Oracle Enterprise Manager Ops Center vulnerabilities
107 known vulnerabilities affecting oracle/enterprise_manager_ops_center.
Total CVEs
107
CISA KEV
2
actively exploited
Public exploits
12
Exploited in wild
10
Severity breakdown
CRITICAL18HIGH41MEDIUM47LOW1
Vulnerabilities
Page 6 of 6
CVE-2013-1620P4MEDIUMCVSS 4.3v11.1v12.1+1 more2013-02-08
CVE-2013-1620 [MEDIUM] CVE-2013-1620: The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing
The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets,
nvd
CVE-2018-11055P4MEDIUMCVSS 5.5v12.3.3v12.4.02018-08-31
CVE-2018-11055 [MEDIUM] CWE-404 CVE-2018-11055: RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x),
RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x), contains an Improper Clearing of Heap Memory Before Release ('Heap Inspection') vulnerability. Decoded PKCS #12 data in heap memory is not zeroized by MES before releasing the memory internally and a malicious local user could gain access to the unauth
nvd
CVE-2021-1993P4MEDIUMCVSS 4.8v12.4.0.02021-01-20
CVE-2021-1993 [MEDIUM] CVE-2021-1993: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affect
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Java VM. Successful attacks require human interaction from a person other
nvd
CVE-2020-15358P4MEDIUMCVSS 5.5v12.4.0.02020-06-27
CVE-2020-15358 [MEDIUM] CWE-787 CVE-2020-15358: In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectO
In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.
nvd
CVE-2019-2728P4MEDIUMCVSS 4.3v12.3.3v12.4.02019-07-23
CVE-2019-2728 [MEDIUM] CVE-2019-2728: Vulnerability in the Enterprise Manager Ops Center component of Oracle Enterprise Manager Products S
Vulnerability in the Enterprise Manager Ops Center component of Oracle Enterprise Manager Products Suite (subcomponent: Networking). Supported versions that are affected are 12.3.3 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Enterprise Manager Ops Center. Successful attacks of this vul
nvd
CVE-2021-23839P4LOWCVSS 3.7v12.4.0.02021-02-16
CVE-2021-23839 [LOW] CWE-327 CVE-2021-23839: OpenSSL 1.0.2 supports SSLv2. If a client attempts to negotiate SSLv2 with a server that is configur
OpenSSL 1.0.2 supports SSLv2. If a client attempts to negotiate SSLv2 with a server that is configured to support both SSLv2 and more recent SSL and TLS versions then a check is made for a version rollback attack when unpadding an RSA signature. Clients that support SSL or TLS versions greater than SSLv2 are supposed to use a special form of padding. A
nvd
CVE-2021-1999P4MEDIUMCVSS 5.0v12.4.0.02021-01-20
CVE-2021-1999 [MEDIUM] CVE-2021-1999: Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: RAS subs
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: RAS subsystems). The supported version that is affected is 8.8. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise Oracle ZFS Storage Appliance Kit. Successfu
nvd
← Previous6 / 6