Oracle Ilearning vulnerabilities

16 known vulnerabilities affecting oracle/ilearning.

Total CVEs
16
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM11

Vulnerabilities

Page 1 of 1
CVE-2022-23437MEDIUMCVSS 6.5v6.2v6.32022-01-24
CVE-2022-23437 [MEDIUM] CWE-835 CVE-2022-23437: There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially c There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
nvd
CVE-2021-2351HIGHCVSS 7.5v6.2v6.32021-07-21
CVE-2021-2351 [HIGH] CWE-327 CVE-2021-2351: Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versi Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a perso
nvd
CVE-2020-17521MEDIUMCVSS 5.5v6.2v6.32020-12-07
CVE-2020-17521 [MEDIUM] CVE-2020-17521: Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this f Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected,
nvd
CVE-2020-14595HIGHCVSS 8.2v6.1v6.1.12020-07-15
CVE-2020-14595 [HIGH] CVE-2020-14595: Vulnerability in the Oracle iLearning product of Oracle iLearning (component: Assessment Manager). S Vulnerability in the Oracle iLearning product of Oracle iLearning (component: Assessment Manager). Supported versions that are affected are 6.1 and 6.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iLearning. Successful attacks of this vulnerability can result in unauthorized access to cr
nvd
CVE-2020-2709MEDIUMCVSS 4.7v6.12020-01-15
CVE-2020-2709 [MEDIUM] CVE-2020-2709: Vulnerability in the Oracle iLearning product of Oracle iLearning (component: Learner Pages). The su Vulnerability in the Oracle iLearning product of Oracle iLearning (component: Learner Pages). The supported version that is affected is 6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iLearning. Successful attacks require human interaction from a person other than the attacker and while t
nvd
CVE-2018-3146HIGHCVSS 8.2v6.1v6.22018-10-17
CVE-2018-3146 [HIGH] CVE-2018-3146: Vulnerability in the Oracle iLearning component of Oracle iLearning (subcomponent: Learner Administr Vulnerability in the Oracle iLearning component of Oracle iLearning (subcomponent: Learner Administration). Supported versions that are affected are 6.1 and 6.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iLearning. Successful attacks require human interaction from a person other than the a
nvd
CVE-2018-2989HIGHCVSS 8.2v6.22018-07-18
CVE-2018-2989 [HIGH] CVE-2018-2989: Vulnerability in the Oracle iLearning component of Oracle iLearning (subcomponent: Learner Administr Vulnerability in the Oracle iLearning component of Oracle iLearning (subcomponent: Learner Administration). The supported version that is affected is 6.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iLearning. Successful attacks require human interaction from a person other than the attacker
nvd
CVE-2017-10199HIGHCVSS 8.2v6.22017-08-08
CVE-2017-10199 [HIGH] CVE-2017-10199: Vulnerability in the Oracle iLearning component of Oracle iLearning (subcomponent: Learner Pages). T Vulnerability in the Oracle iLearning component of Oracle iLearning (subcomponent: Learner Pages). The supported version that is affected is 6.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iLearning. Successful attacks require human interaction from a person other than the attacker and wh
nvd
CVE-2016-0508MEDIUMCVSS 4.3v6.0v6.12016-01-21
CVE-2016-0508 [MEDIUM] CVE-2016-0508: Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 6.0 and 6.1 allows r Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 6.0 and 6.1 allows remote attackers to affect integrity via unknown vectors related to Learner Administration.
nvd
CVE-2014-6594MEDIUMCVSS 4.3v6.0v6.12015-01-21
CVE-2014-6594 [MEDIUM] CVE-2014-6594: Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 6.0 and 6.1 allows r Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 6.0 and 6.1 allows remote attackers to affect confidentiality via unknown vectors related to Learner Pages.
nvd
CVE-2015-0436MEDIUMCVSS 4.3v6.0v6.12015-01-21
CVE-2015-0436 [MEDIUM] CVE-2015-0436: Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 6.0 and 6.1 allows r Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 6.0 and 6.1 allows remote attackers to affect confidentiality via unknown vectors related to Login.
nvd
CVE-2014-2471MEDIUMCVSS 4.3v6.0v6.12014-04-16
CVE-2014-2471 [MEDIUM] CVE-2014-2471: Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 6.0 and 6.1 allows r Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 6.0 and 6.1 allows remote attackers to affect integrity via unknown vectors related to Learner Pages.
nvd
CVE-2014-0389MEDIUMCVSS 4.3v6.02014-01-15
CVE-2014-0389 [MEDIUM] CVE-2014-0389: Unspecified vulnerability in Oracle iLearning 6.0 allows remote attackers to affect integrity via un Unspecified vulnerability in Oracle iLearning 6.0 allows remote attackers to affect integrity via unknown vectors related to Learner Pages.
nvd
CVE-2013-5845MEDIUMCVSS 4.3v5.2.1v6.02013-10-16
CVE-2013-5845 [MEDIUM] CVE-2013-5845: Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 5.2.1 and 6.0 allows Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 5.2.1 and 6.0 allows remote attackers to affect integrity via unknown vectors related to Learner Administration.
nvd
CVE-2013-5822MEDIUMCVSS 6.8v5.2.1v6.02013-10-16
CVE-2013-5822 [MEDIUM] CVE-2013-5822: Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 5.2.1 and 6.0 allows Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 5.2.1 and 6.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Learner Administration.
nvd
CVE-2013-3775MEDIUMCVSS 4.3v5.2.1v6.02013-07-17
CVE-2013-3775 [MEDIUM] CVE-2013-3775: Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 5.2.1 and 6.0 allows Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 5.2.1 and 6.0 allows remote attackers to affect integrity via unknown vectors related to Learner Pages.
nvd