Oracle Enterprise Manager Base Platform vulnerabilities
120 known vulnerabilities affecting oracle/enterprise_manager_base_platform.
Total CVEs
120
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL14HIGH47MEDIUM59
Vulnerabilities
Page 6 of 6
CVE-2018-3303MEDIUMCVSS 6.5v13.2v13.32019-01-16
CVE-2018-3303 [MEDIUM] CVE-2018-3303: Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Product
Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Products Suite (subcomponent: EM Console). Supported versions that are affected are 13.2 and 13.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of this
nvd
CVE-2018-5407MEDIUMCVSS 4.7PoCv12.1.0.5.0v13.2.0.0.0+1 more2018-11-15
CVE-2018-5407 [MEDIUM] CWE-200 CVE-2018-5407: Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerab
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
nvd
CVE-2018-0734MEDIUMCVSS 5.9v12.1.0.5.0v13.2.0.0.0+1 more2018-10-30
CVE-2018-0734 [MEDIUM] CWE-327 CVE-2018-0734: The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack.
The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.0.2q (Affected 1.0.2-1.0.2p).
nvd
CVE-2018-0735MEDIUMCVSS 5.9v12.1.0.5.0v13.2.0.0.0+1 more2018-10-29
CVE-2018-0735 [MEDIUM] CWE-327 CVE-2018-0735: The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attac
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).
nvd
CVE-2018-11776HIGHCVSS 8.1KEVPoCv13.3.0.0v13.4.0.02018-08-22
CVE-2018-11776 [HIGH] CVE-2018-11776: Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution wh
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag w
nvd
CVE-2018-1656MEDIUMCVSS 6.5v13.2.0.0.0v13.3.0.0.02018-08-20
CVE-2018-1656 [MEDIUM] CWE-22 CVE-2018-1656: The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) (IBM SDK, Java Techn
The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) (IBM SDK, Java Technology Edition 6.0 , 7.0, and 8.0) does not protect against path traversal attacks when extracting compressed dump files. IBM X-Force ID: 144882.
nvd
CVE-2018-12539HIGHCVSS 7.8v13.2.0.0.0v13.3.0.0.02018-08-14
CVE-2018-12539 [HIGH] CWE-419 CVE-2018-12539: In Eclipse OpenJ9 version 0.8, users other than the process owner may be able to use Java Attach API
In Eclipse OpenJ9 version 0.8, users other than the process owner may be able to use Java Attach API to connect to an Eclipse OpenJ9 or IBM JVM on the same machine and use Attach API operations, which includes the ability to execute untrusted native code. Attach API is enabled by default on Windows, Linux and AIX JVMs and can be disabled using the com
nvd
CVE-2018-8032MEDIUMCVSS 6.1v12.1.0.5v13.3.0.02018-08-02
CVE-2018-8032 [MEDIUM] CWE-79 CVE-2018-8032: Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the
Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
nvd
CVE-2018-1000613CRITICALCVSS 9.8v12.1.0.5.0v13.2.0.0+1 more2018-07-09
CVE-2018-1000613 [CRITICAL] CWE-470 CVE-2018-1000613: Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not in
Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result
nvd
CVE-2018-11039MEDIUMCVSS 5.9v12.1.0.5.0v13.2.0.0.0+1 more2018-06-25
CVE-2018-11039 [MEDIUM] CVE-2018-11039: Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupport
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filt
nvd
CVE-2018-1257MEDIUMCVSS 6.5v12.1.0.5.0v13.2.0.0.0+1 more2018-05-11
CVE-2018-1257 [MEDIUM] CVE-2018-1257: Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupport
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of
nvd
CVE-2018-2750HIGHCVSS 7.1v12.1.0.52018-04-19
CVE-2018-2750 [HIGH] CVE-2018-2750: Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Product
Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Products Suite (subcomponent: UI Framework). The supported version that is affected is 12.1.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks require huma
nvd
CVE-2017-10091HIGHCVSS 7.7v12.1.0v13.1.0+1 more2017-08-08
CVE-2017-10091 [HIGH] CVE-2017-10091: Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Co
Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: UI Framework). Supported versions that are affected are 12.1.0, 13.1.0 and 13.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. While the vulner
nvd
CVE-2017-9735HIGHCVSS 7.5v13.2v13.32017-06-16
CVE-2017-9735 [HIGH] CWE-203 CVE-2017-9735: Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easi
Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.
nvd
CVE-2017-3518HIGHCVSS 7.5v12.1.0v13.1.0+1 more2017-04-24
CVE-2017-3518 [HIGH] CVE-2017-3518: Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Co
Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Discovery Framework). Supported versions that are affected are 12.1.0, 13.1.0 and 13.2.0. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Enterprise Manager Base Platform. Success
nvd
CVE-2017-5645CRITICALCVSS 9.8PoCv12.1.0.5v13.2.0.02017-04-17
CVE-2017-5645 [CRITICAL] CWE-502 CVE-2017-5645: In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive s
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
nvd
CVE-2016-5604MEDIUMCVSS 6.3v12.1.0.52016-10-25
CVE-2016-5604 [MEDIUM] CVE-2016-5604: Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Man
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.5 allows local users to affect confidentiality and integrity via vectors related to Security Framework, a different vulnerability than CVE-2016-3563.
nvd
CVE-2016-3563MEDIUMCVSS 6.3v12.1.0.52016-07-21
CVE-2016-3563 [MEDIUM] CVE-2016-3563: Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Man
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.5 allows local users to affect confidentiality and integrity via vectors related to Security Framework, a different vulnerability than CVE-2016-5604.
nvd
CVE-2016-3540MEDIUMCVSS 4.3v12.1.0.5v13.1.0.02016-07-21
CVE-2016-3540 [MEDIUM] CVE-2016-3540: Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Man
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.5 and 13.1.0.0 allows remote attackers to affect confidentiality via vectors related to UI Framework.
nvd
CVE-2016-2381HIGHCVSS 7.5v13.2.0.0.0v13.3.0.0.02016-04-08
CVE-2016-2381 [HIGH] CWE-20 CVE-2016-2381: Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child pro
Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.
nvd
← Previous6 / 6