cbcvebase.

Oracle Enterprise Manager Base Platform vulnerabilities

141 known vulnerabilities affecting oracle/enterprise_manager_base_platform.

Total CVEs
141
CISA KEV
1
actively exploited
Public exploits
8
Exploited in wild
5
Severity breakdown
CRITICAL17HIGH57MEDIUM66LOW1

Vulnerabilities

Page 1 of 8
CVE-2018-11776P1HIGHCVSS 8.1KEVPoCRansomwarev13.3.0.0v13.4.0.02018-08-22
CVE-2018-11776 [HIGH] CVE-2018-11776: Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution wh Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag w
nvd
CVE-2021-45105P1MEDIUMCVSS 5.9ExploitedPoCRansomwarev13.4.0.0v13.5.0.02021-12-18
CVE-2021-45105 [MEDIUM] CWE-20 CVE-2021-45105: Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from u Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
nvd
CVE-2021-4104P1HIGHCVSS 7.5ExploitedPoCv13.4.0.0v13.5.0.02021-12-14
CVE-2021-4104 [HIGH] CWE-502 CVE-2021-4104: JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has wr JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228.
nvd
CVE-2020-9547P1CRITICALCVSS 9.8ExploitedPoCv13.3.0.0v13.4.0.02020-03-02
CVE-2020-9547 [CRITICAL] CWE-502 CVE-2020-9547: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).
nvd
CVE-2020-9548P1CRITICALCVSS 9.8ExploitedPoCv13.3.0.0v13.4.0.02020-03-02
CVE-2020-9548 [CRITICAL] CWE-502 CVE-2020-9548: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).
nvd
CVE-2017-5645P1CRITICALCVSS 9.8PoCv12.1.0.5v13.2.0.02017-04-17
CVE-2017-5645 [CRITICAL] CWE-502 CVE-2017-5645: In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive s In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
nvd
CVE-2019-0227P2HIGHCVSS 7.5PoCv12.1.0.5v13.3.0.02019-05-01
CVE-2019-0227 [HIGH] CWE-918 CVE-2019-0227: A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that wa A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to t
nvd
CVE-2022-23305P2CRITICALCVSS 9.8v13.4.0.0v13.5.0.02022-01-18
CVE-2022-23305 [CRITICAL] CWE-89 CVE-2022-23305: By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter whe By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or headers of an application that ar
nvd
CVE-2022-23302P2HIGHCVSS 8.8v13.4.0.0v13.5.0.02022-01-18
CVE-2022-23302 [HIGH] CVE-2022-23302: JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the att JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in r
nvd
CVE-2020-5398P2HIGHCVSS 7.5v13.2.1.02020-01-17
CVE-2020-5398 [HIGH] CWE-79 CVE-2020-5398: In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0 In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.
nvd
CVE-2022-23307P2HIGHCVSS 8.8v13.4.0.0v13.5.0.02022-01-18
CVE-2022-23307 [HIGH] CVE-2022-23307: CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chain CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
nvd
CVE-2019-12419P2CRITICALCVSS 9.8v13.2.1.02019-11-06
CVE-2019-12419 [CRITICAL] CWE-863 CVE-2019-12419: Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to
nvd
CVE-2021-36160P2HIGHCVSS 7.5v13.4.0.0v13.5.0.02021-09-16
CVE-2021-36160 [HIGH] CWE-125 CVE-2021-36160: A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory an A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive).
nvd
CVE-2021-34798P3HIGHCVSS 7.5v13.4.0.0v13.5.0.02021-09-16
CVE-2021-34798 [HIGH] CWE-476 CVE-2021-34798: Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTT Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.
nvd
CVE-2026-46994P2CRITICALCVSS 9.8v13.5.0.0v24.1.0.0.02026-07-21
CVE-2026-46994 [CRITICAL] CWE-284 CVE-2026-46994: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (c Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attac
nvd
CVE-2020-1967P3HIGHCVSS 7.5v13.4.0.02020-04-21
CVE-2020-1967 [HIGH] CWE-476 CVE-2020-1967: Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 han Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by
nvd
CVE-2020-2961P2CRITICALCVSS 9.8v13.2.0.0v13.3.0.02020-04-15
CVE-2020-2961 [CRITICAL] CVE-2020-2961: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (componen Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Discovery Framework (Oracle OHS)). Supported versions that are affected are 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful atta
nvd
CVE-2019-5063P3HIGHCVSS 8.8v13.4.0.02020-01-03
CVE-2019-5063 [HIGH] CWE-120 CVE-2019-5063: An exploitable heap buffer overflow vulnerability exists in the data structure persistence functiona An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV 4.1.0. A specially crafted XML file can cause a buffer overflow, resulting in multiple heap corruptions and potential code execution. An attacker can provide a specially crafted file to trigger this vulnerability.
nvd
CVE-2026-46995P2HIGHCVSS 8.8v13.5.0.0v24.1.0.0.02026-07-21
CVE-2026-46995 [HIGH] CWE-269 CVE-2026-46995: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (c Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks o
nvd
CVE-2026-47004P3HIGHCVSS 8.8v13.5.0.0v24.1.0.0.02026-07-21
CVE-2026-47004 [HIGH] CWE-306 CVE-2026-47004: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (c Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self Update Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful att
nvd
Oracle Enterprise Manager Base Platform vulnerabilities | cvebase