Oracle Fusion Middleware vulnerabilities
312 known vulnerabilities affecting oracle/fusion_middleware.
Total CVEs
312
CISA KEV
3
actively exploited
Public exploits
30
Exploited in wild
5
Severity breakdown
CRITICAL7HIGH29MEDIUM209LOW67
Vulnerabilities
Page 3 of 16
CVE-2015-4745P3HIGHCVSS 7.5v2.2.2v2.3+3 more2015-07-16
CVE-2015-4745 [HIGH] CVE-2015-4745: Unspecified vulnerability in the Oracle Endeca Information Discovery Studio component in Oracle Fusi
Unspecified vulnerability in the Oracle Endeca Information Discovery Studio component in Oracle Fusion Middleware 2.2.2, 2.3, 2.4, 3.0, and 3.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Integrator, a different vulnerability than CVE-2015-2602, CVE-2015-2603, CVE-2015-2604, CVE-2015-2605, and CV
nvd
CVE-2020-5421P3MEDIUMCVSS 6.5v12.2.1.3.0v12.2.1.4.02020-09-19
CVE-2020-5421 [MEDIUM] CVE-2020-5421: In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and olde
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
nvd
CVE-2024-21191P3HIGHCVSS 7.6v12.2.1.4.02024-10-15
CVE-2024-21191 [HIGH] CVE-2024-21191: Vulnerability in the Oracle Enterprise Manager Fusion Middleware Control product of Oracle Fusion Mi
Vulnerability in the Oracle Enterprise Manager Fusion Middleware Control product of Oracle Fusion Middleware (component: FMW Control Plugin). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager Fusion Middleware Control. Succe
nvd
CVE-2013-1509P4MEDIUMCVSS 4.0PoCv7.6.2v11.1.1.6.0+1 more2013-04-17
CVE-2013-1509 [MEDIUM] CVE-2013-1509: Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 7.6.2,
Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 7.6.2, 11.1.1.6.0, and 11.1.1.6.1 allows remote authenticated users to affect integrity via unknown vectors related to WebCenter Sites.
nvd
CVE-2015-0396P3HIGHCVSS 7.5v3.0.1v3.1.22015-01-21
CVE-2015-0396 [HIGH] CVE-2015-0396: Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 3.0.1
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 3.0.1 and 3.1.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Admin Console.
nvd
CVE-2012-1695P3MEDIUMCVSS 6.8≤ 28.2.2v7.5.2+21 more2012-05-03
CVE-2012-1695 [MEDIUM] CVE-2012-1695: Unspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware 28.2.2 and ear
Unspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware 28.2.2 and earlier, and JDK/JRE 5 and 6 27.7.1 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2013-5785P3HIGHCVSS 7.5v11.1.1.6.0v11.1.1.7.0+1 more2014-01-15
CVE-2013-5785 [HIGH] CVE-2013-5785: Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.6, 11.1.1.7, and 11.1.2.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security and Authentication.
nvd
CVE-2011-2264P3MEDIUMCVSS 4.4v8.3.2.0v8.3.5.02011-07-21
CVE-2011-2264 [MEDIUM] CVE-2011-2264: Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.2.0 and 8.3.5.0 allows context-dependent attackers to affect confidentiality, integrity, and availability via unknown vectors related to Outside In Filters. NOTE: the previous information was obtained from the July 2011 CPU. Oracle has not commented on claim
nvd
CVE-2010-0853P3HIGHCVSS 7.5v10.1.2.3v10.1.4.0.12010-04-13
CVE-2010-0853 [HIGH] CVE-2010-0853: Unspecified vulnerability in the Oracle Internet Directory component in Oracle Database 9.2.0.8, 9.2
Unspecified vulnerability in the Oracle Internet Directory component in Oracle Database 9.2.0.8, 9.2.0.8, and DV; and Oracle Fusion Middleware 10.1.2.3 and 10.1.4.0.1; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2010-2390P3HIGHCVSS 7.5v10.1.2.3v10.1.4.32010-10-14
CVE-2010-2390 [HIGH] CVE-2010-2390: Unspecified vulnerability in the Database Control component in EM Console in Oracle Database Server
Unspecified vulnerability in the Database Control component in EM Console in Oracle Database Server 10.1.0.5 and 10.2.0.3, Oracle Fusion Middleware 10.1.2.3 and 10.1.4.3, and Enterprise Manager Grid Control allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2012-0557P3HIGHCVSS 7.5v8.3.5.0v8.3.7.02012-05-03
CVE-2012-0557 [HIGH] CVE-2012-0557: Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows remote attackers to affect confidentiality, integrity, and availability, related to Outside In Image Export SDK, a different vulnerability than CVE-2012-0554, CVE-2012-0555, and CVE-2012-0556.
nvd
CVE-2012-0555P3HIGHCVSS 7.5v8.3.5.0v8.3.7.02012-05-03
CVE-2012-0555 [HIGH] CVE-2012-0555: Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows remote attackers to affect confidentiality, integrity, and availability, related to Outside In Image Export SDK, a different vulnerability than CVE-2012-0554, CVE-2012-0556, and CVE-2012-0557.
nvd
CVE-2012-0556P3HIGHCVSS 7.5v8.3.5.0v8.3.7.02012-05-03
CVE-2012-0556 [HIGH] CVE-2012-0556: Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows remote attackers to affect confidentiality, integrity, and availability, related to Outside In Image Export SDK, a different vulnerability than CVE-2012-0554, CVE-2012-0555, and CVE-2012-0557.
nvd
CVE-2012-0554P3HIGHCVSS 7.5v8.3.5.0v8.3.7.02012-05-03
CVE-2012-0554 [HIGH] CVE-2012-0554: Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows remote attackers to affect confidentiality, integrity, and availability, related to Outside In Image Export SDK, a different vulnerability than CVE-2012-0555, CVE-2012-0556, and CVE-2012-0557.
nvd
CVE-2012-1709P3HIGHCVSS 7.5v10.1.3.52012-05-03
CVE-2012-1709 [HIGH] CVE-2012-1709: Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middl
Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Designer, a different vulnerability than CVE-2012-1710.
nvd
CVE-2015-2636P3HIGHCVSS 7.5v11.1.1.3.02015-07-16
CVE-2015-2636 [HIGH] CVE-2015-2636: Unspecified vulnerability in the Oracle Data Integrator component in Oracle Fusion Middleware 11.1.1
Unspecified vulnerability in the Oracle Data Integrator component in Oracle Fusion Middleware 11.1.1.3.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Data Quality based on Trillium, a different vulnerability than CVE-2015-0443, CVE-2015-0444, CVE-2015-0445, CVE-2015-0446, CVE-2015-2634, CVE-2015-2
nvd
CVE-2014-4267P3MEDIUMCVSS 6.8v10.0.2v10.3.6+2 more2014-07-17
CVE-2014-4267 [MEDIUM] CVE-2014-4267: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Core Components.
nvd
CVE-2024-21205P3MEDIUMCVSS 6.5v12.2.1.4.02024-10-15
CVE-2024-21205 [MEDIUM] CWE-200 CVE-2024-21205: Vulnerability in the Oracle Service Bus product of Oracle Fusion Middleware (component: OSB Core Fun
Vulnerability in the Oracle Service Bus product of Oracle Fusion Middleware (component: OSB Core Functionality). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Service Bus. Successful attacks of this vulnerability can result in un
nvd
CVE-2018-3109P3MEDIUMCVSS 6.5v12.2.1.2v12.2.1.32018-08-02
CVE-2018-3109 [MEDIUM] CVE-2018-3109: Vulnerability in the Oracle Fusion Middleware MapViewer component of Oracle Fusion Middleware (subco
Vulnerability in the Oracle Fusion Middleware MapViewer component of Oracle Fusion Middleware (subcomponent: Map Builder). Supported versions that are affected are 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Fusion Middleware MapViewer. Successful attacks of this vuln
nvd
CVE-2018-3108P3MEDIUMCVSS 6.5v12.2.1.2v12.2.1.32018-08-02
CVE-2018-3108 [MEDIUM] CVE-2018-3108: Vulnerability in the Oracle Fusion Middleware component of Oracle Fusion Middleware (subcomponent: O
Vulnerability in the Oracle Fusion Middleware component of Oracle Fusion Middleware (subcomponent: Oracle Notification Service). Supported versions that are affected are 12.2.1.2 and 12.2.1.3. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Fusion Middleware. Successful attacks of this vulne
nvd