Oracle Fusion Middleware vulnerabilities
312 known vulnerabilities affecting oracle/fusion_middleware.
Total CVEs
312
CISA KEV
3
actively exploited
Public exploits
30
Exploited in wild
5
Severity breakdown
CRITICAL7HIGH29MEDIUM209LOW67
Vulnerabilities
Page 1 of 16
CVE-2012-3152P1CRITICALCVSS 9.1KEVPoCv11.1.1.4.0v11.1.1.6.0+1 more2012-10-16
CVE-2012-3152 [CRITICAL] CVE-2012-3152: Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Report Server Component. NOTE: the previous information is from the October 2012 CPU. Oracle has not commented on claims from the origi
nvd
CVE-2012-1710P1CRITICALCVSS 9.8KEVRansomwarev10.1.3.52012-05-03
CVE-2012-1710 [CRITICAL] CVE-2012-1710: Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middl
Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Designer, a different vulnerability than CVE-2012-1709.
nvd
CVE-2012-0518P2MEDIUMCVSS 4.7KEVv10.1.4.32012-10-16
CVE-2012-0518 [MEDIUM] CWE-601 CVE-2012-0518: Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion
Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers to affect integrity via unknown vectors related to Redirects, a different vulnerability than CVE-2012-3175.
nvd
CVE-2012-3153P2MEDIUMCVSS 6.4ExploitedPoCv11.1.1.4.0v11.1.1.6.0+1 more2012-10-16
CVE-2012-3153 [MEDIUM] CVE-2012-3153: Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Servlet. NOTE: the previous information is from the October 2012 CPU. Oracle has not commented on claims from the original researcher tha
nvd
CVE-2013-3827P2MEDIUMCVSS 5.0ExploitedPoCv2.1.1v3.0.1+6 more2013-10-16
CVE-2013-3827 [MEDIUM] CVE-2013-3827: Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2; the Oracle JDeveloper component in Oracle Fusion Middleware 11.1.2.3.0, 11.1.2.4.0, and 12.1.2.0.0; and the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0 and 12.1.1 allows remote attackers to affect confidentiality vi
nvd
CVE-2010-1622P2MEDIUMCVSS 6.0PoCv7.6.2v11.1.1.6.1+1 more2010-06-21
CVE-2010-1622 [MEDIUM] CWE-94 CVE-2010-1622: SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar file.
nvd
CVE-2010-3599P2CRITICALCVSS 9.4PoCv10.1.3.4v10.1.3.52011-01-19
CVE-2010-3599 [CRITICAL] CVE-2010-3599: Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.
Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affect integrity and availability via unknown vectors related to Import Server. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from the original researcher
nvd
CVE-2010-3591P3CRITICALCVSS 9.3PoCv10.1.3.4v10.1.3.52011-01-19
CVE-2010-3591 [CRITICAL] CVE-2010-3591: Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.
Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Internal Operations. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from
nvd
CVE-2013-3763P3MEDIUMCVSS 5.5PoCv7.4.0v7.5.1.12013-07-17
CVE-2013-3763 [MEDIUM] CVE-2013-3763: Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 7.4.0 an
Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 7.4.0 and 7.5.1.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2013-3764.
nvd
CVE-2010-3595P3HIGHCVSS 7.8PoCv10.1.3.4v10.1.3.52011-01-19
CVE-2010-3595 [HIGH] CVE-2010-3595: Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.
Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affect confidentiality via unknown vectors related to Import Server. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from the original researcher that remote att
nvd
CVE-2014-4210P3MEDIUMCVSS 5.0PoCv10.0.2v10.3.62014-07-17
CVE-2014-4210 [MEDIUM] CVE-2014-4210: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0 and 10.3.6.0 allows remote attackers to affect confidentiality via vectors related to WLS - Web Services.
nvd
CVE-2013-1559P3MEDIUMCVSS 4.0PoCv10.1.3.5.1v11.1.1.6.02013-04-17
CVE-2013-1559 [MEDIUM] CVE-2013-1559: Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1
Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote authenticated users to affect availability via unknown vectors related to Content Server.
nvd
CVE-2010-4437P3MEDIUMCVSS 5.8PoCv9.0v9.1+4 more2011-01-19
CVE-2010-4437 [MEDIUM] CVE-2010-4437: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.0, 9
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.0, 9.1, 9.2.4, 10.0.2, 10.3.2, and 10.3.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Servlet Container.
nvd
CVE-2014-2424P3MEDIUMCVSS 4.0PoCv11.1.1.7.02014-04-16
CVE-2014-2424 [MEDIUM] CVE-2014-2424: Unspecified vulnerability in the Oracle Event Processing component in Oracle Fusion Middleware 11.1.
Unspecified vulnerability in the Oracle Event Processing component in Oracle Fusion Middleware 11.1.1.7.0 allows remote authenticated users to affect integrity via vectors related to CEP system.
nvd
CVE-2019-10086P3HIGHCVSS 7.3v11.1.1.9v12.2.1.3.0+1 more2019-08-20
CVE-2019-10086 [HIGH] CWE-502 CVE-2019-10086: In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressi
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
nvd
CVE-2014-0191P4MEDIUMCVSS 4.3PoCv11.1.1.7.0v12.1.2.0.0+1 more2015-01-21
CVE-2014-0191 [MEDIUM] CVE-2014-0191: The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as used in Web Listener
The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as used in Web Listener in Oracle HTTP Server in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 and other products, loads external parameter entities regardless of whether entity substitution or validation is enabled, which allows remote attackers to cause a denial of se
nvd
CVE-2020-10683P3CRITICALCVSS 9.8v12.2.1.4.02020-05-01
CVE-2020-10683 [CRITICAL] CWE-611 CVE-2020-10683: dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, whi
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
nvd
CVE-2014-2399P4MEDIUMCVSS 4.3PoCv2.2.22014-04-16
CVE-2014-2399 [MEDIUM] CVE-2014-2399: Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2.2.2 al
Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2.2.2 allows remote attackers to affect integrity via unknown vectors related to Oracle Endeca Information Discovery (Formerly Latitude), a different vulnerability than CVE-2014-2400.
nvd
CVE-2012-3183P4MEDIUMCVSS 4.9PoCv7.0v7.0.1+9 more2012-10-17
CVE-2012-3183 [MEDIUM] CVE-2012-3183: Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6
Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2, and 11.1.1.6.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Advanced UI, a different vulnerability than CVE-2012-3185 and CVE-2012-3186.
nvd
CVE-2012-3185P4MEDIUMCVSS 4.9PoCv6.1v6.2+9 more2012-10-17
CVE-2012-3185 [MEDIUM] CVE-2012-3185: Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6
Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2, and 11.1.1.6.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Advanced UI, a different vulnerability than CVE-2012-3183 and CVE-2012-3186.
nvd
1 / 16Next →