{"id":"CVE-2016-0635","description":"Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 12.1.4, 12.2.2, and 12.3.2; the Oracle Health Sciences Information Manager component in Oracle Health Sciences Applications 1.2.8.3, 2.0.2.3, and 3.0.1.0; the Oracle Healthcare Master Person Index component in Oracle Health Sciences Applications 2.0.12, 3.0.0, and 4.0.1; the Oracle Documaker component in Oracle Insurance Applications before 12.5; the Oracle Insurance Calculation Engine component in Oracle Insurance Applications 9.7.1, 10.1.2, and 10.2.2; the Oracle Insurance Policy Administration J2EE and Oracle Insurance Rules Palette components in Oracle Insurance Applications 9.6.1, 9.7.1, 10.0.1, 10.1.2, 10.2.0, and 10.2.2; the Oracle Retail Integration Bus component in Oracle Retail Applications 15.0; the Oracle Retail Order Broker component in Oracle Retail Applications 5.1, 5.2, and 15.0; the Primavera Contract Management component in Oracle Primavera Products Suite 14.2; the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.2, 8.3, 8.4, 15.1, 15.2, and 16.1; the Oracle Financial Services Analytical Applications Infrastructure component in Oracle Financial Services Applications 8.0.0, 8.0.1, 8.0.2, and 8.0.3; the Oracle Commerce Guided Search / Oracle Commerce Experience Manager component in Oracle Commerce 3.1.1, 3.1.2, 11.0, 11.1, and 11.2; the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5; the Oracle Communications BRM - Elastic Charging Engine 11.2.0.0.0 and 11.3.0.0.0; the Oracle Enterprise Repository Enterprise Repository 12.1.3.0.0; the Oracle Financial Services Behavior Detection Platform 8.0.1 and 8.0.2; the Oracle Hyperion Essbase 12.2.1.1; the Oracle Tuxedo System and Applications Monitor (TSAM) 11.1.1.2.0, 11.1.1.2.1, 11.1.1.2.1, 12.1.1.1.0, 12.1.3.0.0, and 12.2.2.0.0; the Oracle Communications WebRTC Session Controller component of Oracle Communications Applications (subcomponent: Security (Spring)) 7.0, 7.1 and 7.2; the Oracle Endeca Information Discovery Integrator 3.2; the Converged Commerce component of Oracle Retail Applications 16.0.1; the Oracle Identity Manager 11.1.2.3.0; Oracle Enterprise Manager for MySQL Database 12.1.0.4; Oracle Retail Invoice Matching 12.0, 13.0, 13.1, 13.2, 14.0, and 14.1; Oracle Communications Performance Intelligence Center (PIC) Software Prior to 10.2.1 and the Oracle Knowledge component of Oracle Siebel CRM (subcomponent: AnswerFlow (Spring Framework)) version 8.5.1.0 - 8.5.1.7 and 8.6.0 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.","cvssScore":8.8,"cvssVersion":"3.0","cvssVector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssMetrics":[{"version":"3.0","score":8.8,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"},{"version":"2.0","score":9,"vector":"AV:N/AC:L/Au:S/C:C/I:C/A:C","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"resolved":"OUT-OF-SCOPE","published":"2016-07-21","lastModified":"2026-06-17","affectedProducts":[{"vendor":"oracle","product":"documaker","versionEnd":"\u003c=12.5"},{"vendor":"oracle","product":"enterprise manager ops center","version":"12.1.4"},{"vendor":"oracle","product":"enterprise manager ops center","version":"12.2.2"},{"vendor":"oracle","product":"enterprise manager ops center","version":"12.3.2"},{"vendor":"oracle","product":"health sciences information manager","version":"1.2.8.3"},{"vendor":"oracle","product":"health sciences information manager","version":"2.0.2.3"},{"vendor":"oracle","product":"health sciences information manager","version":"3.0.1.0"},{"vendor":"oracle","product":"healthcare master person index","version":"2.0.12"},{"vendor":"oracle","product":"healthcare master person index","version":"3.0.0"},{"vendor":"oracle","product":"healthcare master person index","version":"4.0.1"},{"vendor":"oracle","product":"insurance calculation engine","version":"9.7.1"},{"vendor":"oracle","product":"insurance calculation engine","version":"10.1.2"},{"vendor":"oracle","product":"insurance calculation engine","version":"10.2.2"},{"vendor":"oracle","product":"insurance policy administration j2ee","version":"9.6.1"},{"vendor":"oracle","product":"insurance policy administration j2ee","version":"9.7.1"},{"vendor":"oracle","product":"insurance policy administration j2ee","version":"10.0.1"},{"vendor":"oracle","product":"insurance policy administration j2ee","version":"10.1.2"},{"vendor":"oracle","product":"insurance policy administration j2ee","version":"10.2.0"},{"vendor":"oracle","product":"insurance policy administration j2ee","version":"10.2.2"},{"vendor":"oracle","product":"insurance rules palette","version":"9.6.1"}],"totalAffectedProducts":11,"references":[{"url":"http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html","source":"secalert_us@oracle.com"},{"url":"http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html","source":"secalert_us@oracle.com"},{"url":"http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html","source":"secalert_us@oracle.com"},{"url":"http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html","source":"secalert_us@oracle.com","tags":["Patch","Vendor Advisory"]},{"url":"http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html","source":"secalert_us@oracle.com"},{"url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html","source":"secalert_us@oracle.com"},{"url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html","source":"secalert_us@oracle.com"},{"url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html","source":"secalert_us@oracle.com"},{"url":"http://www.securityfocus.com/bid/91787","source":"secalert_us@oracle.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"http://www.securityfocus.com/bid/91869","source":"secalert_us@oracle.com"}],"reasoning":{"decidingSource":"h2-out-of-scope-with-cpe","decidingReason":"Manual classification marked OUT-OF-SCOPE but CVE matches known CPE products","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"matched","status":"OUT-OF-SCOPE","detail":"Found in legacy manual classifications","decisive":true}]},"oracleAdvisories":[{"advisory":"Oracle Critical Patch Update April 2019","releaseType":"CPU","quarter":"2019-Q2","url":"https://www.oracle.com/security-alerts/cpuapr2019.html","products":[{"product":"Oracle Siebel CRM","component":"AnswerFlow (Spring Framework)","affectedVersions":"High"}]},{"advisory":"Oracle Critical Patch Update January 2019","releaseType":"CPU","quarter":"2019-Q1","url":"https://www.oracle.com/security-alerts/cpujan2019.html","products":[{"product":"Oracle Communications Applications","component":"Security (Spring Framework)","affectedVersions":"prior to 7.0.0.1"},{"product":"Oracle Sun Systems Products Suite","component":"Software (Spring Framework)","affectedVersions":"8.4"}]},{"advisory":"Oracle Critical Patch Update October 2018","releaseType":"CPU","quarter":"2018-Q4","url":"https://www.oracle.com/security-alerts/cpuoct2018.html","products":[{"product":"Oracle Communications Applications","component":"Security (Spring Framework)","affectedVersions":"Prior to 10.2.1"}]},{"advisory":"Oracle Critical Patch Update April 2018","releaseType":"CPU","quarter":"2018-Q2","url":"https://www.oracle.com/security-alerts/cpuapr2018.html","products":[{"product":"Oracle Enterprise Manager Products Suite","component":"EM Plugin: General (Spring Framework)","affectedVersions":"12.1.0.4"},{"product":"Oracle Retail Applications","component":"Security (Spring Framework)","affectedVersions":"12.0, 13.0, 13.1, 13.2, 14.0, 14.1"}]},{"advisory":"Oracle Critical Patch Update January 2018","releaseType":"CPU","quarter":"2018-Q1","url":"https://www.oracle.com/security-alerts/cpujan2018.html","products":[{"product":"Oracle Fusion Middleware","component":"Security","affectedVersions":"11.1.2.3.0"},{"product":"Oracle Retail Applications","component":"Foundation Data","affectedVersions":"16.0.1"}]},{"advisory":"Oracle Critical Patch Update October 2017","releaseType":"CPU","quarter":"2017-Q4","url":"https://www.oracle.com/security-alerts/cpuoct2017.html","products":[{"product":"Oracle Communications Applications","component":"Security (Spring)","affectedVersions":"7.0, 7.1, 7.2"},{"product":"Oracle Fusion Middleware","component":"Security (Spring Framework)","affectedVersions":"3.2"}]},{"advisory":"Oracle Critical Patch Update July 2017","releaseType":"CPU","quarter":"2017-Q3","url":"https://www.oracle.com/security-alerts/cpujul2017.html","products":[{"product":"Oracle Communications Applications","component":"Elastic Charging Engine (Spring)","affectedVersions":"11.2.0.0.0, 11.3.0.0.0"},{"product":"Oracle Financial Services Applications","component":"Admin Tool (Spring)","affectedVersions":"8.0.1, 8.0.2"},{"product":"Oracle Fusion Middleware","component":"General (Spring)","affectedVersions":"11.1.1.2.0, 11.1.1.2.1, 11.1.1.2.2, 12.1.1.1.0, 12.1.3.0.0, 12.2.2.0.0"},{"product":"Oracle Fusion Middleware","component":"Security Subsystem","affectedVersions":"12.1.3.0.0"},{"product":"Oracle Hyperion","component":"Java Based Agent (Spring)"}]},{"advisory":"Oracle Critical Patch Update April 2017","releaseType":"CPU","quarter":"2017-Q2","url":"https://www.oracle.com/security-alerts/cpuapr2017.html","products":[{"product":"Oracle Communications Applications","component":"Security (Spring)","affectedVersions":"7.3.0, 7.2.4"},{"product":"Oracle Financial Services Applications","component":"Core (Spring Framework)","affectedVersions":"12.0.1, 12.0.2, 12.0.3, 12.1.0"},{"product":"Oracle Retail Applications","component":"Infrastructure","affectedVersions":"14.1.3"},{"product":"Oracle Retail Applications","component":"Mobile POS","affectedVersions":"14.1.3"},{"product":"Oracle Retail Applications","component":"Security","affectedVersions":"13.2, 14.0, 14.1"},{"product":"Oracle Retail Applications","component":"Security","affectedVersions":"14.1"},{"product":"Oracle Retail Applications","component":"Security","affectedVersions":"14.1"}]},{"advisory":"Oracle Critical Patch Update January 2017","releaseType":"CPU","quarter":"2017-Q1","url":"https://www.oracle.com/security-alerts/cpujan2017.html","products":[{"product":"Oracle Communications Applications","component":"Oracle Communications Network Intelligence","affectedVersions":"7.3.0.0"},{"product":"Oracle MySQL","component":"MySQL Enterprise Monitor","affectedVersions":"3.1.4.7895 and earlier, 3.2.1.1049 and earlier"},{"product":"Oracle Retail Applications","component":"Oracle Retail Assortment Planning","affectedVersions":"14.1, 15.0"},{"product":"Oracle Retail Applications","component":"Oracle Retail Predictive Application Server","affectedVersions":"13.1, 13.2, 13.3, 13.4, 14.0, 14.1, 15.0"}]},{"advisory":"Oracle Critical Patch Update October 2016","releaseType":"CPU","quarter":"2016-Q4","url":"https://www.oracle.com/security-alerts/cpuoct2016.html","products":[{"product":"Oracle Commerce","component":"Content Acquisition System","affectedVersions":"3.1.1, 3.1.2, 11.0, 11.1, 11.2"},{"product":"Oracle Commerce","component":"Tools and Frameworks","affectedVersions":"3.1.1, 3.1.2, 11.0, 11.1, 11.2"},{"product":"Oracle Financial Services Applications","component":"Inline Processing","affectedVersions":"8.0.0, 8.0.1, 8.0.2, 8.0.3"},{"product":"Oracle Supply Chain Products Suite","component":"Spring","affectedVersions":"9.3.4, 9.3.5"}]},{"advisory":"Oracle Critical Patch Update July 2016","releaseType":"CPU","quarter":"2016-Q3","url":"https://www.oracle.com/security-alerts/cpujul2016.html","products":[{"product":"Oracle Enterprise Manager Grid Control","component":"Framework","affectedVersions":"12.1.4, 12.2.2, 12.3.2"},{"product":"Oracle Health Sciences Applications","component":"Health Policy Monitor","affectedVersions":"1.2.8.3, 2.0.2.3, 3.0.1.0"},{"product":"Oracle Health Sciences Applications","component":"Internal operations","affectedVersions":"2.0.12, 3.0.0, 4.0.1"},{"product":"Oracle Insurance Applications","component":"Architecture","affectedVersions":"9.6.1, 9.7.1, 10.0.1, 10.1.2, 10.2.0, 10.2.2"},{"product":"Oracle Insurance Applications","component":"Architecture","affectedVersions":"9.6.1, 9.7.1, 10.0.1, 10.1.2, 10.2.0, 10.2.2"},{"product":"Oracle Insurance Applications","component":"Architecture","affectedVersions":"9.7.1, 10.1.2, 10.2.2"},{"product":"Oracle Insurance Applications","component":"Development tools","affectedVersions":"Prior to 12.5"},{"product":"Oracle Primavera Products Suite","component":"PCM web services","affectedVersions":"14.2"},{"product":"Oracle Primavera Products Suite","component":"Web access","affectedVersions":"8.2, 8.3, 8.4, 15.1, 15.2, 16.1"},{"product":"Oracle Retail Applications","component":"Install","affectedVersions":"15.0"},{"product":"Oracle Retail Applications","component":"Order Broker Foundation","affectedVersions":"5.1, 5.2, 15.0"}]}],"assessment":{"record":{"state":"active"},"protection":{"level":"none"},"action":{"state":"not-needed","type":"none"},"review":{"state":"human","basis":"manual-review"}},"h2Comments":"## Manual Classification Context\n\n\n**Labels:** ADMIN TOOL (SPRING), GENERAL (SPRING), MONITORING: GENERAL, ARCHITECTURE, TOOLS AND FRAMEWORKS, FRAMEWORK, UDP, INLINE PROCESSING, CONTENT ACQUISITION SYSTEM, DEVELOPMENT TOOLS, ELASTIC CHARGING ENGINE (SPRING), SECURITY (SPRING FRAMEWORK), OPERATIONS \u0026 MAINTENANCE, PCM WEB SERVICES, SECURITY (SPRING), SEE NOTE 1, HEALTH POLICY MONITOR, HTTP, JAVA BASED AGENT (SPRING), CORE (SPRING FRAMEWORK), MOBILE POS, INSTALL, SECURITY SUBSYSTEM, MULTIPLE, RPAS FUSION CLIENT, ORDER BROKER FOUNDATION, INFRASTRUCTURE, INTERNAL OPERATIONS, SPRING, FOUNDATION DATA, EM PLUGIN: GENERAL (SPRING FRAMEWORK), SOFTWARE (SPRING FRAMEWORK), WEB ACCESS, ANSWERFLOW (SPRING FRAMEWORK), TLS, SECURITY\n\n**Products:** ORACLE COMMUNICATIONS CONVERGED APPLICATION SERVER, ORACLE TUXEDO SYSTEM AND APPLICATIONS MONITOR, ORACLE COMMERCE, ORACLE RETAIL ASSORTMENT PLANNING, ORACLE RETAIL POINT-OF-SERVICE, ORACLE FINANCIAL SERVICES APPLICATIONS, ORACLE MYSQL, ORACLE INSURANCE POLICY ADMINISTRATION J2EE, ENTERPRISE MANAGER OPS CENTER, ORACLE FINANCIAL SERVICES ANALYTICAL APPLICATIONS INFRASTRUCTURE, TAPE LIBRARY ACSLS, ENTERPRISE MANAGER FOR MYSQL DATABASE, ORACLE INSURANCE APPLICATIONS, ORACLE FLEXCUBE PRIVATE BANKING, PRIMAVERA P6 ENTERPRISE PROJECT PORTFOLIO MANAGEMENT, PRIMAVERA CONTRACT MANAGEMENT, MYSQL ENTERPRISE MONITOR, ORACLE SIEBEL CRM, ORACLE FUSION MIDDLEWARE, ORACLE RETAIL INTEGRATION BUS, ORACLE COMMUNICATIONS NETWORK INTELLIGENCE, ORACLE DOCUMAKER, ORACLE SUN SYSTEMS PRODUCTS SUITE, HYPERION ESSBASE, ORACLE HYPERION, ORACLE SUPPLY CHAIN PRODUCTS SUITE, ORACLE PRIMAVERA PRODUCTS SUITE, ORACLE COMMUNICATIONS APPLICATIONS, ORACLE HEALTH SCIENCES APPLICATIONS, ORACLE ENTERPRISE MANAGER PRODUCTS SUITE, ORACLE COMMUNICATIONS WEBRTC SESSION CONTROLLER, ORACLE RETAIL PREDICTIVE APPLICATION SERVER, ORACLE IDENTITY MANAGER, ORACLE RETAIL RETURNS MANAGEMENT, ORACLE COMMUNICATIONS PERFORMANCE INTELLIGENCE CENTER (PIC) SOFTWARE, ORACLE ENTERPRISE MANAGER GRID CONTROL, ORACLE INSURANCE CALCULATION ENGINE, CONVERGED COMMERCE, ORACLE RETAIL APPLICATIONS, ORACLE RETAIL BACK OFFICE, ORACLE HEALTHCARE MASTER PERSON INDEX, ORACLE ENDECA INFORMATION DISCOVERY INTEGRATOR, ORACLE AGILE PLM, FINANCIAL SERVICES BEHAVIOR DETECTION PLATFORM, ORACLE COMMUNICATIONS BRM, ORACLE KNOWLEDGE, ORACLE HEALTH SCIENCES INFORMATION MANAGER, ORACLE COMMUNICATIONS NETWORK INTEGRITY, ORACLE ENTERPRISE REPOSITORY, ORACLE COMMERCE GUIDED SEARCH / ORACLE COMMERCE EXPERIENCE MANAGER, ORACLE RETAIL ORDER BROKER, ORACLE INSURANCE RULES PALETTE, ORACLE RETAIL INVOICE MATCHING","signals":{"hasPOC":false,"pocCount":0},"kev":{"inKEV":false},"epss":{"available":true,"score":0.05077,"percentile":0.91853},"ssvc":{"available":true,"exploitation":"none","automatable":"no","technicalImpact":"total"}}