cbcvebase.

Oracle Product Lifecycle Analytics vulnerabilities

14 known vulnerabilities affecting oracle/product_lifecycle_analytics.

Total CVEs
14
CISA KEV
2
actively exploited
Public exploits
2
Exploited in wild
3
Severity breakdown
CRITICAL4HIGH6MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2022-22965P1CRITICALCVSS 9.8KEVPoCRansomwarev3.6.12022-04-01
CVE-2022-22965 [CRITICAL] CWE-94 CVE-2022-22965: A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execut A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature
nvd
CVE-2022-22963P1CRITICALCVSS 9.8KEVPoCv3.6.1.02022-04-01
CVE-2022-22963 [CRITICAL] CWE-94 CVE-2022-22963: In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing fu In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
nvd
CVE-2021-44832P1MEDIUMCVSS 6.6ExploitedRansomwarev3.6.12021-12-28
CVE-2021-44832 [MEDIUM] CWE-20 CVE-2021-44832: Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) a Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java
nvd
CVE-2020-11987P2HIGHCVSS 8.2v3.6.12021-02-24
CVE-2020-11987 [HIGH] CWE-20 CVE-2020-11987: Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
nvd
CVE-2026-61175P3CRITICALCVSS 9.3v3.6.12026-07-21
CVE-2026-61175 [CRITICAL] CWE-200 CVE-2026-61175: Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: I Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracl
nvd
CVE-2026-71049P3HIGHCVSS 8.5v3.6.12026-08-18
CVE-2026-71049 [HIGH] CWE-284 CVE-2026-71049: Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: I Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle Net to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Orac
nvd
CVE-2026-71050P3HIGHCVSS 8.7v3.6.12026-08-18
CVE-2026-71050 [HIGH] CWE-284 CVE-2026-71050: Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: I Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Ora
nvd
CVE-2026-61174P3CRITICALCVSS 9.0v3.6.12026-07-21
CVE-2026-61174 [CRITICAL] CWE-284 CVE-2026-61174: Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: I Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Product Lifecycle Analytics executes to compromise Oracle Product Li
nvd
CVE-2026-71048P3HIGHCVSS 7.6v3.6.12026-08-18
CVE-2026-71048 [HIGH] CWE-284 CVE-2026-71048: Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: I Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics. Successful attacks of this vulnerability
nvd
CVE-2026-71051P3HIGHCVSS 8.8v3.6.12026-08-18
CVE-2026-71051 [HIGH] CWE-284 CVE-2026-71051: Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: I Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Product Lifecycle Analytics executes to compromise Oracle Product Lifecyc
nvd
CVE-2021-2351P3HIGHCVSS 7.5v3.6.12021-07-21
CVE-2021-2351 [HIGH] CWE-327 CVE-2021-2351: Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versi Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a perso
nvd
CVE-2022-23437P3MEDIUMCVSS 6.5v3.6.12022-01-24
CVE-2022-23437 [MEDIUM] CWE-835 CVE-2022-23437: There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially c There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
nvd
CVE-2026-61176P3MEDIUMCVSS 6.7v3.6.12026-07-21
CVE-2026-61176 [MEDIUM] CWE-269 CVE-2026-61176: Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: I Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics. Successful attacks of this vulnerabil
nvd
CVE-2021-36374P4MEDIUMCVSS 5.5v3.6.12021-07-14
CVE-2021-36374 [MEDIUM] CWE-130 CVE-2021-36374: When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apac
nvd
Oracle Product Lifecycle Analytics vulnerabilities | cvebase