cbcvebase.

Oracle Fusion Middleware vulnerabilities

312 known vulnerabilities affecting oracle/fusion_middleware.

Total CVEs
312
CISA KEV
3
actively exploited
Public exploits
30
Exploited in wild
5
Severity breakdown
CRITICAL7HIGH29MEDIUM209LOW67

Vulnerabilities

Page 2 of 16
CVE-2012-3186P4MEDIUMCVSS 4.9PoCv7.0v7.0.1+9 more2012-10-17
CVE-2012-3186 [MEDIUM] CVE-2012-3186: Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6 Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2, and 11.1.1.6.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Advanced UI, a different vulnerability than CVE-2012-3183 and CVE-2012-3185.
nvd
CVE-2012-3135P3CRITICALCVSS 10.0≤ 27.7.2v28.2.32012-07-17
CVE-2012-3135 [CRITICAL] CVE-2012-3135: Unspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware 28.2.3 and bef Unspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware 28.2.3 and before, and 27.7.2 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2012-3184P4MEDIUMCVSS 4.3PoCv6.0v6.1+10 more2012-10-17
CVE-2012-3184 [MEDIUM] CVE-2012-3184: Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6 Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2, and 11.1.1.6.0 allows remote attackers to affect integrity via unknown vectors related to Advanced UI.
nvd
CVE-2014-4241P4MEDIUMCVSS 4.3PoCv10.0.2v10.3.62014-07-17
CVE-2014-4241 [MEDIUM] CVE-2014-4241: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2 Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0 and 10.3.6.0 allows remote attackers to affect integrity via vectors related to WLS - Web Services.
nvd
CVE-2010-3510P3CRITICALCVSS 10.0v9.0v9.1+4 more2011-01-19
CVE-2010-3510 [CRITICAL] CVE-2010-3510: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.0, 9 Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.0, 9.1, 9.2.3, 10.0.2, 10.3.2, and 10.3.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Node Manager.
nvd
CVE-2021-2351P3HIGHCVSS 7.5v12.2.1.3.0v12.2.1.4.02021-07-21
CVE-2021-2351 [HIGH] CWE-327 CVE-2021-2351: Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versi Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a perso
nvd
CVE-2010-2370P4MEDIUMCVSS 4.3PoCv5.7v6.0+1 more2010-07-13
CVE-2010-2370 [MEDIUM] CVE-2010-2370: Unspecified vulnerability in the Oracle Business Process Management component in Oracle Fusion Middl Unspecified vulnerability in the Oracle Business Process Management component in Oracle Fusion Middleware 5.7 MP3, 6.0 MP5, and 10.3 MP2 allows remote attackers to affect integrity, related to BPM.
nvd
CVE-2024-21190P3HIGHCVSS 7.5v12.2.1.4.02024-10-15
CVE-2024-21190 [HIGH] CVE-2024-21190: Vulnerability in the Oracle Global Lifecycle Management FMW Installer product of Oracle Fusion Middl Vulnerability in the Oracle Global Lifecycle Management FMW Installer product of Oracle Fusion Middleware (component: Cloning). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SFTP to compromise Oracle Global Lifecycle Management FMW Installer. Successful attacks of
nvd
CVE-2013-5791P4LOWCVSS 1.5PoCv8.4v8.4.12013-10-16
CVE-2013-5791 [LOW] CVE-2013-5791: Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.0 and 8.4.1 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters. NOTE: the previous information is from the October 2013 CPU. Oracle has not commented on claims from a third party that the issue is a stack
nvd
CVE-2014-2470P3HIGHCVSS 7.5v10.0.2v10.3.6+2 more2014-04-16
CVE-2014-2470 [HIGH] CVE-2014-2470: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2 Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Security.
nvd
CVE-2018-1304P3MEDIUMCVSS 5.9v12.2.1.3.02018-02-28
CVE-2018-1304 [MEDIUM] CVE-2018-1304: The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly ha The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access
nvd
CVE-2014-3576P3HIGHCVSS 7.5v8.1v9.0+2 more2015-08-14
CVE-2014-3576 [HIGH] CWE-264 CVE-2014-3576: The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11 The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command.
nvd
CVE-2018-1305P3MEDIUMCVSS 6.5v12.2.1.3.02018-02-23
CVE-2018-1305 [MEDIUM] CVE-2018-1305: Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 were only applied once a Servlet had been loaded. Because security constraints defined in this way apply to the URL pattern and any URLs below that point, it was possible - depending on the order Servlets were lo
nvd
CVE-2024-21215P3HIGHCVSS 7.5v12.2.1.4.0v14.1.1.0.02024-10-15
CVE-2024-21215 [HIGH] CWE-862 CVE-2024-21215: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in u
nvd
CVE-2010-3592P3HIGHCVSS 8.5v10.1.3.4v10.1.3.52011-01-19
CVE-2010-3592 [HIGH] CVE-2010-3592: Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1. Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affect integrity and availability via unknown vectors related to Internal Operations.
nvd
CVE-2015-2606P3HIGHCVSS 7.5v2.2.2v2.3+3 more2015-07-16
CVE-2015-2606 [HIGH] CVE-2015-2606: Unspecified vulnerability in the Oracle Endeca Information Discovery Studio component in Oracle Fusi Unspecified vulnerability in the Oracle Endeca Information Discovery Studio component in Oracle Fusion Middleware 2.2.2, 2.3, 2.4, 3.0, and 3.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Integrator, a different vulnerability than CVE-2015-2602, CVE-2015-2603, CVE-2015-2604, CVE-2015-2605, and CV
nvd
CVE-2015-2605P3HIGHCVSS 7.5v2.2.2v2.3+3 more2015-07-16
CVE-2015-2605 [HIGH] CVE-2015-2605: Unspecified vulnerability in the Oracle Endeca Information Discovery Studio component in Oracle Fusi Unspecified vulnerability in the Oracle Endeca Information Discovery Studio component in Oracle Fusion Middleware 2.2.2, 2.3, 2.4, 3.0, and 3.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Integrator, a different vulnerability than CVE-2015-2602, CVE-2015-2603, CVE-2015-2604, CVE-2015-2606, and CV
nvd
CVE-2015-2603P3HIGHCVSS 7.5v2.2.2v2.3+3 more2015-07-16
CVE-2015-2603 [HIGH] CVE-2015-2603: Unspecified vulnerability in the Oracle Endeca Information Discovery Studio component in Oracle Fusi Unspecified vulnerability in the Oracle Endeca Information Discovery Studio component in Oracle Fusion Middleware 2.2.2, 2.3, 2.4, 3.0, and 3.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Integrator, a different vulnerability than CVE-2015-2602, CVE-2015-2604, CVE-2015-2605, CVE-2015-2606, and CV
nvd
CVE-2015-2604P3HIGHCVSS 7.5v2.2.2v2.3+3 more2015-07-16
CVE-2015-2604 [HIGH] CVE-2015-2604: Unspecified vulnerability in the Oracle Endeca Information Discovery Studio component in Oracle Fusi Unspecified vulnerability in the Oracle Endeca Information Discovery Studio component in Oracle Fusion Middleware 2.2.2, 2.3, 2.4, 3.0, and 3.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Integrator, a different vulnerability than CVE-2015-2602, CVE-2015-2603, CVE-2015-2605, CVE-2015-2606, and CV
nvd
CVE-2015-2602P3HIGHCVSS 7.5v2.2.2v2.3+3 more2015-07-16
CVE-2015-2602 [HIGH] CVE-2015-2602: Unspecified vulnerability in the Oracle Endeca Information Discovery Studio component in Oracle Fusi Unspecified vulnerability in the Oracle Endeca Information Discovery Studio component in Oracle Fusion Middleware 2.2.2, 2.3, 2.4, 3.0, and 3.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Integrator, a different vulnerability than CVE-2015-2603, CVE-2015-2604, CVE-2015-2605, CVE-2015-2606, and CV
nvd
Oracle Fusion Middleware vulnerabilities | cvebase