| identity: Does this identifier describe a vulnerability at all? first match wins |
| 1 |
rejected |
no-match |
|
CVE Program withdrawal of this identifier |
| scope: Is the vulnerability ARMR's to address? first match wins |
| 2 |
armr-patch-file |
no-match |
|
An ARMR patch file on disk for this CVE |
| 3 |
armr-secure-rule-file |
no-match |
|
An ARMR security-rule template on disk for this CVE |
| 4 |
manual-classification |
no-match |
|
A researcher's recorded decision for this specific CVE |
| 5 |
manual classification |
no-match |
|
Manual classification of this CVE in the legacy dataset |
| 6 |
non-java-upstream |
no-match |
|
A root cause in non-Java code: an OS kernel, a C library, or a bundled runtime |
| 7 |
oracle-component |
no-match |
|
The defect being in a component of a tracked product the agent does not reach: JavaFX, the Java SE installer, the native WebLogic proxy plug-in. Oracle gives these no CPE of their own and names them only in the description. |
| 8 |
osv-maven |
no-match |
|
An OSV.dev record of this CVE affecting a package published to Maven Central |
| 9 |
cna-maven-package |
no-match |
|
An affected Maven artifact named by the CNA itself |
| 10 |
known-cpe-product |
matched |
Queued for review |
Matches known products: oracle/self-service_human_resources |
| 11 |
cna-cpe-product |
not-reached |
|
A CPE the CNA published naming a tracked product. Oracle publishes these on advisory day, months before NVD. |
| 12 |
oracle-advisory-family |
not-reached |
|
A tracked product family named in Oracle's own risk matrix. CPE cannot carry a suite name, only a module. |
| 13 |
non-deployable-product |
not-reached |
|
The only affected product being a sealed appliance image, where Java runs but no -javaagent can be attached |
| 14 |
unmatched-product |
not-reached |
|
No tracked product matched above, and none present at all |
| disposition: What do we do about one that is? cumulative: every rule gets a turn |
| 15 |
patch-hint |
no-match |
|
A reference pointing at the upstream fix: a commit, a PR, a Red Hat bug |
| 16 |
open-source-maven |
no-match |
|
The affected package being open source on Maven, so the fix can be read |
| 17 |
poc-derivable |
no-match |
|
An indexed exploit to reverse-engineer, where there is no source to read |
| 18 |
no-exploit decided it |
matched |
No fix identified |
No public exploits or POCs found in Exploit-DB, Nuclei templates, or GitHub POC repositories, and CISA's Vulnrichment assessment records no demonstrated exploit. No upstream fix reference or open-source Maven package was found either, so there is nothing to act on from either direction. |
| 19 |
secure-rule-match |
no-match |
|
A vulnerability class already blocked by an ARMR security rule |
| 20 |
below-action-threshold |
skipped |
|
Medium or Low severity, no KEV listing, no PoC clearing the evidence bar, no CISA verdict, no Oracle advisory |
| 21 |
no-exploit-published |
skipped |
|
A published working exploit for this candidate, not only a proof of concept, a forecast, or nothing at all |