Oracle Fusion Middleware vulnerabilities

310 known vulnerabilities affecting oracle/fusion_middleware.

Total CVEs
310
CISA KEV
3
actively exploited
Public exploits
28
Exploited in wild
3
Severity breakdown
CRITICAL7HIGH29MEDIUM207LOW67

Vulnerabilities

Page 5 of 16
CVE-2015-0362MEDIUMCVSS 5.0v11.1.1.7.02015-01-21
CVE-2015-0362 [MEDIUM] CVE-2015-0362: Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Mi Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Middleware 11.1.1.7 allows remote attackers to affect confidentiality via unknown vectors related to BI Publisher Security.
nvd
CVE-2014-6571MEDIUMCVSS 6.8v11.1.1.7.0v12.1.2.0.0+1 more2015-01-21
CVE-2014-6571 [MEDIUM] CVE-2014-6571: Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.7.0 Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Web Listener, a different vulnerability than CVE-2011-1944.
nvd
CVE-2015-0420MEDIUMCVSS 4.3v11.1.1.7.0v11.1.2.2.02015-01-21
CVE-2015-0420 [MEDIUM] CVE-2015-0420: Unspecified vulnerability in the Oracle Forms component in Oracle Fusion Middleware 11.1.1.7 and 11. Unspecified vulnerability in the Oracle Forms component in Oracle Fusion Middleware 11.1.1.7 and 11.1.2.2 allows remote attackers to affect confidentiality via unknown vectors related to Forms Services.
nvd
CVE-2014-6526MEDIUMCVSS 4.3v7.02015-01-21
CVE-2014-6526 [MEDIUM] CVE-2014-6526: Unspecified vulnerability in the Oracle Directory Server Enterprise Edition component in Oracle Fusi Unspecified vulnerability in the Oracle Directory Server Enterprise Edition component in Oracle Fusion Middleware 7.0 allows remote attackers to affect integrity via unknown vectors related to Admin Console.
nvd
CVE-2014-0191MEDIUMCVSS 4.3v11.1.1.7.0v12.1.2.0.0+1 more2015-01-21
CVE-2014-0191 [MEDIUM] CVE-2014-0191: The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as used in Web Listener The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as used in Web Listener in Oracle HTTP Server in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 and other products, loads external parameter entities regardless of whether entity substitution or validation is enabled, which allows remote attackers to cause a denial of se
nvd
CVE-2015-0372MEDIUMCVSS 5.0v10.1.3.52015-01-21
CVE-2015-0372 [MEDIUM] CVE-2015-0372: Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Fusion Middleware 10 Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality via unknown vectors.
nvd
CVE-2014-6576MEDIUMCVSS 5.5v11.1.1.5.0v11.1.1.7.0+2 more2015-01-21
CVE-2014-6576 [MEDIUM] CVE-2014-6576: Unspecified vulnerability in the Oracle Adaptive Access Manager component in Oracle Fusion Middlewar Unspecified vulnerability in the Oracle Adaptive Access Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote authenticated users to affect confidentiality and integrity via vectors related to OAM Integration.
nvd
CVE-2015-0376MEDIUMCVSS 4.3v11.1.1.8.02015-01-21
CVE-2015-0376 [MEDIUM] CVE-2015-0376: Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 11.1 Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 11.1.1.8.0 allows remote attackers to affect integrity via unknown vectors related to Content Server.
nvd
CVE-2015-0399MEDIUMCVSS 4.0v10.1.3.4.2v11.1.1.7.02015-01-21
CVE-2015-0399 [MEDIUM] CVE-2015-0399: Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Fusion Middleware 10.1.3.4.2 and 11.1.1.7 allows remote authenticated users to affect confidentiality via unknown vectors related to Analytics Web General.
nvd
CVE-2015-0434MEDIUMCVSS 4.3v11.1.1.5v11.1.1.7+2 more2015-01-21
CVE-2015-0434 [MEDIUM] CVE-2015-0434: Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1.1. Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote attackers to affect confidentiality via vectors related to Integration with OAM.
nvd
CVE-2015-0401MEDIUMCVSS 4.0v7.0v11.1.1.7.02015-01-21
CVE-2015-0401 [MEDIUM] CVE-2015-0401: Unspecified vulnerability in the Oracle Directory Server Enterprise Edition component in Oracle Fusi Unspecified vulnerability in the Oracle Directory Server Enterprise Edition component in Oracle Fusion Middleware 7.0 and 11.1.1.7 allows remote authenticated users to affect integrity via unknown vectors related to Admin Console.
nvd
CVE-2014-6580MEDIUMCVSS 4.3v11.1.1.7.0v11.1.2.2.02015-01-21
CVE-2014-6580 [MEDIUM] CVE-2014-6580: Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1 Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.7 and 11.1.2.2 allows remote attackers to affect integrity via unknown vectors.
nvd
CVE-2015-0386MEDIUMCVSS 4.3v11.1.1.7.0v12.1.2.0.0+1 more2015-01-21
CVE-2015-0386 [MEDIUM] CVE-2015-0386: Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.7.0 Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 allows remote attackers to affect availability via unknown vectors related to Web Listener, a different vulnerability than CVE-2013-0338, CVE-2013-2877, and CVE-2014-0191.
nvd
CVE-2015-0389LOWCVSS 3.5v8.02015-01-21
CVE-2015-0389 [LOW] CVE-2015-0389: Unspecified vulnerability in the Oracle OpenSSO component in Oracle Fusion Middleware 8.0 Update 2 P Unspecified vulnerability in the Oracle OpenSSO component in Oracle Fusion Middleware 8.0 Update 2 Patch 5 allows remote authenticated users to affect integrity via vectors related to SAML, a different vulnerability than CVE-2014-6592.
nvd
CVE-2014-6592LOWCVSS 3.5v8.02015-01-21
CVE-2014-6592 [LOW] CVE-2014-6592: Unspecified vulnerability in the Oracle OpenSSO component in Oracle Fusion Middleware 8.0 Update 2 P Unspecified vulnerability in the Oracle OpenSSO component in Oracle Fusion Middleware 8.0 Update 2 Patch 5 allows remote authenticated users to affect integrity via vectors related to SAML, a different vulnerability than CVE-2015-0389.
nvd
CVE-2015-0414LOWCVSS 3.5v11.1.1.7.0v12.1.3.0.02015-01-21
CVE-2015-0414 [LOW] CVE-2015-0414: Unspecified vulnerability in the Oracle SOA Suite component in Oracle Fusion Middleware 11.1.1.7 and Unspecified vulnerability in the Oracle SOA Suite component in Oracle Fusion Middleware 11.1.1.7 and 12.1.3.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Fabric Layer.
nvd
CVE-2014-6462MEDIUMCVSS 4.3v11.1.2.1.0v11.1.2.2.02014-10-15
CVE-2014-6462 [MEDIUM] CVE-2014-6462: Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1.2. Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1.2.1 and 11.1.2.2 allows remote attackers to affect integrity via unknown vectors related to Admin Console.
nvd
CVE-2014-6553MEDIUMCVSS 6.4v11.1.1.5.0v11.1.1.7.02014-10-15
CVE-2014-6553 [MEDIUM] CVE-2014-6553: Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1.1. Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1.1.5 and 11.1.1.7 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Admin Console.
nvd
CVE-2014-6534MEDIUMCVSS 4.0v10.0.2v10.3.6+3 more2014-10-15
CVE-2014-6534 [MEDIUM] CVE-2014-6534: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2 Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, 12.1.2.0, and 12.1.3.0 allows remote authenticated users to affect integrity via vectors related to WLS Console.
nvd
CVE-2014-6554MEDIUMCVSS 5.5v11.1.2.1.0v11.1.2.2.02014-10-15
CVE-2014-6554 [MEDIUM] CVE-2014-6554: Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1.2. Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1.2.1 and 11.1.2.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Admin Console.
nvd