Oracle Fusion Middleware vulnerabilities
310 known vulnerabilities affecting oracle/fusion_middleware.
Total CVEs
310
CISA KEV
3
actively exploited
Public exploits
30
Exploited in wild
3
Severity breakdown
CRITICAL7HIGH29MEDIUM207LOW67
Vulnerabilities
Page 13 of 16
CVE-2012-0554HIGHCVSS 7.5v8.3.5.0v8.3.7.02012-05-03
CVE-2012-0554 [HIGH] CVE-2012-0554: Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows remote attackers to affect confidentiality, integrity, and availability, related to Outside In Image Export SDK, a different vulnerability than CVE-2012-0555, CVE-2012-0556, and CVE-2012-0557.
nvd
CVE-2012-0543MEDIUMCVSS 4.3v10.1.3.4.1v10.1.3.4.22012-05-03
CVE-2012-0543 [MEDIUM] CVE-2012-0543: Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Mi
Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Middleware 10.1.3.4.1 and 10.1.3.4.2 allows remote attackers to affect integrity via unknown vectors related to Administration.
nvd
CVE-2012-0515MEDIUMCVSS 4.0v9.1.0.42012-05-03
CVE-2012-0515 [MEDIUM] CVE-2012-0515: Unspecified vulnerability in the Identity Manager Connector component in Oracle Fusion Middleware 9.
Unspecified vulnerability in the Identity Manager Connector component in Oracle Fusion Middleware 9.1.0.4 allows remote authenticated users to affect integrity via unknown vectors.
nvd
CVE-2012-0522MEDIUMCVSS 4.3v10.1.3.52012-05-03
CVE-2012-0522 [MEDIUM] CVE-2012-0522: Unspecified vulnerability in the Oracle JDeveloper component in Oracle Fusion Middleware 10.1.3.5 al
Unspecified vulnerability in the Oracle JDeveloper component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect integrity via unknown vectors related to Java Business Objects.
nvd
CVE-2012-0532MEDIUMCVSS 5.5v11.1.1.3.0v11.1.1.5.02012-05-03
CVE-2012-0532 [MEDIUM] CVE-2012-0532: Unspecified vulnerability in the Identity Manager component in Oracle Fusion Middleware 11.1.1.3 and
Unspecified vulnerability in the Identity Manager component in Oracle Fusion Middleware 11.1.1.3 and 11.1.1.5 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to User Config Management.
nvd
CVE-2012-1695MEDIUMCVSS 6.8≤ 28.2.2v7.5.2+21 more2012-05-03
CVE-2012-1695 [MEDIUM] CVE-2012-1695: Unspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware 28.2.2 and ear
Unspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware 28.2.2 and earlier, and JDK/JRE 5 and 6 27.7.1 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2012-0085MEDIUMCVSS 4.3v7.5.2v10.1.3.5.12012-01-18
CVE-2012-0085 [MEDIUM] CVE-2012-0085: Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 7.5.
Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 7.5.2 and 10.1.3.5.1 allows remote attackers to affect integrity via unknown vectors related to Content Server.
nvd
CVE-2011-3566MEDIUMCVSS 5.0v9.2.4v10.0.2+3 more2012-01-18
CVE-2011-3566 [MEDIUM] CVE-2011-3566: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.2.4,
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.2.4, 10.0.2, 10.3.3, 10.3.4, and 10.3.5 allows remote attackers to affect availability via unknown vectors related to Web Container.
nvd
CVE-2012-0083MEDIUMCVSS 6.4v7.5.2v10.1.3.5.1+3 more2012-01-18
CVE-2012-0083 [MEDIUM] CVE-2012-0083: Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 7.5.
Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 7.5.2, 10.1.3.5.1, 11.1.1.3, 11.1.1.4, and 11.1.1.5 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Search.
nvd
CVE-2011-3568MEDIUMCVSS 5.5v11.1.1.3.0v11.1.1.4.0+1 more2012-01-18
CVE-2011-3568 [MEDIUM] CVE-2011-3568: Unspecified vulnerability in the Oracle Web Services Manager component in Oracle Fusion Middleware 1
Unspecified vulnerability in the Oracle Web Services Manager component in Oracle Fusion Middleware 11.1.1.3, 11.1.1.4, and 11.1.1.5 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Web Services Security.
nvd
CVE-2011-3569MEDIUMCVSS 5.0v11.1.1.3.0v11.1.1.4.0+1 more2012-01-18
CVE-2011-3569 [MEDIUM] CVE-2011-3569: Unspecified vulnerability in the Oracle Web Services Manager component in Oracle Fusion Middleware 1
Unspecified vulnerability in the Oracle Web Services Manager component in Oracle Fusion Middleware 11.1.1.3, 11.1.1.4, and 11.1.1.5 allows remote attackers to affect confidentiality via unknown vectors related to Web Services Security.
nvd
CVE-2012-0110MEDIUMCVSS 4.4v8.3.5.0v8.3.7.02012-01-18
CVE-2012-0110 [MEDIUM] CVE-2012-0110: Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect confidentiality, integrity, and availability, related to Outside In Image Export SDK.
nvd
CVE-2011-3531MEDIUMCVSS 5.0v11.1.1.3.0v11.1.1.4.0+1 more2012-01-18
CVE-2011-3531 [MEDIUM] CVE-2011-3531: Unspecified vulnerability in the Oracle Web Services Manager component in Oracle Fusion Middleware 1
Unspecified vulnerability in the Oracle Web Services Manager component in Oracle Fusion Middleware 11.1.1.3, 11.1.1.4, and 11.1.1.5 allows remote attackers to affect availability via unknown vectors related to Web Services Security.
nvd
CVE-2012-0077LOWCVSS 3.5v9.2.4v10.0.2+3 more2012-01-18
CVE-2012-0077 [LOW] CVE-2012-0077: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.2.4,
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.2.4, 10.0.2, 10.3.3, 10.3.4, and 10.3.5 allows remote authenticated users to affect integrity, related to WLS-Console.
nvd
CVE-2012-0084LOWCVSS 3.5v7.5.2v10.1.3.5.1+3 more2012-01-18
CVE-2012-0084 [LOW] CVE-2012-0084: Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 7.5.
Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 7.5.2, 10.1.3.5.1, 11.1.1.3, 11.1.1.4, and 11.1.1.5 allows remote authenticated users to affect integrity via unknown vectors related to Content Server.
nvd
CVE-2011-2319MEDIUMCVSS 4.3v9.2.4v10.0.2+3 more2011-10-18
CVE-2011-2319 [MEDIUM] CVE-2011-2319: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.2.4.
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.2.4.0, 10.0.2.0, 10.3.3.0, 10.3.4.0, and 10.3.5.0 allows remote attackers to affect confidentiality, related to JMS.
nvd
CVE-2011-3510MEDIUMCVSS 4.9v11.1.1.3.0v11.1.1.5.02011-10-18
CVE-2011-3510 [MEDIUM] CVE-2011-3510: Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle
Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Fusion Middleware 11.1.1.3.0 and 11.1.1.5.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to BI Platform Security.
nvd
CVE-2011-2320MEDIUMCVSS 5.0v9.2.4v10.0.2+3 more2011-10-18
CVE-2011-2320 [MEDIUM] CVE-2011-2320: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.2.4.
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.2.4.0, 10.0.2.0, 10.3.3.0, 10.3.4.0, and 10.3.5.0 allows remote attackers to affect confidentiality via unknown vectors related to Web Services.
nvd
CVE-2011-2314MEDIUMCVSS 4.3v10.1.2.32011-10-18
CVE-2011-2314 [MEDIUM] CVE-2011-2314: Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Fusion Middleware 10
Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Fusion Middleware 10.1.2.3 allows remote attackers to affect integrity via unknown vectors related to JavaServer Pages.
nvd
CVE-2011-2255MEDIUMCVSS 6.8v9.2.3v10.0.1+2 more2011-10-18
CVE-2011-2255 [MEDIUM] CVE-2011-2255: Unspecified vulnerability in the Oracle WebLogic Portal component in Oracle Fusion Middleware 9.2.3.
Unspecified vulnerability in the Oracle WebLogic Portal component in Oracle Fusion Middleware 9.2.3.0, 10.0.1.0, 10.2.1.0, and 10.3.2.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd