Oracle Enterprise Manager Base Platform vulnerabilities

120 known vulnerabilities affecting oracle/enterprise_manager_base_platform.

Total CVEs
120
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL14HIGH47MEDIUM59

Vulnerabilities

Page 5 of 6
CVE-2020-2611MEDIUMCVSS 6.0v12.1.0.5v13.2.0.0+1 more2020-01-15
CVE-2020-2611 [MEDIUM] CVE-2020-2611: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (componen Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful
nvd
CVE-2020-2643MEDIUMCVSS 6.0v12.1.0.5v13.2.0.0+1 more2020-01-15
CVE-2020-2643 [MEDIUM] CVE-2020-2643: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (componen Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Job System). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of this vu
nvd
CVE-2020-2635MEDIUMCVSS 6.0v12.1.0.5v13.2.0.0+1 more2020-01-15
CVE-2020-2635 [MEDIUM] CVE-2020-2635: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (componen Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: System Monitoring). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of
nvd
CVE-2020-2632MEDIUMCVSS 6.0v12.1.0.5v13.2.0.0+1 more2020-01-15
CVE-2020-2632 [MEDIUM] CVE-2020-2632: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (componen Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: System Monitoring). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of
nvd
CVE-2019-20330CRITICALCVSS 9.8v13.3.0.0v13.4.0.02020-01-03
CVE-2019-20330 [CRITICAL] CWE-502 CVE-2019-20330: FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking. FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
nvd
CVE-2019-5064HIGHCVSS 8.8v13.4.0.02020-01-03
CVE-2019-5064 [HIGH] CWE-120 CVE-2019-5064: An exploitable heap buffer overflow vulnerability exists in the data structure persistence functiona An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, before version 4.2.0. A specially crafted JSON file can cause a buffer overflow, resulting in multiple heap corruptions and potentially code execution. An attacker can provide a specially crafted file to trigger this vulnerability.
nvd
CVE-2019-5063HIGHCVSS 8.8v13.4.0.02020-01-03
CVE-2019-5063 [HIGH] CWE-120 CVE-2019-5063: An exploitable heap buffer overflow vulnerability exists in the data structure persistence functiona An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV 4.1.0. A specially crafted XML file can cause a buffer overflow, resulting in multiple heap corruptions and potential code execution. An attacker can provide a specially crafted file to trigger this vulnerability.
nvd
CVE-2019-10219MEDIUMCVSS 6.1v13.4.0.0v13.5.0.02019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2019-12419CRITICALCVSS 9.8v13.2.1.02019-11-06
CVE-2019-12419 [CRITICAL] CWE-863 CVE-2019-12419: Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to
nvd
CVE-2019-12415MEDIUMCVSS 5.5v12.1.0.5v13.3.0.0+1 more2019-10-23
CVE-2019-12415 [MEDIUM] CWE-611 CVE-2019-12415: In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Ex In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
nvd
CVE-2019-2897MEDIUMCVSS 6.4v13.4.0.02019-10-16
CVE-2019-2897 [MEDIUM] CVE-2019-2897: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middle Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.
nvd
CVE-2019-17195CRITICALCVSS 9.8v13.4.0.02019-10-15
CVE-2019-17195 [CRITICAL] CWE-755 CVE-2019-17195: Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, wh Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
nvd
CVE-2019-13990CRITICALCVSS 9.8v13.2.1.02019-07-26
CVE-2019-13990 [CRITICAL] CWE-611 CVE-2019-13990: initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3 initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
nvd
CVE-2019-0188HIGHCVSS 7.5v13.3.0.0v13.4.0.02019-05-28
CVE-2019-0188 [HIGH] CWE-611 CVE-2019-0188: Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed.
nvd
CVE-2019-0227HIGHCVSS 7.5PoCv12.1.0.5v13.3.0.02019-05-01
CVE-2019-0227 [HIGH] CWE-918 CVE-2019-0227: A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that wa A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to t
nvd
CVE-2019-5427HIGHCVSS 7.5v13.2.1.02019-04-22
CVE-2019-5427 [HIGH] CWE-776 CVE-2019-5427: c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration du c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
nvd
CVE-2019-10247MEDIUMCVSS 5.3v13.2v13.32019-04-22
CVE-2019-10247 [MEDIUM] CWE-213 CVE-2019-10247: In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the ser In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a Context that matches the requested path. The default server behavior on je
nvd
CVE-2019-10246MEDIUMCVSS 5.3v13.2v13.32019-04-22
CVE-2019-10246 [MEDIUM] CWE-213 CVE-2019-10246: In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource dire
nvd
CVE-2019-0222HIGHCVSS 7.5v12.1.0.5.0v13.2.0.0.0+1 more2019-03-28
CVE-2019-0222 [HIGH] CVE-2019-0222: In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.
nvd
CVE-2019-1559MEDIUMCVSS 5.9v12.1.0.5.0v13.2.0.0.0+1 more2019-02-27
CVE-2019-1559 [MEDIUM] CWE-203 CVE-2019-1559: If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to sen If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behave
nvd