Oracle Enterprise Manager Base Platform vulnerabilities
141 known vulnerabilities affecting oracle/enterprise_manager_base_platform.
Total CVEs
141
CISA KEV
1
actively exploited
Public exploits
8
Exploited in wild
5
Severity breakdown
CRITICAL17HIGH57MEDIUM66LOW1
Vulnerabilities
Page 4 of 8
CVE-2020-11112P3HIGHCVSS 8.8v13.3.0.0v13.4.0.02020-03-31
CVE-2020-11112 [HIGH] CWE-502 CVE-2020-11112: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
nvd
CVE-2020-10672P3HIGHCVSS 8.8v13.3.0.0v13.4.0.02020-03-18
CVE-2020-10672 [HIGH] CWE-502 CVE-2020-10672: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
nvd
CVE-2026-46996P3HIGHCVSS 7.1v13.5.0.0v24.1.0.0.02026-07-21
CVE-2026-46996 [HIGH] CWE-284 CVE-2026-46996: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (c
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks o
nvd
CVE-2020-11619P3HIGHCVSS 8.1v13.3.0.0v13.4.0.02020-04-07
CVE-2020-11619 [HIGH] CWE-502 CVE-2020-11619: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).
nvd
CVE-2019-1559P3MEDIUMCVSS 5.9v12.1.0.5.0v13.2.0.0.0+1 more2019-02-27
CVE-2019-1559 [MEDIUM] CWE-203 CVE-2019-1559: If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to sen
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behave
nvd
CVE-2020-10968P3HIGHCVSS 8.8v13.3.0.0v13.4.0.02020-03-26
CVE-2020-10968 [HIGH] CWE-502 CVE-2020-10968: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
nvd
CVE-2022-21516P3HIGHCVSS 7.3v13.4.0.0v13.5.0.02022-07-19
CVE-2022-21516 [HIGH] CVE-2022-21516: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (componen
Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Manager Install). Supported versions that are affected are 13.4.0.0 and 13.5.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of t
nvd
CVE-2020-12723P3HIGHCVSS 7.5v13.4.0.02020-06-05
CVE-2020-12723 [HIGH] CWE-120 CVE-2020-12723: regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of
regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls.
nvd
CVE-2019-5427P3HIGHCVSS 7.5v13.2.1.02019-04-22
CVE-2019-5427 [HIGH] CWE-776 CVE-2019-5427: c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration du
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
nvd
CVE-2017-3518P3HIGHCVSS 7.5v12.1.0v13.1.0+1 more2017-04-24
CVE-2017-3518 [HIGH] CVE-2017-3518: Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Co
Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Discovery Framework). Supported versions that are affected are 12.1.0, 13.1.0 and 13.2.0. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Enterprise Manager Base Platform. Success
nvd
CVE-2020-7595P3HIGHCVSS 7.5v13.4.0.0v13.5.0.02020-01-21
CVE-2020-7595 [HIGH] CWE-835 CVE-2020-7595: xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-fi
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
nvd
CVE-2020-11111P3HIGHCVSS 8.8v13.3.0.0v13.4.0.02020-03-31
CVE-2020-11111 [HIGH] CWE-502 CVE-2020-11111: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
nvd
CVE-2024-20917P3HIGHCVSS 7.5v13.5.0.02024-02-17
CVE-2024-20917 [HIGH] CVE-2024-20917: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (c
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Log Management). The supported version that is affected is 13.5.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. Successful attacks require huma
nvd
CVE-2018-12539P3HIGHCVSS 7.8v13.2.0.0.0v13.3.0.0.02018-08-14
CVE-2018-12539 [HIGH] CWE-419 CVE-2018-12539: In Eclipse OpenJ9 version 0.8, users other than the process owner may be able to use Java Attach API
In Eclipse OpenJ9 version 0.8, users other than the process owner may be able to use Java Attach API to connect to an Eclipse OpenJ9 or IBM JVM on the same machine and use Attach API operations, which includes the ability to execute untrusted native code. Attach API is enabled by default on Windows, Linux and AIX JVMs and can be disabled using the com
nvd
CVE-2018-0734P3MEDIUMCVSS 5.9v12.1.0.5.0v13.2.0.0.0+1 more2018-10-30
CVE-2018-0734 [MEDIUM] CWE-327 CVE-2018-0734: The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack.
The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.0.2q (Affected 1.0.2-1.0.2p).
nvd
CVE-2020-2982P3HIGHCVSS 7.1v13.3.0.0v13.4.0.02020-07-15
CVE-2020-2982 [HIGH] CVE-2020-2982: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (componen
Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management). Supported versions that are affected are 13.3.0.0 and 13.4.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of th
nvd
CVE-2019-20388P3HIGHCVSS 7.5v13.4.0.0v13.5.0.02020-01-21
CVE-2019-20388 [HIGH] CWE-401 CVE-2019-20388: xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak.
xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak.
nvd
CVE-2026-47003P3MEDIUMCVSS 5.9v13.5.0.0v24.1.0.0.02026-07-21
CVE-2026-47003 [MEDIUM] CWE-284 CVE-2026-47003: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (c
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). Supported versions that are affected are 13.5 and 24.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks
nvd
CVE-2018-3303P3MEDIUMCVSS 6.5v13.2v13.32019-01-16
CVE-2018-3303 [MEDIUM] CVE-2018-3303: Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Product
Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Products Suite (subcomponent: EM Console). Supported versions that are affected are 13.2 and 13.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of this
nvd
CVE-2020-1971P3MEDIUMCVSS 5.9v13.3.0.0v13.4.0.02020-12-08
CVE-2020-1971 [MEDIUM] CWE-476 CVE-2020-1971: The X.509 GeneralName type is a generic type for representing different types of names. One of those
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A
nvd