VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 19 hours ago
Reset
More filters (1)
Columns
Oracle product: Oracle JD Edwards Products / Enterprise Infrastructure SEC
Overview 11 matches · 10 in RASP scope · 0 protected · 0 KEV · 0 public PoC · 0 CISA SSVC · 0 EPSS ≥ 0.5 · 0 disputed
11matches 10in RASP scope90.9% 0protected0.0% 0KEV0.0% 0public PoC0.0% 0CISA SSVC0.0% 0EPSS ≥ 0.50.0% 0disputed0.0%
Critical 0 0.0% High 3 27.3% Medium 8 72.7% Low 0 0.0% None 0 0.0% Unknown 0 0.0%
Protected by RASP 0 0.0% Rule in development 0 0.0% Mitigation candidate 0 0.0% No exploit published 0 0.0% No fix identified 10 90.9% Mitigated by environment configuration 0 0.0% Queued for review 0 0.0% Not applicable 0 0.0% Out of RASP scope 1 9.1% Rejected 0 0.0%
blocked by ARMR today 0 0.0% not blocked 11 100.0% not established 0 0.0% unrecorded 0 0.0%
Exploited in the wild 0 0.0% Working exploit published 0 0.0% Proof of concept only 0 0.0% Forecast only 0 0.0% No public exploit 11 100.0%
split by peak 7 / quarter
Unknown: 0None: 0Low: 0Medium: 8High: 3Critical: 0 Rejected: 0Out of RASP scope: 1Not applicable: 0Queued for review: 0Mitigated by environment configuration: 0No fix identified: 10No exploit published: 0Mitigation candidate: 0Rule in development: 0Protected by RASP: 0 unrecorded: 0not established: 0not blocked: 11blocked by ARMR today: 0 No public exploit: 11Forecast only: 0Proof of concept only: 0Working exploit published: 0Exploited in the wild: 0 Q2 2011: 7 CVEs Q3 2011: 0 CVEs Q4 2011: 0 CVEs Q1 2012: 0 CVEs Q2 2012: 0 CVEs Q3 2012: 0 CVEs Q4 2012: 0 CVEs Q1 2013: 0 CVEs Q2 2013: 0 CVEs Q3 2013: 0 CVEs Q4 2013: 0 CVEs Q1 2014: 0 CVEs Q2 2014: 0 CVEs Q3 2014: 0 CVEs Q4 2014: 0 CVEs Q1 2015: 0 CVEs Q2 2015: 0 CVEs Q3 2015: 0 CVEs Q4 2015: 0 CVEs Q1 2016: 4 CVEs
Q3 11Q1 12Q3 12Q1 13Q3 13Q1 14Q3 14Q1 15Q3 15Q1 16
11 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2015-3197 Medium 2016-02-15 Out of RASP scope No public exploit ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by performing computations on SSLv2 traffic, related to the get_client_master_key and get_client_hello functions.
CVE-2016-0424 High 2016-01-21 No fix identified No public exploit Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 9.1 and 9.2 allows remote attackers to affect availability via vectors related to Enterprise Infrastructure SEC, a different vulnerability than CVE-2016-0422.
CVE-2016-0423 High 2016-01-21 No fix identified No public exploit Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 9.1 and 9.2 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Enterprise Infrastructure SEC.
CVE-2016-0422 High 2016-01-21 No fix identified No public exploit Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 9.1 and 9.2 allows remote attackers to affect availability via vectors related to Enterprise Infrastructure SEC, a different vulnerability than CVE-2016-0424.
CVE-2011-0825 Medium 2011-04-20 No fix identified No public exploit Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Tools 8.9 GA through 8.98.4.1 and OneWorld Tools through 24.1.3 allows remote attackers to affect confidentiality, integrity, and availability, related to Enterprise Infrastructure SEC.
CVE-2011-0824 Medium 2011-04-20 No fix identified No public exploit Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Tools 8.9 GA through 8.98.4.1 and OneWorld Tools through 24.1.3 allows remote attackers to affect confidentiality and integrity, related to Enterprise Infrastructure SEC.
CVE-2011-0823 Medium 2011-04-20 No fix identified No public exploit Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Tools 8.9 GA through 8.98.4.1 and OneWorld Tools through 24.1.3 allows remote attackers to affect integrity, related to Enterprise Infrastructure SEC, a different vulnerability than CVE-2011-0819.
CVE-2011-0819 Medium 2011-04-20 No fix identified No public exploit Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Tools 8.9 GA through 8.98.4.1 and OneWorld Tools through 24.1.3 allows remote attackers to affect integrity, related to Enterprise Infrastructure SEC, a different vulnerability than CVE-2011-0823.
CVE-2011-0818 Medium 2011-04-20 No fix identified No public exploit Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Tools 8.9 GA through 8.98.4.1 and OneWorld Tools through 24.1.3 allows remote attackers to affect availability, related to Enterprise Infrastructure SEC.
CVE-2011-0810 Medium 2011-04-20 No fix identified No public exploit Unspecified vulnerability Oracle JD Edwards EnterpriseOne Tools 8.9 GA through 8.98.4.1 and OneWorld Tools through 24.1.3 allows remote attackers to affect availability, related to Enterprise Infrastructure SEC.
CVE-2011-0803 Medium 2011-04-20 No fix identified No public exploit Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 8.9 GA through 8.98.4.1, and OneWorld Tools through 24.1.3, allows remote attackers to affect integrity and availability, related to Enterprise Infrastructure SEC.