cbcvebase.

Oracle Enterprise Manager vulnerabilities

33 known vulnerabilities affecting oracle/enterprise_manager.

Total CVEs
33
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH9MEDIUM16LOW2

Vulnerabilities

Page 2 of 2
CVE-2007-0292P4HIGHCVSS 7.5v10.1.0.52007-01-17
CVE-2007-0292 [HIGH] CVE-2007-0292: Multiple unspecified vulnerabilities in Oracle Enterprise Manager 10.1.0.5 have unknown impact and a Multiple unspecified vulnerabilities in Oracle Enterprise Manager 10.1.0.5 have unknown impact and attack vectors related to Oracle Agent, aka (1) EM01 and (2) EM02. NOTE: EM05 might be related to CVE-2007-0222.
nvd
CVE-2004-1366P4MEDIUMCVSS 4.6v9v9.0.12004-08-04
CVE-2004-1366 [MEDIUM] CWE-255 CVE-2004-1366: Oracle 10g Database Server stores the password for the SYSMAN account in cleartext in the world-read Oracle 10g Database Server stores the password for the SYSMAN account in cleartext in the world-readable emoms.properties file, which could allow local users to gain DBA privileges.
nvd
CVE-2007-0293P4MEDIUMCVSS 6.4v10.1.0.5v10.2.0.12007-01-17
CVE-2007-0293 [MEDIUM] CVE-2007-0293: Multiple unspecified vulnerabilities in Oracle Enterprise Manager 10.1.0.5 and 10.2.0.1 have unknown Multiple unspecified vulnerabilities in Oracle Enterprise Manager 10.1.0.5 and 10.2.0.1 have unknown impact and attack vectors related to (1) Oracle Agent (EM03) and (2) EM04 and (3) EM05 in Enterprise Manager Console. NOTE: EM05 might be related to CVE-2007-0222.
nvd
CVE-2009-1967P4MEDIUMCVSS 5.5v10.2.0.42009-07-14
CVE-2009-1967 [MEDIUM] CVE-2009-1967: Unspecified vulnerability in the Config Management component in (1) Oracle Database 11.1.0.7 and (2) Unspecified vulnerability in the Config Management component in (1) Oracle Database 11.1.0.7 and (2) Oracle Enterprise Manager 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-1966.
nvd
CVE-2009-1966P4MEDIUMCVSS 5.5v10.2.0.42009-07-14
CVE-2009-1966 [MEDIUM] CVE-2009-1966: Unspecified vulnerability in the Config Management component in (1) Oracle Database 11.1.0.7 and (2) Unspecified vulnerability in the Config Management component in (1) Oracle Database 11.1.0.7 and (2) Oracle Enterprise Manager 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-1967.
nvd
CVE-2013-3791P4MEDIUMCVSS 4.3v10.2.0.52013-07-17
CVE-2013-3791 [MEDIUM] CVE-2013-3791: Unspecified vulnerability in Enterprise Manager (EM) Base Platform 10.2.0.5 and EM DB Control 11.1.0 Unspecified vulnerability in Enterprise Manager (EM) Base Platform 10.2.0.5 and EM DB Control 11.1.0.7 in Oracle Enterprise Manager Grid Control allows remote attackers to affect integrity via unknown vectors related to User Interface Framework.
nvd
CVE-2013-3758P4MEDIUMCVSS 4.3v10.2.0.5v11.1.0.12013-07-17
CVE-2013-3758 [MEDIUM] CVE-2013-3758: Unspecified vulnerability in the Enterprise Manager (EM) Base Platform 10.2.0.5 and 11.1.0.1; EM DB Unspecified vulnerability in the Enterprise Manager (EM) Base Platform 10.2.0.5 and 11.1.0.1; EM DB Control 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3; and EM Plugin for DB 12.1.0.2 and 12.1.0.3 in Oracle Enterprise Manager Grid Control allows remote attackers to affect integrity via unknown vectors related to Schema Management.
nvd
CVE-2004-1369P4MEDIUMCVSS 5.0v9v9.0.12004-08-04
CVE-2004-1369 [MEDIUM] CVE-2004-1369: The TNS Listener in Oracle 10g allows remote attackers to cause a denial of service (listener crash) The TNS Listener in Oracle 10g allows remote attackers to cause a denial of service (listener crash) via a malformed service_register_NSGR request containing a value that is used as an invalid offset for a pointer that references incorrect memory.
nvd
CVE-2006-3720P4MEDIUMCVSS 5.5v10.1.0.32006-07-21
CVE-2006-3720 [MEDIUM] CVE-2006-3720: Unspecified vulnerability in Enterprise Config Management for Oracle Enterprise Manager 10.1.0.3 has Unspecified vulnerability in Enterprise Config Management for Oracle Enterprise Manager 10.1.0.3 has unknown impact and attack vectors, aka Oracle Vuln# EM02.
nvd
CVE-2004-1367P4MEDIUMCVSS 4.4v9v9.0.12004-08-04
CVE-2004-1367 [MEDIUM] CWE-200 CVE-2004-1367: Oracle 10g Database Server, when installed with a password that contains an exclamation point ("!") Oracle 10g Database Server, when installed with a password that contains an exclamation point ("!") for the (1) DBSNMP or (2) SYSMAN user, generates an error that logs the password in the world-readable postDBCreation.log file, which could allow local users to obtain that password and use it against SYS or SYSTEM accounts, which may have been installed
nvd
CVE-2006-3719P4MEDIUMCVSS 5.5v9.0.1.0v9.2.0.12006-07-21
CVE-2006-3719 [MEDIUM] CVE-2006-3719: Unspecified vulnerability in CORE: Repository for Oracle Enterprise Manager 9.0.1.0 and 9.2.0.1 has Unspecified vulnerability in CORE: Repository for Oracle Enterprise Manager 9.0.1.0 and 9.2.0.1 has unknown impact and attack vectors, aka Oracle Vuln# EM01.
nvd
CVE-2008-2603P4LOWCVSS 3.5v10.1.0.5v10.2.0.4+1 more2008-07-15
CVE-2008-2603 [LOW] CVE-2008-2603: Unspecified vulnerability in the Resource Manager component in Oracle Database 10.1.0.5, 10.2.0.4, a Unspecified vulnerability in the Resource Manager component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.6, and Database Control in Enterprise Manager, has unknown impact and remote authenticated attack vectors. NOTE: the previous information was obtained from the Oracle July 2008 CPU. Oracle has not commented on reliable researcher claims that this is a cr
nvd
CVE-2007-0294P4LOWCVSS 1.7v10.2.0.12007-01-17
CVE-2007-0294 [LOW] CVE-2007-0294: Unspecified vulnerability in Oracle Enterprise Manager 10.2.0.1 has unknown impact and attack vector Unspecified vulnerability in Oracle Enterprise Manager 10.2.0.1 has unknown impact and attack vectors related to Database Cloning & Data Guard Management, aka EM06.
nvd
Oracle Enterprise Manager vulnerabilities | cvebase