cbcvebase.

Oracle Enterprise Manager vulnerabilities

33 known vulnerabilities affecting oracle/enterprise_manager.

Total CVEs
33
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH9MEDIUM16LOW2

Vulnerabilities

Page 1 of 2
CVE-2004-1364P3HIGHCVSS 8.5PoCv9v9.0.12004-08-04
CVE-2004-1364 [HIGH] CWE-22 CVE-2004-1364: Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\bin directory.
nvd
CVE-2018-11040P3HIGHCVSS 7.5v13.22018-06-25
CVE-2018-11040 [HIGH] CWE-829 CVE-2018-11040: Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported vers Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not enabled by default in Spring Framewor
nvd
CVE-2019-2895P3HIGHCVSS 7.5v12.1.0.5.0v13.2.2.0.0+2 more2019-10-16
CVE-2019-2895 [HIGH] CVE-2019-2895: Vulnerability in the Enterprise Manager for Exadata product of Oracle Enterprise Manager (component: Vulnerability in the Enterprise Manager for Exadata product of Oracle Enterprise Manager (component: Exadata Plug-In Deploy and Ins). Supported versions that are affected are 12.1.0.5.0, 13.2.2.0.0, 13.3.1.0.0 and 13.3.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Enterprise Manager for Exada
nvd
CVE-2004-1371P3CRITICALCVSS 9.0v9v9.0.12004-08-04
CVE-2004-1371 [CRITICAL] CWE-119 CVE-2004-1371: Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code v Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedure.
nvd
CVE-2021-2008P3HIGHCVSS 7.3v11.1.1.9v12.2.1.32021-04-22
CVE-2021-2008 [HIGH] CVE-2021-2008: Vulnerability in the Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager ( Vulnerability in the Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: FMW Control Plugin). The supported version that is affected are 11.1.1.9 and 12.2.1.3 Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager for Fusion Middleware. Successful attac
nvd
CVE-2007-5531P3CRITICALCVSS 10.0v10.1.0.62007-10-17
CVE-2007-5531 [CRITICAL] CVE-2007-5531: Unspecified vulnerability in Oracle Help for Web, as used in Oracle Application Server, Oracle Datab Unspecified vulnerability in Oracle Help for Web, as used in Oracle Application Server, Oracle Database 10.2.0.3, and Enterprise Manager 10.1.0.6, has unknown impact and remote attack vectors, aka EM02.
nvd
CVE-2024-20916P3HIGHCVSS 8.3v13.5.0.02024-01-16
CVE-2024-20916 [HIGH] CWE-284 CVE-2024-20916: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (c Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). The supported version that is affected is 13.5.0.0. Easily exploitable vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Enterprise Mana
nvd
CVE-2006-3721P3CRITICALCVSS 10.0v10.1.0.5v10.2.0.12006-07-21
CVE-2006-3721 [CRITICAL] CVE-2006-3721: Multiple unspecified vulnerabilities in Oracle Management Service for Oracle Enterprise Manager 10.1 Multiple unspecified vulnerabilities in Oracle Management Service for Oracle Enterprise Manager 10.1.0.5 and 10.2.0.1 have unknown impact and attack vectors, aka Oracle Vuln# EM03 and EM04.
nvd
CVE-2004-1362P3HIGHCVSS 7.5v9v9.0.12004-08-04
CVE-2004-1362 [HIGH] CVE-2004-1362: The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO8859P1 character set, does not perform character conversions properly, which allows remote attackers to bypass access restrictions for certain procedures via an encoded URL with "%FF" encoded sequences that are improperly converted to "Y" characters.
nvd
CVE-2004-1370P3HIGHCVSS 7.5v9v9.0.12004-08-04
CVE-2004-1370 [HIGH] CVE-2004-1370: Multiple SQL injection vulnerabilities in PL/SQL procedures that run with definer rights in Oracle 9 Multiple SQL injection vulnerabilities in PL/SQL procedures that run with definer rights in Oracle 9i and 10g allow remote attackers to execute arbitrary SQL commands and gain privileges via (1) DBMS_EXPORT_EXTENSION, (2) WK_ACL.GET_ACL, (3) WK_ACL.STORE_ACL, (4) WK_ADM.COMPLETE_ACL_SNAPSHOT, (5) WK_ACL.DELETE_ACLS_WITH_STATEMENT, or (6) DRILOAD.VALIDATE_STMT.
nvd
CVE-2004-1363P3CRITICALCVSS 9.8v9v9.0.12004-08-04
CVE-2004-1363 [CRITICAL] CWE-131 CVE-2004-1363: Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via envir Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are expanded after the length check is performed.
nvd
CVE-2004-1368P4HIGHCVSS 7.8v9v9.0.12004-08-04
CVE-2004-1368 [HIGH] CVE-2004-1368: ISQL*Plus in Oracle 10g Application Server allows remote attackers to execute arbitrary files via an ISQL*Plus in Oracle 10g Application Server allows remote attackers to execute arbitrary files via an absolute pathname in the file parameter to the load.uix script.
nvd
CVE-2006-1885P4CRITICALCVSS 10.0v9.0.1.5v9.2.0.72006-04-20
CVE-2006-1885 [CRITICAL] CVE-2006-1885: Multiple unspecified vulnerabilities in the Reporting Framework component in Oracle Enterprise Manag Multiple unspecified vulnerabilities in the Reporting Framework component in Oracle Enterprise Manager 9.0.1.5 and 9.2.0.7 have unknown impact and attack vectors, aka Vuln# (1) EM01 and (2) EM02.
nvd
CVE-2021-2134P4MEDIUMCVSS 6.5v12.2.1.42021-04-22
CVE-2021-2134 [MEDIUM] CVE-2021-2134: Vulnerability in the Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager ( Vulnerability in the Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: FMW Control Plugin). The supported version that is affected is 12.2.1.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Enterprise Manager for Fusion Middleware. Successful attacks of this v
nvd
CVE-2007-2129P4CRITICALCVSS 10.0v9.2.0.82007-04-18
CVE-2007-2129 [CRITICAL] CVE-2007-2129: Unspecified vulnerability in the Agent component in Oracle Enterprise Manager 9.2.0.8 has unknown im Unspecified vulnerability in the Agent component in Oracle Enterprise Manager 9.2.0.8 has unknown impact and remote attack vectors, aka EM01.
nvd
CVE-2020-2640P4MEDIUMCVSS 6.0v12.1.0.5v13.2.0.0+1 more2020-01-15
CVE-2020-2640 [MEDIUM] CVE-2020-2640: Vulnerability in the Enterprise Manager for Oracle Database product of Oracle Enterprise Manager (co Vulnerability in the Enterprise Manager for Oracle Database product of Oracle Enterprise Manager (component: Target Management). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager for Oracle Database. Successful
nvd
CVE-2020-2638P4MEDIUMCVSS 6.0v12.1.0.5v13.2.0.0+1 more2020-01-15
CVE-2020-2638 [MEDIUM] CVE-2020-2638: Vulnerability in the Enterprise Manager for Oracle Database product of Oracle Enterprise Manager (co Vulnerability in the Enterprise Manager for Oracle Database product of Oracle Enterprise Manager (component: Enterprise Config Management). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager for Oracle Database.
nvd
CVE-2020-2641P4MEDIUMCVSS 6.0v12.1.0.5v13.2.0.0+1 more2020-01-15
CVE-2020-2641 [MEDIUM] CVE-2020-2641: Vulnerability in the Enterprise Manager for Oracle Database product of Oracle Enterprise Manager (co Vulnerability in the Enterprise Manager for Oracle Database product of Oracle Enterprise Manager (component: Discovery Framework). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager for Oracle Database. Successf
nvd
CVE-2020-2637P4MEDIUMCVSS 6.0v12.1.0.5v13.2.0.0+1 more2020-01-15
CVE-2020-2637 [MEDIUM] CVE-2020-2637: Vulnerability in the Enterprise Manager for Oracle Database product of Oracle Enterprise Manager (co Vulnerability in the Enterprise Manager for Oracle Database product of Oracle Enterprise Manager (component: Change Manager - web based). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager for Oracle Database. S
nvd
CVE-2004-1365P4MEDIUMCVSS 4.6v9v9.0.12004-08-04
CVE-2004-1365 [MEDIUM] CVE-2004-1365: Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function, which allows local users to execute arbitrary commands as the Oracle user.
nvd
Oracle Enterprise Manager vulnerabilities | cvebase