target entity

Oracle

45 source-linked records in the current knowledge graph.

high

CVE-2026-46817: Oracle E-Business Suite Improper Privilege Management Vulnerability

Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-46817EPSS 1.0%E-Business SuiteOracle
CISA KEV ↗ · unattributed attribution
high

CVE-2026-35273: Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability

Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-35273EPSS 92.3% PeopleSoft Enterprise PeopleToolsOracle
CISA KEV ↗ · unattributed attribution
high

CVE-2024-21182: Oracle WebLogic Server Unspecified Vulnerability

Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-21182EPSS 49.7%OracleWebLogic Server
CISA KEV ↗ · unattributed attribution
high

CVE-2025-61757: Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability

Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-61757EPSS 88.3%Fusion MiddlewareOracle
CISA KEV ↗ · unattributed attribution
high

CVE-2025-61884: Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability

Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-61884EPSS 97.8%E-Business SuiteOracle
CISA KEV ↗ · unattributed attribution
high

CVE-2025-61882: Oracle E-Business Suite Unspecified Vulnerability

Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks can result in takeover of Oracle Concurrent Processing. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-61882EPSS 99.7%E-Business SuiteOracle
CISA KEV ↗ · unattributed attribution
high

CVE-2024-20953: Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability

Oracle Agile Product Lifecycle Management (PLM) contains a deserialization vulnerability that allows a low-privileged attacker with network access via HTTP to compromise the system. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-20953EPSS 3.4%Agile Product Lifecycle Management (PLM)Oracle
CISA KEV ↗ · unattributed attribution
high

CVE-2020-2883: Oracle WebLogic Server Unspecified Vulnerability

Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an unspecified vulnerability exploitable by an unauthenticated attacker with network access via IIOP or T3. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2020-2883EPSS 94.9%OracleWebLogic Server
CISA KEV ↗ · unattributed attribution
high

CVE-2024-21287: Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability

Oracle Agile Product Lifecycle Management (PLM) contains an incorrect authorization vulnerability in the Process Extension component of the Software Development Kit. Successful exploitation of this vulnerability may result in unauthenticated file disclosure. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-21287EPSS 1.5%Agile Product Lifecycle Management (PLM)Oracle
CISA KEV ↗ · unattributed attribution
high

CVE-2020-14644: Oracle WebLogic Server Remote Code Execution Vulnerability

Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deserialization vulnerability. Unauthenticated attackers with network access via T3 or IIOP can exploit this vulnerability to achieve remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2020-14644EPSS 94.5%OracleWebLogic Server
CISA KEV ↗ · unattributed attribution
high

CVE-2022-21445: Oracle ADF Faces Deserialization of Untrusted Data Vulnerability

Oracle ADF Faces library, included with Oracle JDeveloper Distribution, contains a deserialization of untrusted data vulnerability leading to unauthenticated remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2022-21445EPSS 62.5%ADF FacesOracle
CISA KEV ↗ · unattributed attribution
high

CVE-2017-3506: Oracle WebLogic Server OS Command Injection Vulnerability

Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an OS command injection vulnerability that allows an attacker to execute arbitrary code via a specially crafted HTTP request that includes a malicious XML document. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2017-3506EPSS 96.3%OracleWebLogic Server
CISA KEV ↗ · unattributed attribution
high

CVE-2020-2551: Oracle Fusion Middleware Unspecified Vulnerability

Oracle Fusion Middleware contains an unspecified vulnerability in the WLS Core Components that allows an unauthenticated attacker with network access via IIOP to compromise the WebLogic Server. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2020-2551EPSS 93.2%Fusion MiddlewareOracle
CISA KEV ↗ · unattributed attribution
high

CVE-2016-3427: Oracle Java SE and JRockit Unspecified Vulnerability

Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Management Extensions (JMX). This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. Required action: Apply updates per vendor instructions.

CVE-2016-3427EPSS 92.3%Java SE and JRockitOracle
CISA KEV ↗ · unattributed attribution
high

CVE-2023-21839: Oracle WebLogic Server Unspecified Vulnerability

Oracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticated attacker with network access via T3, IIOP, to compromise Oracle WebLogic Server. Required action: Apply updates per vendor instructions.

CVE-2023-21839EPSS 99.8%OracleWebLogic Server
CISA KEV ↗ · unattributed attribution
high

CVE-2022-21587: Oracle E-Business Suite Unspecified Vulnerability

Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Required action: Apply updates per vendor instructions.

CVE-2022-21587EPSS 98.3%E-Business SuiteOracle
CISA KEV ↗ · unattributed attribution
high

CVE-2018-2628: Oracle WebLogic Server Unspecified Vulnerability

Oracle WebLogic Server contains an unspecified vulnerability which can allow an unauthenticated attacker with T3 network access to compromise the server. Required action: Apply updates per vendor instructions.

CVE-2018-2628EPSS 99.4%OracleWebLogic Server
CISA KEV ↗ · unattributed attribution
high

CVE-2013-2423: Oracle JRE Unspecified Vulnerability

Unspecified vulnerability in hotspot for Java Runtime Environment (JRE) allows remote attackers to affect integrity. Required action: Apply updates per vendor instructions.

CVE-2013-2423EPSS 85.3%Java Runtime Environment (JRE)Oracle
CISA KEV ↗ · unattributed attribution
high

CVE-2013-0431: Oracle JRE Sandbox Bypass Vulnerability

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox. Required action: Apply updates per vendor instructions.

CVE-2013-0431EPSS 90.0%Java Runtime Environment (JRE)Oracle
CISA KEV ↗ · unattributed attribution
high

CVE-2013-0422: Oracle JRE Remote Code Execution Vulnerability

A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system. Required action: Apply updates per vendor instructions.

CVE-2013-0422EPSS 97.6%Java Runtime Environment (JRE)Oracle
CISA KEV ↗ · unattributed attribution
high

CVE-2012-1710: Oracle Fusion Middleware Unspecified Vulnerability

Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Designer. Required action: Apply updates per vendor instructions.

CVE-2012-1710EPSS 11.6%Fusion MiddlewareOracle
CISA KEV ↗ · unattributed attribution
high

CVE-2010-0840: Oracle JRE Unspecified Vulnerability

Unspecified vulnerability in the Java Runtime Environment (JRE) in Java SE component allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors. Required action: Apply updates per vendor instructions.

CVE-2010-0840EPSS 96.3%Java Runtime Environment (JRE)Oracle
CISA KEV ↗ · unattributed attribution
high

CVE-2013-2465: Oracle Java SE Unspecified Vulnerability

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to 2D Required action: Apply updates per vendor instructions.

CVE-2013-2465EPSS 98.7%Java SEOracle
CISA KEV ↗ · unattributed attribution
high

CVE-2012-5076: Oracle Java SE Sandbox Bypass Vulnerability

The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions. Required action: Apply updates per vendor instructions.

CVE-2012-5076EPSS 91.0%Java SEOracle
CISA KEV ↗ · unattributed attribution · 2 IOCs
high

CVE-2012-0518: Oracle Fusion Middleware Unspecified Vulnerability

Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware allows remote attackers to affect integrity via Unknown vectors Required action: Apply updates per vendor instructions.

CVE-2012-0518EPSS 4.7%Fusion MiddlewareOracle
CISA KEV ↗ · unattributed attribution
high

CVE-2019-2616: Oracle BI Publisher Unauthorized Access Vulnerability

Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for authentication bypass. Required action: Apply updates per vendor instructions.

CVE-2019-2616EPSS 92.2%BI Publisher (Formerly XML Publisher)Oracle
CISA KEV ↗ · unattributed attribution
high

CVE-2019-2725: Oracle WebLogic Server, Injection

Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Required action: Apply updates per vendor instructions.

CVE-2019-2725EPSS 100.0%OracleWebLogic Server
CISA KEV ↗ · unattributed attribution
high

CVE-2020-2555: Oracle Multiple Products Remote Code Execution Vulnerability

Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware, Oracle Utilities Framework, Oracle Retail Assortment Planning, Oracle Commerce, Oracle Communications Diameter Signaling Router (DSR). Required action: Apply updates per vendor instructions.

CVE-2020-2555EPSS 97.1%Multiple ProductsOracle
CISA KEV ↗ · unattributed attribution
high

CVE-2012-3152: Oracle Fusion Middleware Unspecified Vulnerability

Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability that allows remote attackers to affect confidentiality and integrity of affected systems. Required action: Apply updates per vendor instructions.

CVE-2012-3152EPSS 98.7%Fusion MiddlewareOracle
CISA KEV ↗ · unattributed attribution
high

CVE-2020-14750: Oracle WebLogic Server Remote Code Execution Vulnerability

Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882. Required action: Apply updates per vendor instructions.

CVE-2020-14750CVE-2020-14882EPSS 100.0%OracleWebLogic Server
CISA KEV ↗ · unattributed attribution
high

CVE-2020-14883: Oracle WebLogic Server Unspecified Vulnerability

Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentilaity, integrity, and availability. Required action: Apply updates per vendor instructions.

CVE-2020-14883EPSS 97.9%OracleWebLogic Server
CISA KEV ↗ · unattributed attribution