cbcvebase.

Oracle Enterprise Manager Base Platform vulnerabilities

141 known vulnerabilities affecting oracle/enterprise_manager_base_platform.

Total CVEs
141
CISA KEV
1
actively exploited
Public exploits
8
Exploited in wild
5
Severity breakdown
CRITICAL17HIGH57MEDIUM66LOW1

Vulnerabilities

Page 7 of 8
CVE-2020-2631P4MEDIUMCVSS 6.0v12.1.0.5v13.2.0.0+1 more2020-01-15
CVE-2020-2631 [MEDIUM] CVE-2020-2631: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (componen Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Application Service Level Mgmt). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successfu
nvd
CVE-2020-2620P4MEDIUMCVSS 6.0v12.1.0.5v13.2.0.0+1 more2020-01-15
CVE-2020-2620 [MEDIUM] CVE-2020-2620: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (componen Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful
nvd
CVE-2020-2639P4MEDIUMCVSS 6.0v12.1.0.5v13.2.0.0+1 more2020-01-15
CVE-2020-2639 [MEDIUM] CVE-2020-2639: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (componen Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Host Management). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of th
nvd
CVE-2020-2624P4MEDIUMCVSS 6.0v12.1.0.5v13.2.0.0+1 more2020-01-15
CVE-2020-2624 [MEDIUM] CVE-2020-2624: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (componen Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Connector Framework). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks o
nvd
CVE-2020-2619P4MEDIUMCVSS 6.0v12.1.0.5v13.2.0.0+1 more2020-01-15
CVE-2020-2619 [MEDIUM] CVE-2020-2619: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (componen Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful
nvd
CVE-2020-2622P4MEDIUMCVSS 6.0v12.1.0.5v13.2.0.0+1 more2020-01-15
CVE-2020-2622 [MEDIUM] CVE-2020-2622: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (componen Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of t
nvd
CVE-2020-2643P4MEDIUMCVSS 6.0v12.1.0.5v13.2.0.0+1 more2020-01-15
CVE-2020-2643 [MEDIUM] CVE-2020-2643: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (componen Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Job System). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of this vu
nvd
CVE-2020-2635P4MEDIUMCVSS 6.0v12.1.0.5v13.2.0.0+1 more2020-01-15
CVE-2020-2635 [MEDIUM] CVE-2020-2635: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (componen Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: System Monitoring). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of
nvd
CVE-2020-5397P4MEDIUMCVSS 5.3v13.2.1.02020-01-17
CVE-2020-5397 [MEDIUM] CWE-352 CVE-2020-5397: Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS prefligh Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail au
nvd
CVE-2021-3537P4MEDIUMCVSS 5.9v13.4.0.0v13.5.0.02021-05-14
CVE-2021-3537 [MEDIUM] CWE-476 CVE-2021-3537: A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors wh A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the flaw could be used to crash the application. The highest threat from this vulnerability is to system availability
nvd
CVE-2021-2053P4MEDIUMCVSS 6.1v13.4.0.02021-04-22
CVE-2021-2053 [MEDIUM] CVE-2021-2053: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (componen Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). The supported version that is affected is 13.4.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks require human interaction from
nvd
CVE-2019-10219P4MEDIUMCVSS 6.1v13.4.0.0v13.5.0.02019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2019-12415P4MEDIUMCVSS 5.5v12.1.0.5v13.3.0.0+1 more2019-10-23
CVE-2019-12415 [MEDIUM] CWE-611 CVE-2019-12415: In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Ex In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
nvd
CVE-2020-2646P4MEDIUMCVSS 5.4v12.1.0.5v13.2.0.0+1 more2020-01-15
CVE-2020-2646 [MEDIUM] CVE-2020-2646: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (componen Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Command Line Interface). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks
nvd
CVE-2022-29577P4MEDIUMCVSS 6.1v13.4.0.0v13.5.0.02022-04-21
CVE-2022-29577 [MEDIUM] CVE-2022-29577: OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. T OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content. NOTE: this issue exists because of an incomplete fix for CVE-2022-28367.
nvd
CVE-2016-3540P4MEDIUMCVSS 4.3v12.1.0.5v13.1.0.02016-07-21
CVE-2016-3540 [MEDIUM] CVE-2016-3540: Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Man Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.5 and 13.1.0.0 allows remote attackers to affect confidentiality via vectors related to UI Framework.
nvd
CVE-2022-21469P4MEDIUMCVSS 4.7v13.4.0.0v13.5.0.02022-04-19
CVE-2022-21469 [MEDIUM] CVE-2022-21469: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (componen Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). Supported versions that are affected are 13.4.0.0 and 13.5.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks require human in
nvd
CVE-2016-3563P4MEDIUMCVSS 6.3v12.1.0.52016-07-21
CVE-2016-3563 [MEDIUM] CVE-2016-3563: Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Man Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.5 allows local users to affect confidentiality and integrity via vectors related to Security Framework, a different vulnerability than CVE-2016-5604.
nvd
CVE-2016-5604P4MEDIUMCVSS 6.3v12.1.0.52016-10-25
CVE-2016-5604 [MEDIUM] CVE-2016-5604: Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Man Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.5 allows local users to affect confidentiality and integrity via vectors related to Security Framework, a different vulnerability than CVE-2016-3563.
nvd
CVE-2026-46991P4MEDIUMCVSS 4.4v13.5.0.0v24.1.0.0.02026-07-21
CVE-2026-46991 [MEDIUM] CWE-284 CVE-2026-46991: Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (c Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise Manager Base Platform executes to
nvd