Oracle Agile Engineering Data Management vulnerabilities

30 known vulnerabilities affecting oracle/agile_engineering_data_management.

Total CVEs
30
CISA KEV
2
actively exploited
Public exploits
6
Exploited in wild
2
Severity breakdown
CRITICAL3HIGH12MEDIUM12LOW3

Vulnerabilities

Page 2 of 2
CVE-2019-0227HIGHCVSS 7.5PoCv6.2.1.02019-05-01
CVE-2019-0227 [HIGH] CWE-918 CVE-2019-0227: A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that wa A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to t
nvd
CVE-2018-8032MEDIUMCVSS 6.1v6.2.1.02018-08-02
CVE-2018-8032 [MEDIUM] CWE-79 CVE-2018-8032: Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
nvd
CVE-2017-10161MEDIUMCVSS 4.8v6.1.3.0v6.2.2.02017-10-19
CVE-2017-10161 [MEDIUM] CVE-2017-10161: Vulnerability in the Oracle Engineering Data Management component of Oracle Supply Chain Products Su Vulnerability in the Oracle Engineering Data Management component of Oracle Supply Chain Products Suite (subcomponent: Web Services Security). Supported versions that are affected are 6.1.3.0 and 6.2.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Engineering Data Management. Successf
nvd
CVE-2017-3730HIGHCVSS 7.5PoCv6.1.3v6.2.02017-05-04
CVE-2017-3730 [HIGH] CWE-476 CVE-2017-3730: In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack.
nvd
CVE-2016-8735CRITICALCVSS 9.8KEVPoCv6.1.3v6.2.0+1 more2017-04-06
CVE-2016-8735 [CRITICAL] CVE-2016-8735: Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8. Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential ty
nvd
CVE-2016-5518HIGHCVSS 8.1v6.1.3.0v6.2.0.02016-10-25
CVE-2016-5518 [HIGH] CVE-2016-5518: Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.3.0 and 6.2.0.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to webfileservices.
nvd
CVE-2016-3468CRITICALCVSS 9.8v6.1.3.0v6.2.0.02016-07-21
CVE-2016-3468 [CRITICAL] CVE-2016-3468: Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.3.0 and 6.2.0.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Install.
nvd
CVE-2016-3428LOWCVSS 3.1v6.1.3.0v6.2.0.02016-04-21
CVE-2016-3428 [LOW] CVE-2016-3428: Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.3.0 and 6.2.0.0 allows remote attackers to affect availability via vectors related to Engineering Communication Interface.
nvd
CVE-2016-0497MEDIUMCVSS 4.3v6.1.2.2v6.1.3.0+1 more2016-01-21
CVE-2016-0497 [MEDIUM] CVE-2016-0497: Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.2.2, 6.1.3.0, and 6.2.0.0 allows remote attackers to affect integrity via unknown vectors related to Web Client.
nvd
CVE-2016-0498LOWCVSS 1.5v6.1.2.2v6.1.3.0+1 more2016-01-21
CVE-2016-0498 [LOW] CVE-2016-0498: Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.2.2, 6.1.3.0, and 6.2.0.0 allows local users to affect confidentiality via unknown vectors related to Install.
nvd