Oracle Soa Suite vulnerabilities

9 known vulnerabilities affecting oracle/soa_suite.

Total CVEs
9
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH5MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2022-21622HIGHCVSS 7.5v12.2.1.3.0v12.2.1.4.02022-10-18
CVE-2022-21622 [HIGH] CVE-2022-21622: Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Adapters). Sup Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Adapters). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this vulnerability can result in unauthorized cr
nvd
CVE-2022-21562HIGHCVSS 7.5v12.2.1.3.0v12.2.1.4.02022-07-19
CVE-2022-21562 [HIGH] CVE-2022-21562: Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Fabric Layer). Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Fabric Layer). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this vulnerability can result in unauthorize
nvd
CVE-2019-17359HIGHCVSS 7.5v12.2.1.3.0v12.2.1.4.02019-10-08
CVE-2019-17359 [HIGH] CWE-770 CVE-2019-17359: The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory all The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
nvd
CVE-2019-2572MEDIUMCVSS 5.3v11.1.1.9.02019-04-23
CVE-2019-2572 [MEDIUM] CVE-2019-2572: Vulnerability in the Oracle SOA Suite component of Oracle Fusion Middleware (subcomponent: Fabric La Vulnerability in the Oracle SOA Suite component of Oracle Fusion Middleware (subcomponent: Fabric Layer). The supported version that is affected is 11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this vulnerability can result in unauthorized read ac
nvd
CVE-2018-3105MEDIUMCVSS 4.3v11.1.1.7.0v11.1.1.9.0+3 more2018-07-18
CVE-2018-3105 [MEDIUM] CVE-2018-3105: Vulnerability in the Oracle SOA Suite component of Oracle Fusion Middleware (subcomponent: Health Ca Vulnerability in the Oracle SOA Suite component of Oracle Fusion Middleware (subcomponent: Health Care FastPath). Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, 12.2.1.2.0 and 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks
nvd
CVE-2018-1000613CRITICALCVSS 9.8v12.1.3.0.0v12.2.1.3.02018-07-09
CVE-2018-1000613 [CRITICAL] CWE-470 CVE-2018-1000613: Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not in Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result
nvd
CVE-2018-1000180HIGHCVSS 7.5v12.1.3.0.0v12.2.1.3.02018-06-05
CVE-2018-1000180 [HIGH] CWE-327 CVE-2018-1000180: Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level in Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
nvd
CVE-2017-10026HIGHCVSS 8.2v11.1.1.7.02017-10-19
CVE-2017-10026 [HIGH] CVE-2017-10026: Vulnerability in the Oracle SOA Suite component of Oracle Fusion Middleware (subcomponent: Fabric La Vulnerability in the Oracle SOA Suite component of Oracle Fusion Middleware (subcomponent: Fabric Layer). The supported version that is affected is 11.1.1.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks require human interaction from a person other than the a
nvd
CVE-2017-5645CRITICALCVSS 9.8PoCv12.1.3.0.0v12.2.1.3.0+1 more2017-04-17
CVE-2017-5645 [CRITICAL] CWE-502 CVE-2017-5645: In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive s In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
nvd