cbcvebase.

Oracle Enterprise Manager Base Platform vulnerabilities

141 known vulnerabilities affecting oracle/enterprise_manager_base_platform.

Total CVEs
141
CISA KEV
1
actively exploited
Public exploits
8
Exploited in wild
5
Severity breakdown
CRITICAL17HIGH57MEDIUM66LOW1

Vulnerabilities

Page 2 of 8
CVE-2019-13990P3CRITICALCVSS 9.8v13.2.1.02019-07-26
CVE-2019-13990 [CRITICAL] CWE-611 CVE-2019-13990: initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3 initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
nvd
CVE-2026-46989P3CRITICALCVSS 9.1v13.5.0.0v24.1.0.0.02026-07-21
CVE-2026-46989 [CRITICAL] CWE-284 CVE-2026-46989: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (c Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. While the vulnerabi
nvd
CVE-2026-46998P3HIGHCVSS 8.8v13.5.0.0v24.1.0.0.02026-07-21
CVE-2026-46998 [HIGH] CWE-601 CVE-2026-46998: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (c Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks
nvd
CVE-2020-11973P3CRITICALCVSS 9.8v13.3.0.0v13.4.0.02020-05-14
CVE-2020-11973 [CRITICAL] CWE-502 CVE-2020-11973: Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.2 Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.
nvd
CVE-2021-3517P3HIGHCVSS 8.6v13.4.0.0v13.5.0.02021-05-19
CVE-2021-3517 [HIGH] CWE-787 CVE-2021-3517: There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An at There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential im
nvd
CVE-2020-11972P3CRITICALCVSS 9.8v13.3.0.0v13.4.0.02020-05-14
CVE-2020-11972 [CRITICAL] CWE-502 CVE-2020-11972: Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.
nvd
CVE-2019-17195P3CRITICALCVSS 9.8v13.4.0.02019-10-15
CVE-2019-17195 [CRITICAL] CWE-755 CVE-2019-17195: Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, wh Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
nvd
CVE-2026-34279P3CRITICALCVSS 9.1v13.5.0.0v24.1.0.0.02026-04-21
CVE-2026-34279 [CRITICAL] CWE-306 CVE-2026-34279: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (c Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. While the vulne
nvd
CVE-2019-5064P3HIGHCVSS 8.8v13.4.0.02020-01-03
CVE-2019-5064 [HIGH] CWE-120 CVE-2019-5064: An exploitable heap buffer overflow vulnerability exists in the data structure persistence functiona An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, before version 4.2.0. A specially crafted JSON file can cause a buffer overflow, resulting in multiple heap corruptions and potentially code execution. An attacker can provide a specially crafted file to trigger this vulnerability.
nvd
CVE-2020-10683P3CRITICALCVSS 9.8v13.4.0.02020-05-01
CVE-2020-10683 [CRITICAL] CWE-611 CVE-2020-10683: dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, whi dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
nvd
CVE-2018-1000613P3CRITICALCVSS 9.8v12.1.0.5.0v13.2.0.0+1 more2018-07-09
CVE-2018-1000613 [CRITICAL] CWE-470 CVE-2018-1000613: Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not in Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result
nvd
CVE-2019-20330P3CRITICALCVSS 9.8v13.3.0.0v13.4.0.02020-01-03
CVE-2019-20330 [CRITICAL] CWE-502 CVE-2019-20330: FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking. FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
nvd
CVE-2019-0188P3HIGHCVSS 7.5v13.3.0.0v13.4.0.02019-05-28
CVE-2019-0188 [HIGH] CWE-611 CVE-2019-0188: Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed.
nvd
CVE-2026-46993P3HIGHCVSS 8.2v13.5.0.0v24.1.0.0.02026-07-21
CVE-2026-46993 [HIGH] CWE-284 CVE-2026-46993: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (c Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. While the vulnerabi
nvd
CVE-2020-10543P3HIGHCVSS 8.2v13.4.0.02020-06-05
CVE-2020-10543 [HIGH] CWE-190 CVE-2020-10543: Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular ex Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.
nvd
CVE-2021-3518P3HIGHCVSS 8.8v13.4.0.0v13.5.0.02021-05-18
CVE-2021-3518 [HIGH] CWE-416 CVE-2021-3518: There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted fil There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.
nvd
CVE-2021-2137P3HIGHCVSS 8.8v13.4.0.0v13.5.0.02021-10-20
CVE-2021-2137 [HIGH] CVE-2021-2137: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (componen Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Policy Framework). Supported versions that are affected are 13.4.0.0 and 13.5.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of this vulnerabi
nvd
CVE-2020-11971P3HIGHCVSS 7.5v13.3.0.0v13.4.0.02020-05-14
CVE-2020-11971 [HIGH] CVE-2020-11971: Apache Camel's JMX is vulnerable to Rebind Flaw. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.x, 3.0.0 Apache Camel's JMX is vulnerable to Rebind Flaw. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.x, 3.0.0 up to 3.1.0 is affected. Users should upgrade to 3.2.0.
nvd
CVE-2017-9735P3HIGHCVSS 7.5v13.2v13.32017-06-16
CVE-2017-9735 [HIGH] CWE-203 CVE-2017-9735: Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easi Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.
nvd
CVE-2026-46987P3HIGHCVSS 7.7v13.5.0.0v24.1.0.0.02026-07-21
CVE-2026-46987 [HIGH] CWE-284 CVE-2026-46987: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (c Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Application Service Level Mgmt). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. While
nvd
Oracle Enterprise Manager Base Platform vulnerabilities | cvebase