-03

CVE-2020-2555

CVE-2020-2555 is an Oracle Multiple Products remote code execution vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. The supplied official sources do not provide deeper technical detail, but KEV inclusion means defenders should treat it as an actively exploited issue and prioritize remediation using Oracle’s vendor guidance.

Known exploited Oracle CVE published 2021-11-03

CVE-2020-14883

CVE-2020-14883 is an Oracle WebLogic Server vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The public material provided here does not include technical detail beyond the vulnerability being unspecified, but the KEV entry indicates active exploitation risk significant enough to require patching. CISA’s required action is to apply updates per vendor instructions.

Known exploited Oracle CVE published 2021-11-03

CVE-2020-14882

CVE-2020-14882 is identified in the supplied corpus as an Oracle WebLogic Server remote code execution vulnerability. CISA includes it in the Known Exploited Vulnerabilities catalog, which indicates known real-world exploitation. The official defensive guidance in the source set is to apply updates per vendor instructions.

Known exploited Oracle CVE published 2021-11-03

CVE-2020-14871

CVE-2020-14871 affects Oracle Solaris and Zettabyte File System (ZFS) and is listed by CISA in the Known Exploited Vulnerabilities catalog. The supplied source corpus does not provide technical details of the flaw, but it does confirm that CISA considers it actively exploited and directs defenders to apply vendor updates.

Known exploited Oracle CVE published 2021-11-03

CVE-2020-14750

CVE-2020-14750 is cataloged by CISA as an Oracle WebLogic Server remote code execution vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 and listed a remediation due date of 2022-05-03, which makes it a high-priority issue for any environment running affected WebLogic Server instances. The supplied corpus does not include deeper technical details or CVSS scoring, so [truncated]

Known exploited Oracle CVE published 2021-11-03

CVE-2015-4852

CVE-2015-4852 is an Oracle WebLogic Server deserialization of untrusted data vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because it is marked as known exploited, organizations running WebLogic Server should treat remediation as urgent and follow Oracle's update guidance.

Known exploited Oracle CVE published 2021-11-03

CVE-2012-3152

CVE-2012-3152 is an Oracle Fusion Middleware vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The available public metadata is limited and does not describe the flaw in detail, but the KEV listing means defenders should treat it as a confirmed exploitation concern and prioritize vendor-directed remediation.

CRITICAL Oracle CVE published 2017-01-30

CVE-2017-5611

CVE-2017-5611 is a critical SQL injection vulnerability affecting WordPress before 4.7.2. The issue is in wp-includes/class-wp-query.php within WP_Query, and the CVE description says exploitation depends on an affected plugin or theme that mishandles a crafted post type name. WordPress 4.7.2 is the documented security release in the source corpus.

HIGH Oracle CVE published 2017-01-27

CVE-2017-3443

CVE-2017-3443 is a high-severity Oracle E-Business Suite Common Applications vulnerability in the User Interface subcomponent. Oracle and NVD describe it as network-reachable over HTTP, unauthenticated, and requiring human interaction, with successful attacks capable of exposing critical data and allowing unauthorized data modification in affected Common Applications environments. The issue affects suppor [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3442

CVE-2017-3442 is a high-severity vulnerability in Oracle E-Business Suite’s Customer Interaction History component, specifically the User Interface subcomponent. Oracle and NVD identify affected supported versions 12.1.1, 12.1.2, and 12.1.3. The issue is network reachable over HTTP and can be exploited by an unauthenticated attacker, but successful attacks require human interaction from someone other than [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3441

CVE-2017-3441 is a HIGH-severity Oracle Customer Interaction History vulnerability in Oracle E-Business Suite. Oracle states it is easily exploitable over HTTP by an unauthenticated attacker, but successful exploitation requires human interaction. If exploited, the issue can lead to unauthorized access to critical data, full access to Customer Interaction History data, and unauthorized update, insert, or [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3440

CVE-2017-3440 is a high-severity Oracle Customer Interaction History issue in Oracle E-Business Suite. Oracle’s January 2017 security advisory reference and the NVD record describe it as a network-reachable HTTP vulnerability that can be triggered only with human interaction from someone other than the attacker. If exploited, it can expose critical data and allow unauthorized data changes in the affected [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3439

CVE-2017-3439 is a high-severity Oracle E-Business Suite issue in the One-to-One Fulfillment user interface component. Oracle’s advisory and the NVD record describe it as easily exploitable over HTTP by an unauthenticated attacker, with successful attacks requiring human interaction. The documented impact includes unauthorized access to critical data and unauthorized update, insert, or delete access to so [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3438

CVE-2017-3438 is a high-severity Oracle One-to-One Fulfillment vulnerability in Oracle E-Business Suite’s User Interface component. NVD describes it as easily exploitable by an unauthenticated attacker with network access via HTTP, while also noting that successful exploitation requires human interaction from someone other than the attacker. Impact can include unauthorized access to critical data and unau [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3437

CVE-2017-3437 is a high-severity Oracle One-to-One Fulfillment vulnerability in Oracle E-Business Suite, published on 2017-01-27. NVD lists affected versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6. The issue is reachable over HTTP, requires no privileges, but does require user interaction from a person other than the attacker. Oracle/NVD describe the impact as unauthorized access to cr [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3436

CVE-2017-3436 is a high-severity Oracle E-Business Suite issue in the One-to-One Fulfillment component (User Interface). Oracle’s advisory and the NVD record describe it as easily exploitable over HTTP by an unauthenticated attacker, but with required human interaction. Successful exploitation may expose critical data and allow unauthorized data modification in affected One-to-One Fulfillment deployments.

HIGH Oracle CVE published 2017-01-27

CVE-2017-3435

CVE-2017-3435 is a high-severity Oracle E-Business Suite issue in the One-to-One Fulfillment user interface. NVD describes it as easily exploitable over HTTP by an unauthenticated network attacker, but requiring human interaction from someone other than the attacker. Oracle and NVD list affected supported versions from 12.1.1 through 12.2.6. The published impact centers on confidentiality and integrity, w [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3433

CVE-2017-3433 is a high-severity Oracle One-to-One Fulfillment vulnerability in Oracle E-Business Suite’s User Interface subcomponent. Oracle and NVD describe it as easily exploitable by an unauthenticated attacker with network access via HTTP, but successful attacks require human interaction from someone other than the attacker. Oracle’s affected versions in the supplied record are 12.1.1, 12.1.2, 12.1.3 [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3431

CVE-2017-3431 is a high-severity Oracle One-to-One Fulfillment vulnerability in Oracle E-Business Suite that can be reached over HTTP by an unauthenticated network attacker. Oracle and NVD list supported affected releases across 12.1.1 through 12.2.6, with successful attacks requiring user interaction and potentially exposing sensitive data or enabling data modification.

HIGH Oracle CVE published 2017-01-27

CVE-2017-3430

CVE-2017-3430 is a high-severity Oracle One-to-One Fulfillment vulnerability in Oracle E-Business Suite’s User Interface component. Oracle and NVD describe it as network-exploitable over HTTP by an unauthenticated attacker, with successful exploitation requiring human interaction from a person other than the attacker. The documented impact includes unauthorized access to critical data and unauthorized upd [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3429

CVE-2017-3429 is a high-severity Oracle One-to-One Fulfillment vulnerability in Oracle E-Business Suite’s user interface. According to the NVD record, it is network-reachable over HTTP, does not require authentication, and can be triggered with human interaction. Oracle and NVD list affected versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6. The stated impact is unauthorized access to se [truncated]