Oracle Enterprise Manager Base Platform vulnerabilities
141 known vulnerabilities affecting oracle/enterprise_manager_base_platform.
Total CVEs
141
CISA KEV
1
actively exploited
Public exploits
8
Exploited in wild
5
Severity breakdown
CRITICAL17HIGH57MEDIUM66LOW1
Vulnerabilities
Page 3 of 8
CVE-2022-21536P3HIGHCVSS 8.1v13.4.0.0v13.5.0.02022-07-19
CVE-2022-21536 [HIGH] CVE-2022-21536: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (componen
Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Policy Framework). Supported versions that are affected are 13.4.0.0 and 13.5.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of this vuln
nvd
CVE-2016-2381P3HIGHCVSS 7.5v13.2.0.0.0v13.3.0.0.02016-04-08
CVE-2016-2381 [HIGH] CWE-20 CVE-2016-2381: Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child pro
Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.
nvd
CVE-2020-10878P3HIGHCVSS 8.6v13.4.0.02020-06-05
CVE-2020-10878 [HIGH] CWE-190 CVE-2020-10878: Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING
Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection.
nvd
CVE-2018-5407P4MEDIUMCVSS 4.7PoCv12.1.0.5.0v13.2.0.0.0+1 more2018-11-15
CVE-2018-5407 [MEDIUM] CWE-200 CVE-2018-5407: Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerab
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
nvd
CVE-2026-46990P3HIGHCVSS 7.3v13.5.0.0v24.1.0.0.02026-07-21
CVE-2026-46990 [HIGH] CWE-284 CVE-2026-46990: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (c
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. Success
nvd
CVE-2020-10673P3HIGHCVSS 8.8v13.3.0.0v13.4.0.02020-03-18
CVE-2020-10673 [HIGH] CWE-502 CVE-2020-10673: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
nvd
CVE-2020-9546P3CRITICALCVSS 9.8v13.3.0.0v13.4.0.02020-03-02
CVE-2020-9546 [CRITICAL] CWE-502 CVE-2020-9546: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).
nvd
CVE-2021-2351P3HIGHCVSS 7.5v13.4.0.0v13.5.0.02021-07-21
CVE-2021-2351 [HIGH] CWE-327 CVE-2021-2351: Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versi
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a perso
nvd
CVE-2020-11994P3HIGHCVSS 7.5v13.4.0.02020-07-08
CVE-2020-11994 [HIGH] CWE-74 CVE-2020-11994: Server-Side Template Injection and arbitrary file disclosure on Camel templating components
Server-Side Template Injection and arbitrary file disclosure on Camel templating components
nvd
CVE-2022-21392P3HIGHCVSS 8.8v13.4.0.0v13.5.0.02022-01-19
CVE-2022-21392 [HIGH] CVE-2022-21392: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (componen
Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Policy Framework). Supported versions that are affected are 13.4.0.0 and 13.5.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of this vulnera
nvd
CVE-2024-21067P3HIGHCVSS 8.8v13.5.0.02024-04-16
CVE-2024-21067 [HIGH] CWE-284 CVE-2024-21067: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (c
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Host Management). The supported version that is affected is 13.5.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise Manager Base Platform executes to compromise Oracle
nvd
CVE-2020-11620P3HIGHCVSS 8.1v13.3.0.0v13.4.0.02020-04-07
CVE-2020-11620 [HIGH] CWE-502 CVE-2020-11620: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).
nvd
CVE-2026-47006P3HIGHCVSS 7.2v13.5.0.0v24.1.0.0.02026-07-21
CVE-2026-47006 [HIGH] CWE-284 CVE-2026-47006: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (c
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self Update Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful at
nvd
CVE-2026-47005P3HIGHCVSS 7.2v13.5.0.0v24.1.0.0.02026-07-21
CVE-2026-47005 [HIGH] CWE-284 CVE-2026-47005: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (c
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self Update Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful at
nvd
CVE-2026-46988P3HIGHCVSS 7.2v13.5.0.0v24.1.0.0.02026-07-21
CVE-2026-46988 [HIGH] CWE-284 CVE-2026-46988: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (c
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Connector Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful atta
nvd
CVE-2020-11113P3HIGHCVSS 8.8v13.3.0.0v13.4.0.02020-03-31
CVE-2020-11113 [HIGH] CWE-502 CVE-2020-11113: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
nvd
CVE-2020-10969P3HIGHCVSS 8.8v13.3.0.0v13.4.0.02020-03-26
CVE-2020-10969 [HIGH] CWE-502 CVE-2020-10969: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
nvd
CVE-2022-21623P3HIGHCVSS 7.5v13.4.0.0v13.5.0.02022-10-18
CVE-2022-21623 [HIGH] CVE-2022-21623: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (componen
Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Application Config Console). Supported versions that are affected are 13.4.0.0 and 13.5.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of t
nvd
CVE-2019-0222P3HIGHCVSS 7.5v12.1.0.5.0v13.2.0.0.0+1 more2019-03-28
CVE-2019-0222 [HIGH] CVE-2019-0222: In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory
In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.
nvd
CVE-2017-10091P3HIGHCVSS 7.7v12.1.0v13.1.0+1 more2017-08-08
CVE-2017-10091 [HIGH] CVE-2017-10091: Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Co
Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: UI Framework). Supported versions that are affected are 12.1.0, 13.1.0 and 13.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. While the vulner
nvd