VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 18 hours ago
Reset
More filters (1)
Columns
Oracle product: Oracle Fusion Middleware / Servlet
Overview 2 matches, all in RASP scope · 1 protected · 0 KEV · 1 public PoC · 0 CISA SSVC · 1 EPSS ≥ 0.5 · 0 disputed
2matches, all in RASP scope 1protected50.0% 0KEV0.0% 1public PoC50.0% 0CISA SSVC0.0% 1EPSS ≥ 0.550.0% 0disputed0.0%
Critical 0 0.0% High 0 0.0% Medium 2 100.0% Low 0 0.0% None 0 0.0% Unknown 0 0.0%
Protected by RASP 1 50.0% Rule in development 0 0.0% Mitigation candidate 0 0.0% No exploit published 0 0.0% No fix identified 1 50.0% Mitigated by environment configuration 0 0.0% Queued for review 0 0.0% Not applicable 0 0.0% Out of RASP scope 0 0.0% Rejected 0 0.0%
blocked by ARMR today 1 50.0% not blocked 1 50.0% not established 0 0.0% unrecorded 0 0.0%
Exploited in the wild 0 0.0% Working exploit published 1 50.0% Proof of concept only 0 0.0% Forecast only 0 0.0% No public exploit 1 50.0%
split by peak 1 / year
Unknown: 0None: 0Low: 0Medium: 2High: 0Critical: 0 Rejected: 0Out of RASP scope: 0Not applicable: 0Queued for review: 0Mitigated by environment configuration: 0No fix identified: 1No exploit published: 0Mitigation candidate: 0Rule in development: 0Protected by RASP: 1 unrecorded: 0not established: 0not blocked: 1blocked by ARMR today: 1 No public exploit: 1Forecast only: 0Proof of concept only: 0Working exploit published: 1Exploited in the wild: 0 2012: 1 CVE 2013: 0 CVEs 2014: 0 CVEs 2015: 0 CVEs 2016: 0 CVEs 2017: 0 CVEs 2018: 0 CVEs 2019: 0 CVEs 2020: 0 CVEs 2021: 0 CVEs 2022: 0 CVEs 2023: 0 CVEs 2024: 1 CVE
2012201420162018202020222024
2 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2024-21133 Medium 2024-07-16 No fix identified No public exploit Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Servlet). Supported versions that are affected are 12.2.1.4.0 and 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Reports Developer accessible data as well as unauthorized read access to a subset of Oracle Reports Developer accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
CVE-2012-3153 Medium 2012-10-16 Protected by RASP Working exploit published Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Servlet. NOTE: the previous information is from the October 2012 CPU. Oracle has not commented on claims from the original researcher that the PARSEQUERY function allows remote attackers to obtain database credentials via reports/rwservlet/parsequery, and that this issue occurs in earlier versions. NOTE: this can be leveraged with CVE-2012-3152 to execute arbitrary code by uploading a .jsp file.