Oracle Fusion Middleware vulnerabilities
310 known vulnerabilities affecting oracle/fusion_middleware.
Total CVEs
310
CISA KEV
3
actively exploited
Public exploits
30
Exploited in wild
3
Severity breakdown
CRITICAL7HIGH29MEDIUM207LOW67
Vulnerabilities
Page 10 of 16
CVE-2013-1522MEDIUMCVSS 4.3v10.1.3.5.1v11.1.1.6.02013-04-17
CVE-2013-1522 [MEDIUM] CVE-2013-1522: Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1
Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote attackers to affect integrity via unknown vectors related to Content Server.
nvd
CVE-2013-1514MEDIUMCVSS 4.0v10.1.3.52013-04-17
CVE-2013-1514 [MEDIUM] CVE-2013-1514: Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Fusion Middleware 10
Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Fusion Middleware 10.1.3.5 allows remote authenticated users to affect integrity via vectors related to RMI Support.
nvd
CVE-2013-1504MEDIUMCVSS 4.3v10.0.2v10.3.5+2 more2013-04-17
CVE-2013-1504 [MEDIUM] CVE-2013-1504: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2, 10.3.5, 10.3.6, and 12.1.1 allows remote attackers to affect integrity via unknown vectors related to WebLogic Console, a different vulnerability than CVE-2013-2390.
nvd
CVE-2013-2390MEDIUMCVSS 4.3v10.0.2v10.3.5+2 more2013-04-17
CVE-2013-2390 [MEDIUM] CVE-2013-2390: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2, 10.3.5, 10.3.6, and 12.1.1 allows remote attackers to affect integrity via unknown vectors related to WebLogic Console, a different vulnerability than CVE-2013-1504.
nvd
CVE-2013-1559MEDIUMCVSS 4.0PoCv10.1.3.5.1v11.1.1.6.02013-04-17
CVE-2013-1559 [MEDIUM] CVE-2013-1559: Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1
Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote authenticated users to affect availability via unknown vectors related to Content Server.
nvd
CVE-2012-4303LOWCVSS 3.5v11.1.1.6.02013-04-17
CVE-2012-4303 [LOW] CVE-2012-4303: Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 11.1
Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 11.1.1.6.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Content Server.
nvd
CVE-2013-2393LOWCVSS 1.5v8.3.7.0v8.42013-04-17
CVE-2013-2393 [LOW] CVE-2013-2393: Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 and 8.4.0 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters.
nvd
CVE-2013-1503LOWCVSS 3.5v10.1.3.5.1v11.1.1.6.02013-04-17
CVE-2013-1503 [LOW] CVE-2013-1503: Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1
Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote authenticated users to affect integrity via unknown vectors related to Content Server.
nvd
CVE-2012-1677MEDIUMCVSS 4.3v6.0v6.1+43 more2013-01-17
CVE-2012-1677 [MEDIUM] CVE-2012-1677: Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion
Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware allows remote attackers to affect integrity via unknown vectors.
nvd
CVE-2012-5097MEDIUMCVSS 4.3v10.1.4.3v11.1.1.5.0+1 more2013-01-17
CVE-2012-5097 [MEDIUM] CVE-2012-5097: Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 10.1.4.
Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 10.1.4.3.0, 11.1.1.5.0, and 11.1.2.0.0 allows remote attackers to affect integrity, related to OAM Webgate.
nvd
CVE-2013-0393MEDIUMCVSS 6.8v8.3.7.0v8.42013-01-17
CVE-2013-0393 [MEDIUM] CVE-2013-0393: Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 and 8.4 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2013-0418.
nvd
CVE-2013-0418MEDIUMCVSS 6.8v8.3.7.0v8.42013-01-17
CVE-2013-0418 [MEDIUM] CVE-2013-0418: Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 and 8.4 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2013-0393. NOTE: the previous information was obtained from the January 2013 CPU. Oracle has not comment
nvd
CVE-2012-3183MEDIUMCVSS 4.9PoCv7.0v7.0.1+9 more2012-10-17
CVE-2012-3183 [MEDIUM] CVE-2012-3183: Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6
Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2, and 11.1.1.6.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Advanced UI, a different vulnerability than CVE-2012-3185 and CVE-2012-3186.
nvd
CVE-2012-3185MEDIUMCVSS 4.9PoCv6.1v6.2+9 more2012-10-17
CVE-2012-3185 [MEDIUM] CVE-2012-3185: Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6
Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2, and 11.1.1.6.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Advanced UI, a different vulnerability than CVE-2012-3183 and CVE-2012-3186.
nvd
CVE-2012-3186MEDIUMCVSS 4.9PoCv7.0v7.0.1+9 more2012-10-17
CVE-2012-3186 [MEDIUM] CVE-2012-3186: Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6
Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2, and 11.1.1.6.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Advanced UI, a different vulnerability than CVE-2012-3183 and CVE-2012-3185.
nvd
CVE-2012-3194MEDIUMCVSS 4.3v10.1.3.4.2v11.1.1.5.0+2 more2012-10-17
CVE-2012-3194 [MEDIUM] CVE-2012-3194: Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 10.1.3.4.
Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 10.1.3.4.2, 11.1.1.5.0, 11.1.1.6.0, and 11.1.1.6.2 allows remote attackers to affect integrity via unknown vectors related to Administration.
nvd
CVE-2012-3175MEDIUMCVSS 4.3v10.1.4.32012-10-17
CVE-2012-3175 [MEDIUM] CVE-2012-3175: Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion
Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers to affect integrity via unknown vectors related to Redirects, a different vulnerability than CVE-2012-0518.
nvd
CVE-2012-3184MEDIUMCVSS 4.3PoCv6.0v6.1+10 more2012-10-17
CVE-2012-3184 [MEDIUM] CVE-2012-3184: Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6
Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2, and 11.1.1.6.0 allows remote attackers to affect integrity via unknown vectors related to Advanced UI.
nvd
CVE-2012-3193LOWCVSS 3.5v10.3.4.2v11.1.1.5.0+2 more2012-10-17
CVE-2012-3193 [LOW] CVE-2012-3193: Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 10.3.4.2,
Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 10.3.4.2, 11.1.1.5.0, 11.1.1.6.0, and 11.1.1.6.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Administration.
nvd
CVE-2012-5065LOWCVSS 2.1v6.1v6.2+9 more2012-10-17
CVE-2012-5065 [LOW] CVE-2012-5065: Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6
Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2, and 11.1.1.6.0 allows local users to affect integrity via unknown vectors related to ImagePicker.
nvd