VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 19 hours ago
Reset
More filters (1)
Columns
Advisory: Oracle Critical Patch Update October 2016
Overview 13 matches · 8 in RASP scope · 4 protected · 0 KEV · 2 public PoC · 0 CISA SSVC · 2 EPSS ≥ 0.5 · 0 disputed
13matches 8in RASP scope61.5% 4protected30.8% 0KEV0.0% 2public PoC15.4% 0CISA SSVC0.0% 2EPSS ≥ 0.515.4% 0disputed0.0%
Critical 13 100.0% High 0 0.0% Medium 0 0.0% Low 0 0.0% None 0 0.0% Unknown 0 0.0%
Protected by RASP 1 7.7% Rule in development 0 0.0% Mitigation candidate 0 0.0% No exploit published 0 0.0% No fix identified 4 30.8% Mitigated by environment configuration 3 23.1% Queued for review 0 0.0% Not applicable 3 23.1% Out of RASP scope 2 15.4% Rejected 0 0.0%
blocked by ARMR today 4 30.8% not blocked 9 69.2% not established 0 0.0% unrecorded 0 0.0%
Exploited in the wild 0 0.0% Working exploit published 2 15.4% Proof of concept only 0 0.0% Forecast only 0 0.0% No public exploit 11 84.6%
split by peak 10 / quarter
Unknown: 0None: 0Low: 0Medium: 0High: 0Critical: 13 Rejected: 0Out of RASP scope: 2Not applicable: 3Queued for review: 0Mitigated by environment configuration: 3No fix identified: 4No exploit published: 0Mitigation candidate: 0Rule in development: 0Protected by RASP: 1 unrecorded: 0not established: 0not blocked: 9blocked by ARMR today: 4 No public exploit: 11Forecast only: 0Proof of concept only: 0Working exploit published: 2Exploited in the wild: 0 Q3 2015: 1 CVE Q4 2015: 0 CVEs Q1 2016: 0 CVEs Q2 2016: 0 CVEs Q3 2016: 1 CVE Q4 2016: 10 CVEs Q1 2017: 0 CVEs Q2 2017: 0 CVEs Q3 2017: 0 CVEs Q4 2017: 1 CVE
Q3 15Q4 15Q1 16Q2 16Q3 16Q4 16Q1 17Q2 17Q3 17Q4 17
13 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2015-7501 Critical 2017-11-09 Protected by RASP Working exploit published Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
CVE-2016-5605 Critical 2016-10-25 Not applicable No public exploit Unspecified vulnerability in the Oracle VM VirtualBox component before 5.1.4 in Oracle Virtualization allows remote attackers to affect confidentiality and integrity via vectors related to VRDE.
CVE-2016-5599 Critical 2016-10-25 No fix identified No public exploit Unspecified vulnerability in the Oracle Advanced Supply Chain Planning component in Oracle Supply Chain Products Suite 12.2.3 through 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to MscObieeSrvlt.
CVE-2016-5582 Critical 2016-10-25 Mitigated by environment configuration No public exploit Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5573.
CVE-2016-5580 Critical 2016-10-25 Not applicable No public exploit Unspecified vulnerability in the Secure Global Desktop component in Oracle Virtualization 4.7 and 5.2 allows remote authenticated users to affect confidentiality and availability via vectors through Web Services.
CVE-2016-5568 Critical 2016-10-25 Mitigated by environment configuration No public exploit Unspecified vulnerability in Oracle Java SE 6u121, 7u111, and 8u102 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.
CVE-2016-5556 Critical 2016-10-25 Mitigated by environment configuration No public exploit Unspecified vulnerability in Oracle Java SE 6u121, 7u111, and 8u102 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to 2D.
CVE-2016-5555 Critical 2016-10-25 Out of RASP scope No public exploit Unspecified vulnerability in the OJVM component in Oracle Database Server 11.2.0.4 and 12.1.0.2 allows remote administrators to affect confidentiality, integrity, and availability via unknown vectors.
CVE-2016-5535 Critical 2016-10-25 No fix identified No public exploit Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, 12.2.1.0, and 12.2.1.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
CVE-2016-5531 Critical 2016-10-25 No fix identified No public exploit Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS-WebServices.
CVE-2016-3551 Critical 2016-10-25 No fix identified No public exploit Unspecified vulnerability in the Oracle Web Services component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, and 12.2.1.0.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAXWS Web Services Stack.
CVE-2016-6662 Critical 2016-09-20 Not applicable Working exploit published Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain protection mechanisms by setting general_log_file to a my.cnf configuration. NOTE: this can be leveraged to execute arbitrary code with root privileges by setting malloc_lib. NOTE: the affected MySQL version information is from Oracle's October 2016 CPU. Oracle has not commented on third-party claims that the issue was silently patched in MySQL 5.5.52, 5.6.33, and 5.7.15.
CVE-2015-3253 Critical 2015-08-13 Out of RASP scope No public exploit The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.