[
  {"cve_id":"CVE-2026-84653","description":"Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to.","exploit_maturity":"No public exploit","published":"2026-09-02","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-59314","description":"Applications that build a Content-Disposition header value from untrusted input may be vulnerable to HTTP response splitting when the input is a malicious file name.\nSpring Framework 7.0.0 - 7.0.8\nSpring Framework 6.2.0 - 6.2.19\nSpring Framework 6.1.0 - 6.1.28\nSpring Framework 6.0.0 - 6.0.30\nSpring Framework 5.3.0 - 5.3.49\nSpring Framework 5.2.25.RELEASE and earlier","exploit_maturity":"No public exploit","published":"2026-08-27","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-73923","description":"Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).  Supported versions that are affected are 1.0.0-1.4.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-71146","description":"Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 1.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-71144","description":"Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data as well as  unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 3.0 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-71089","description":"Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client).   The supported version that is affected is 3.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-71083","description":"Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client).   The supported version that is affected is 3.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 1.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-71082","description":"Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client).   The supported version that is affected is 3.6. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 2.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-71081","description":"Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client).   The supported version that is affected is 3.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 1.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-71080","description":"Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client).   The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Agile PLM MCAD Connector accessible data as well as  unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-71072","description":"Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client).   The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile PLM MCAD Connector. CVSS 3.1 Base Score 3.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-70962","description":"Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration).   The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-70919","description":"Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 2.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-70853","description":"Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 3.3 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-70851","description":"Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 3.1 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-70850","description":"Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 3.0 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-70848","description":"Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-70785","description":"Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server).   The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-70776","description":"Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server).   The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 2.6 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-70711","description":"Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Calculation Manager executes to compromise Oracle Hyperion Calculation Manager.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data as well as  unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-70682","description":"Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-62606","description":"Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-62604","description":"Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Calculation Manager executes to compromise Oracle Hyperion Calculation Manager.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-62583","description":"Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration).   The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 3.0 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-62580","description":"Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Calculation Manager executes to compromise Oracle Hyperion Calculation Manager.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 2.6 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-62577","description":"Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration).   The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 3.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-62570","description":"Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration).   The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 3.0 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-62569","description":"Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration).   The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 3.4 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-62533","description":"Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-62532","description":"Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via SQL to compromise Oracle Hyperion Calculation Manager.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data as well as  unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-62529","description":"Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-62526","description":"Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Security).   The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 3.3 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-62511","description":"Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration).   The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data as well as  unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 3.0 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-62461","description":"Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-60853","description":"Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).  Supported versions that are affected are 3.0.0-3.2.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-60589","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security).  Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and  21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-08-18","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-48791","description":"sigstore-java is a sigstore java client for interacting with sigstore infrastructure. Version 2.0.0 erroneously removed verification of the integrated (Rekor entry) time) against the Fulcio certificate. Version 2.1.0 re-added this verification with enhancements that adhere to the Sigstore verification spec. The old sigstore-conformance test for this check was built incorrectly. This vulnerability impacts only users verifying bundles with `dev.sigstore:sigstore-java:2.0.0`. Older versions are not affected; it is fixed in `dev.sigstore:sigstore-java:2.1.0` A malicious actor may exploit this if they were able to access a users system and exfiltrate the temporary private key used during signing and then reuse an old fulcio certificate later without requiring direct access to the user's credentials. Users may protect themselves by re-verifying their artifacts using the newest sigstore-java or another current sigstore client. Transparency logs may also be audited for unauthorized signatures for a suspected reused identity.","exploit_maturity":"Proof of concept only","published":"2026-08-13","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-14779","description":"The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delete cascade logic, when triggered, fails to enforce organizational boundaries, leading to the removal of secrets associated with that type across all organizations.\n\nExploitation of this vulnerability can result in the unintended deletion of secrets across the entire deployment, potentially causing configuration failures, service interruptions, and a denial-of-service condition. This vulnerability requires delete permissions for the Secret Type Management REST API, which are by default only granted to administrators.","exploit_maturity":"No public exploit","published":"2026-08-06","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2025-12627","description":"The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated sessions. This allows an attacker who has obtained an access token for an impersonated user to leverage the refresh token grant to obtain new access tokens, extending their ability to act as the legitimate user.\n\nAn attacker who gains access to an impersonated user's access token can exploit this weakness to renew their authorization. This results in the continued ability to perform actions on behalf of the actual user, compromising log integrity and traceability by masking the true actor.","exploit_maturity":"No public exploit","published":"2026-08-06","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-70437","description":"Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison function when checking whether the provided and expected webhook bearer token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook bearer token.","exploit_maturity":"No public exploit","published":"2026-08-05","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-70430","description":"Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.","exploit_maturity":"No public exploit","published":"2026-08-05","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-18569","description":"A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component handles authentication and session management for applications. The issue occurs when an OIDC identity provider is configured to skip signature validation. In this specific setup, the system incorrectly accepts logout requests that have no cryptographic signature. An attacker who knows certain technical details about a user's session can use this flaw to force that user to be logged out, potentially disrupting their work.","exploit_maturity":"No public exploit","published":"2026-08-04","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-68980","description":"Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset Identifier. The framework performed authorized based on the supplied Parameter Context Identifier without verifying the requested Identifier against the stored Identifier. Apache NiFi installations that do not implement different levels of authorization across Parameter Contexts are not subject to this vulnerability, because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which verifies Parameter Context ownership of the requested Asset before deletion using the same strategy applied to Asset read operations.","exploit_maturity":"No public exploit","published":"2026-08-03","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-18206","description":"A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services. The issue occurs when a realm administrator uses a wildcard domain (like *.example.com) to restrict which hosts can register or update clients. Due to improper validation, the system accepts any hostname that ends with the specified domain suffix, even if it is not a legitimate subdomain. An attacker who can control the reverse DNS of their connection can bypass these host-based restrictions, potentially allowing unauthorized client modifications.","exploit_maturity":"No public exploit","published":"2026-07-31","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-62508","description":"Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Time and Labor. CVSS 3.1 Base Score 3.1 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-61303","description":"Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle EDI Gateway executes to compromise Oracle EDI Gateway.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle EDI Gateway accessible data. CVSS 3.1 Base Score 1.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-61214","description":"Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (UK).  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle HRMS (UK) accessible data. CVSS 3.1 Base Score 2.2 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-61187","description":"Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install).   The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 2.8 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-61104","description":"Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking).   The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Records.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of PeopleSoft Enterprise CS Student Records accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-61071","description":"Vulnerability in the PeopleSoft Enterprise FIN Engineering Argentina product of Oracle PeopleSoft (component: Engineering).   The supported version that is affected is 9.1. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Engineering Argentina.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN Engineering Argentina accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise FIN Engineering Argentina accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-61048","description":"Vulnerability in the Oracle Inventory Optimization product of Oracle E-Business Suite (component: User Interface).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Inventory Optimization.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Inventory Optimization. CVSS 3.1 Base Score 3.1 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-61047","description":"Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Production Scheduling executes to compromise Oracle Production Scheduling.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Production Scheduling accessible data. CVSS 3.1 Base Score 1.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-61036","description":"Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Norway Payroll).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (Norway).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle HRMS (Norway) accessible data as well as  unauthorized read access to a subset of Oracle HRMS (Norway) accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-61028","description":"Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Inventory Management executes to compromise Oracle Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Inventory Management. CVSS 3.1 Base Score 1.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-61015","description":"Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Time and Labor.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Time and Labor accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-60950","description":"Vulnerability in the Oracle HRMS (Ireland) product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (Ireland).  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle HRMS (Ireland) accessible data. CVSS 3.1 Base Score 2.2 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-60939","description":"Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Contracts.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Project Contracts accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-60937","description":"Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Labor Distribution.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Labor Distribution accessible data. CVSS 3.1 Base Score 3.1 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-60936","description":"Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Labor Distribution.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Labor Distribution. CVSS 3.1 Base Score 3.1 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-60930","description":"Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Public Sector Financials accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-60929","description":"Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Public Sector Financials accessible data. CVSS 3.1 Base Score 3.1 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-60922","description":"Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSupplier Portal.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle iSupplier Portal accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-60919","description":"Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupplier Portal.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle iSupplier Portal accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-60913","description":"Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Property Manager executes to compromise Oracle Property Manager.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Property Manager accessible data. CVSS 3.1 Base Score 1.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-60896","description":"Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Work in Process executes to compromise Oracle Work in Process.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Work in Process accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Work in Process. CVSS 3.1 Base Score 3.6 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-60891","description":"Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Work in Process executes to compromise Oracle Work in Process.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Work in Process accessible data. CVSS 3.1 Base Score 1.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-60847","description":"Vulnerability in the Oracle Order Entry product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Order Entry executes to compromise Oracle Order Entry.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Order Entry accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Order Entry. CVSS 3.1 Base Score 3.4 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-60804","description":"Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Definition).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle E-Business Intelligence.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle E-Business Intelligence accessible data. CVSS 3.1 Base Score 2.0 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-60628","description":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security).   The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the JD Edwards EnterpriseOne Tools executes to compromise JD Edwards EnterpriseOne Tools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as  unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-60596","description":"Vulnerability in the PeopleSoft Enterprise FIN eSettlements product of Oracle PeopleSoft (component: eSettlements).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN eSettlements executes to compromise PeopleSoft Enterprise FIN eSettlements.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of PeopleSoft Enterprise FIN eSettlements accessible data. CVSS 3.1 Base Score 2.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-60357","description":"Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Siebel Server Sync for Exchange).  Supported versions that are affected are 17.0-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel CRM Integration accessible data. CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-60354","description":"Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Data Visualization Tools).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle JDeveloper accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-60353","description":"Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle JDeveloper.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle JDeveloper accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-60352","description":"Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle JDeveloper accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-60347","description":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security).   The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where JD Edwards EnterpriseOne Tools executes to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 3.6 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-60346","description":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Interoperability Security).   The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-60339","description":"Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center).   The supported version that is affected is V16. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Manufacturing.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Project Manufacturing accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-60338","description":"Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center).   The supported version that is affected is V16. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Project Manufacturing executes to compromise Oracle Project Manufacturing.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Project Manufacturing accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Project Manufacturing. CVSS 3.1 Base Score 3.6 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-60318","description":"Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Patchset Assistant).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Data Integrator executes to compromise Oracle Data Integrator.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Data Integrator accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-60144","description":"Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Workflow executes to compromise Oracle Workflow.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Workflow accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Workflow. CVSS 3.1 Base Score 3.6 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-47032","description":"Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Redwood UI).  Supported versions that are affected are 24.4-26.3. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM End User.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM End User. CVSS 3.1 Base Score 2.6 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-47022","description":"Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security).   The supported version that is affected is 26.1.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where GoldenGate Stream Analytics executes to compromise GoldenGate Stream Analytics.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of GoldenGate Stream Analytics. CVSS 3.1 Base Score 3.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-47016","description":"Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Event Publish and Subscribe).  Supported versions that are affected are 17.0-26.4. Difficult to exploit vulnerability allows physical access to compromise Siebel CRM Integration.  While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Siebel CRM Integration accessible data. CVSS 3.1 Base Score 1.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-47011","description":"Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface).  Supported versions that are affected are 17.0-26.4. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 2.6 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-47010","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO).  Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and  21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-47000","description":"Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Security Framework).   The supported version that is affected is 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 3.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-21953","description":"Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile).   The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Retail Xstore Point of Service executes to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Retail Xstore Point of Service accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-46584","description":"Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Camel Mail Component.\n\nThe camel-mail producer (MailProducer.getSender) scanned the outgoing Exchange for message headers in the mail.smtp. / mail.smtps. namespace and, when any were present, built a per-message JavaMail sender with those values applied as JavaMail session properties, overriding the endpoint configuration. This namespace is Camel-internal - only MailProducer interprets it - and was not blocked by any HeaderFilterStrategy, so the values could originate from any inbound protocol (for example platform-http query parameters or request headers, or JMS / Kafka messages from untrusted producers) that feeds a route ending in an smtp / smtps producer without an intervening removeHeaders. The maximal impact is version-dependent: on releases before 4.19.0, setting mail.smtp.host redirects the SMTP connection to a server under the attacker's control, and because the producer then authenticates with the endpoint's configured username and password those credentials are transmitted to the attacker; on 4.19.0 and later the producer connects to the endpoint's configured host explicitly, so the reachable impact is limited to weakening transport security (for example mail.smtp.ssl.trust, mail.smtp.starttls.enable or mail.smtp.socks.host) and interception of the outgoing message rather than host redirect. Exploitation requires a route that channels untrusted input into the mail producer without stripping the namespace.\nThis issue affects Apache Camel: from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0.\n\nUsers are recommended to upgrade to version 4.21.0, which fixes the issue. If users are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.8. If users are on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.3. After upgrading, the per-message override is disabled by default; enable it only on trusted endpoints with useJavaMailSessionPropertiesFromHeaders=true. For deployments that cannot upgrade immediately, strip the namespace before the mail producer with removeHeaders('mail.smtp.*') and removeHeaders('mail.smtps.*') between any untrusted ingress and the smtp / smtps producer. Even with the opt-in enabled, route authors should still strip the namespace on any path that carries untrusted input.","exploit_maturity":"No public exploit","published":"2026-07-06","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-56130","description":"\"Remember me\" cookie age is not verified on the server. This potentially allows an attacker to intercept a valid cookie and reuse it indefinitely, even after the configured expiration time has passed.\nThis issue affects all Apache Shiro versions from 1.2.4 through 2.x, and 3.0.0-alpha-1, only when RememberMe functionality is enabled.\n\n\nUpgrade to version 3.0.0 or later, which fixes the issue.","exploit_maturity":"No public exploit","published":"2026-06-25","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-57288","description":"Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI) authentication path, allowing unauthenticated attackers to inject LDAP wildcard characters to enumerate directory entries and to authenticate as a matching user whose password they know without knowing their exact user name.","exploit_maturity":"No public exploit","published":"2026-06-24","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-44911","description":"Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submit proposed configuration properties. The proposed properties override current configuration, enabling users with read access to invoke predefined verification methods with alternative settings. Apache NiFi installations that do not implement different levels of authorization for viewing and modifying component configuration are not subject to this vulnerability. Upgrading to Apache NiFi 2.10.0 is the recommended mitigation, requiring write access to submit configuration verification requests.","exploit_maturity":"No public exploit","published":"2026-06-22","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-41000","description":"Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation timestamps, Timestamp elements, and certain SAML one-time-use semantics could be ineffective even when operators configured a replay cache on the interceptor.\n\nAffected versions:\nSpring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.","exploit_maturity":"No public exploit","published":"2026-06-11","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-11477","description":"A vulnerability was detected in hs-web hsweb-framework up to 5.0.1. This affects the function OAuth2Client of the file hsweb-authorization/hsweb-authorization-oauth2/src/main/java/org/hswebframework/web/oauth2/server/OAuth2Client.java of the component OAuth2 Client. The manipulation results in open redirect. The attack can be executed remotely. The exploit is now public and may be used. The patch is identified as c2882679a9125cea52678151af5ae213cbd52579. Applying a patch is advised to resolve this issue.","exploit_maturity":"Proof of concept only","published":"2026-06-08","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-11470","description":"A vulnerability has been found in hs-web hsweb-framework up to 5.0.1. The affected element is the function denied of the file hsweb-system/hsweb-system-file/src/main/java/org/hswebframework/web/file/FileUploadProperties.java of the component File Upload. The manipulation of the argument filename leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 8009845b577d8a2c4bbf4fdd8e8913799a714be6. It is suggested to install a patch to address this issue.","exploit_maturity":"Proof of concept only","published":"2026-06-08","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2026-9088","description":"A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured to be denied, leading to information disclosure.","exploit_maturity":"No public exploit","published":"2026-06-05","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-10532","description":"Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted.\n\nMore precisely, an attacker able to influence serialized data sent to \nSimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects.\n\n\nAlthough deserialization is heavily restricted by HardenedObjectInputStream and no \npractical way to achieve remote code execution or significant privilege \nescalation has been identified, this issue constitutes a bypass of the \nintended security restrictions.\n\n\n\nThis issue affects logback: through 1.5.33 inclusive.","exploit_maturity":"No public exploit","published":"2026-06-01","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2026-9828","description":"Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted.\n\nMore precisely, an attacker able to influence serialized data sent to \nSimpleSocketServer or SimpleSSLSocketServer can instantiate objects from\n classes in the java.lang and java.util packages that are not explicitly\n blocked.\n\nAlthough deserialization is heavily restricted by HardenedObjectInputStream and no \npractical way to achieve remote code execution or significant privilege \nescalation has been identified, this issue constitutes a bypass of the \nintended security restrictions.\n\n\n\nThis issue affects logback: through 1.5.32 inclusive.","exploit_maturity":"No public exploit","published":"2026-05-28","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2026-9497","description":"A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject of the component Fastjson AutoType REST API. This manipulation causes deserialization. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.","exploit_maturity":"No public exploit","published":"2026-05-25","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2026-9370","description":"A weakness has been identified in ulisesbocchio jasypt-spring-boot up to 3.0.5/4.0.4. Affected by this vulnerability is the function getSecretKeySaltGenerator of the file jasypt-spring-boot/src/main/java/com/ulisesbocchio/jasyptspringboot/encryptor/SimpleGCMConfig.java of the component Password Hash Handler. Executing a manipulation can lead to use of a one-way hash with a predictable salt. The attack can be launched remotely. The attack requires a high level of complexity. The exploitation appears to be difficult. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.","exploit_maturity":"Proof of concept only","published":"2026-05-24","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-7860","description":"A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes the full set of environment variables in build logs whenever the frontend build process exits with a non-zero status. Because the build environment may contain credentials supplied as secrets, any failed frontend build can expose those secrets in clear text in CI logs and archived build artifacts.\n\n\nUsers of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include:\n\nProduct version\nVaadin 23.0.0 - 23.6.9\nVaadin 24.0.0 - 24.9.16\nVaadin 24.10.0 - 24.10.3\nVaadin 25.0.0 - 25.0.10\nVaadin 25.1.0 - 25.1.4\n\nMitigation\nUpgrade to 23.6.10\nUpgrade to 24.9.17 or newer\nUpgrade to 24.10.4 or newer\nUpgrade to 25.0.11 or newer\nUpgrade to 25.1.5 or newer\n\nPlease note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 23, 24, or 25 version.\n\nArtifactsMaven coordinatesVulnerable versionsFixed versioncom.vaadin:flow-plugin-base23.0.0 - 23.6.10≥23.6.11com.vaadin:flow-plugin-base24.0.0 - 24.9.17≥24.9.18com.vaadin:flow-plugin-base24.10.0 - 24.10.3≥24.10.4com.vaadin:flow-plugin-base25.0.0 - 25.0.11≥25.0.12com.vaadin:flow-plugin-base25.1.0 - 25.1.4≥25.1.5com.vaadin:flow-maven-plugin23.0.0 - 23.6.10≥23.6.11com.vaadin:flow-maven-plugin24.0.0 - 24.9.17≥24.9.18com.vaadin:flow-maven-plugin24.10.0 - 24.10.3≥24.10.4com.vaadin:flow-maven-plugin25.0.0 - 25.0.11≥25.0.12com.vaadin:flow-maven-plugin25.1.0 - 25.1.4≥25.1.5com.vaadin:flow-gradle-plugin24.0.0 - 24.9.17≥24.9.18com.vaadin:flow-gradle-plugin24.10.0 - 24.10.3≥24.10.4com.vaadin:flow-gradle-plugin25.0.0 - 25.0.11≥25.0.12com.vaadin:flow-gradle-plugin25.1.0 - 25.1.4≥25.1.5","exploit_maturity":"No public exploit","published":"2026-05-19","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-42578","description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.","exploit_maturity":"Proof of concept only","published":"2026-05-13","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-44242","description":"Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Prior to 4.10.22, the bundleCache is keyed by (Locale, baseName) where the locale originates from the HTTP Accept-Language header. In applications that explicitly register a ResourceBundleMessageSource bean and serve HTML error responses, an unauthenticated attacker can exhaust heap memory by sending requests with large numbers of unique Accept-Language values, each causing a new entry in the unbounded bundleCache. This vulnerability is fixed in 4.10.22.","exploit_maturity":"Proof of concept only","published":"2026-05-12","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-43514","description":"Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.\nOlder unsupported versions may also be affected.\n\nUsers are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.","exploit_maturity":"No public exploit","published":"2026-05-12","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-22741","description":"Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.\n\n\nMore precisely, an application can be vulnerable when all the following are true:\n\n  *  the application is using Spring MVC or Spring WebFlux\n  *  the application is configuring the  resource chain support https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-config/static-resources.html#page-title  with caching enabled\n  *  the application adds support for encoded resources resolution\n  *  the resource cache must be empty when the attacker has access to the application\n\n\nWhen all the conditions above are met, the attacker can send malicious requests and poison the resource cache with resources using the wrong encoding. This can cause a denial of service by breaking the front-end application for clients.","exploit_maturity":"No public exploit","published":"2026-04-29","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-7303","description":"A security flaw has been discovered in Xuxueli xxl-job up to 3.3.2. Impacted is the function logDetailCat of the file xxl-job-admin/src/main/java/com/xxl/job/admin/controller/biz/JobLogController.java of the component Execution Log Handler. The manipulation of the argument logId results in improper control of resource identifiers. The attack may be performed from remote. This attack is characterized by high complexity. The exploitability is considered difficult. The exploit has been released to the public and may be used for attacks. Upgrading to version 3.4.0 is recommended to address this issue. The patch is identified as d24e4ccd6073cc75305e1d3b9c29bc8db7437e7a. It is suggested to upgrade the affected component.","exploit_maturity":"Proof of concept only","published":"2026-04-28","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-22746","description":"Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or #isAccountNonLocked user attributes, to enable, expire, or lock users, then DaoAuthenticationProvider's timing attack defense can be bypassed for users who are disabled, expired, or locked.This issue affects Spring Security: from 5.7.0 through 5.7.22, from 5.8.0 through 5.8.24, from 6.3.0 through 6.3.15, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.","exploit_maturity":"No public exploit","published":"2026-04-22","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-34268","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security).  Supported versions that are affected are Oracle Java SE: 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26; Oracle GraalVM for JDK: 17.0.18 and  21.0.10; Oracle GraalVM Enterprise Edition: 21.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition executes to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 2.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-04-21","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-22018","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).  Supported versions that are affected are Oracle Java SE: 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26; Oracle GraalVM for JDK: 17.0.18 and  21.0.10; Oracle GraalVM Enterprise Edition: 21.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2026-04-21","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-22014","description":"Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Workflow and Business Events).  Supported versions that are affected are 12.2.7-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle User Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle User Management accessible data as well as  unauthorized read access to a subset of Oracle User Management accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).","exploit_maturity":"No public exploit","published":"2026-04-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-22007","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security).  Supported versions that are affected are Oracle Java SE: 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26; Oracle GraalVM for JDK: 17.0.18 and  21.0.10; Oracle GraalVM Enterprise Edition: 21.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition executes to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 2.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2026-04-21","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-6125","description":"A security flaw has been discovered in Dromara warm-flow up to 1.8.4. Impacted is the function SpelHelper.parseExpression of the file /warm-flow/save-json of the component Workflow Definition Handler. The manipulation of the argument listenerPath/skipCondition/permissionFlag results in code injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.","exploit_maturity":"No public exploit","published":"2026-04-12","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-4874","description":"A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating the `client_session_host` parameter during refresh token requests. This occurs when a Keycloak client is configured to use the `backchannel.logout.url` with the `application.session.host` placeholder. Successful exploitation allows the attacker to make HTTP requests from the Keycloak server’s network context, potentially probing internal networks or internal APIs, leading to information disclosure.","exploit_maturity":"No public exploit","published":"2026-03-26","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-32642","description":"Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an application using the OpenWire protocol attempts to create a non-durable JMS topic subscription on an address that doesn't exist with an authenticated user which has the \"createDurableQueue\" permission but does not have the \"createAddress\" permission and address auto-creation is disabled. In this circumstance, a temporary address will be created whereas the attempt to create the non-durable subscription should instead fail since the user is not authorized to create the corresponding address. When the OpenWire connection is closed the address is removed.\n\nThis issue affects Apache Artemis: from 2.50.0 through 2.52.0; Apache ActiveMQ Artemis: from 2.0.0 through 2.44.0.\n\nUsers are recommended to upgrade to version 2.53.0, which fixes the issue.","exploit_maturity":"No public exploit","published":"2026-03-24","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-4633","description":"A flaw was found in Keycloak. A remote attacker can exploit differential error messages during the identity-first login flow when Organizations are enabled. This vulnerability allows an attacker to determine the existence of users, leading to information disclosure through user enumeration.","exploit_maturity":"No public exploit","published":"2026-03-23","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-22735","description":"Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.","exploit_maturity":"No public exploit","published":"2026-03-20","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-2366","description":"A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim's unique identifier (UUID) and the Organizations feature is enabled.","exploit_maturity":"No public exploit","published":"2026-03-12","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-3911","description":"A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized information disclosure could expose sensitive user data.","exploit_maturity":"No public exploit","published":"2026-03-11","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-1524","description":"An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following conditions:\n\n\nIf a neo4j admin configures two or more OIDC providers AND configures one or more of them to be an authorization provider AND configures one or more of them to be authentication-only, then those that are authentication-only will also provide authorization. This edgecase becomes a security problem only if the authentication-only provider contains groups which have higher privileges than provided by the intended (configured) authorization provider.  \n\nWhen using multiple plugins for authentication and authorisation, prior to the fix the issue could lead to a plugin configured to provide only authentication or authorisation capabilities erroneously providing both capabilities. \n\nWe recommend upgrading to versions 2026.02 (or 5.26.22) where the issue is fixed.","exploit_maturity":"No public exploit","published":"2026-03-11","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-1497","description":"Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22 can lead to the following scenario: \nan admin that intends to give a user an access to a remote database constituent \"namespace.name\" will inadvertently grant access to any local database or remote alias called \"name\". If such database or alias doesn't exist when the command is run, the privileges will apply if it's created in the future.","exploit_maturity":"No public exploit","published":"2026-03-11","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-1471","description":"Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticated users inheriting the context of the first user who authenticated after restart. The issue is limited to certain non-default configurations of SSO (UserInfo endpoint). \nWe recommend upgrading to versions 2026.01.4 (or 5.26.22) where the issue is fixed.","exploit_maturity":"No public exploit","published":"2026-03-11","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2026-2741","description":"Specially crafted ZIP archives can escape the intended extraction directory during Node.js download and extraction in Vaadin 14.2.0 through 14.14.0, 15.0.0 through 23.6.6, 24.0.0 through 24.9.8, and 25.0.0 through 25.0.2. \n\nVaadin’s build process can automatically download and extract Node.js if it is not installed locally. If an attacker can intercept or control this download via DNS hijacking, a MITM attack, a compromised mirror, or a supply chain attack, they can serve a malicious archive containing path traversal sequences that write files outside the intended extraction directory.\n\n\nUsers of affected versions should use a globally preinstalled Node.js version compatible with their Vaadin version, or upgrade as follows: 14.2.0-14.14.0 to 14.14.1, 15.0.0-23.6.6 to 23.6.7, 24.0.0-24.9.8 to 24.9.9, and 25.0.0-25.0.2 to 25.0.3 or newer.\n\nPlease note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 14, 23, 24, 25 version.","exploit_maturity":"No public exploit","published":"2026-03-10","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2026-3293","description":"A weakness has been identified in snowflakedb snowflake-jdbc up to 4.0.1. Impacted is the function SdkProxyRoutePlanner of the file src/main/java/net/snowflake/client/internal/core/SdkProxyRoutePlanner.java of the component JDBC URL Handler. Executing a manipulation of the argument nonProxyHosts can lead to inefficient regular expression complexity. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. This patch is called 5fb0a8a318a2ed87f4022a1f56e742424ba94052. A patch should be applied to remediate this issue.","exploit_maturity":"Proof of concept only","published":"2026-02-27","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-3270","description":"A vulnerability has been found in psi-probe PSI Probe up to 5.3.0. This affects the function lookup of the file psi-probe-core/src/main/java/psiprobe/tools/Whois.java of the component Whois. The manipulation leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","exploit_maturity":"Proof of concept only","published":"2026-02-27","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-3269","description":"A flaw has been found in psi-probe PSI Probe up to 5.3.0. The impacted element is the function handleRequestInternal of the file psi-probe-core/src/main/java/psiprobe/controllers/sessions/ExpireSessionsController.java of the component Session Handler. Executing a manipulation can lead to denial of service. The attack can be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","exploit_maturity":"Proof of concept only","published":"2026-02-27","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-12150","description":"A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: \"none\", even when the realm is configured to require direct attestation. This can lead to weakened authentication integrity and unauthorized authenticator registration.","exploit_maturity":"No public exploit","published":"2026-02-27","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-2733","description":"A flaw was identified in the Docker v2 authentication endpoint of Keycloak, where tokens continue to be issued even after a Docker registry client has been administratively disabled. This means that turning the client “Enabled” setting to OFF does not fully prevent access. As a result, previously valid credentials can still be used to obtain authentication tokens. This weakens administrative controls and could allow unintended access to container registry resources.","exploit_maturity":"No public exploit","published":"2026-02-19","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-2666","description":"A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTemplate.do of the component Template Archive Handler. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be launched remotely. The exploit has been published and may be used.","exploit_maturity":"Proof of concept only","published":"2026-02-18","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-23901","description":"Observable Timing Discrepancy vulnerability in Apache Shiro.\n\nThis issue affects Apache Shiro: from 1.*, 2.* before 2.0.7.\n\nUsers are recommended to upgrade to version 2.0.7 or later, which fixes the issue.\n\nPrior to Shiro 2.0.7, code paths for non-existent vs. existing users are different enough,\nthat a brute-force attack may be able to tell, by timing the requests only, determine if\nthe request failed because of a non-existent user vs. wrong password.\n\nThe most likely attack vector is a local attack only.\nShiro security model  https://shiro.apache.org/security-model.html#username_enumeration  discusses this as well.\n\nTypically, brute force attack can be mitigated at the infrastructure level.","exploit_maturity":"No public exploit","published":"2026-02-10","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-1337","description":"Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML. There is no security impact on Neo4j products, but this advisory is released as a precaution to treat the logs as plain text if using versions prior to 2026.01.\n\nProof of concept exploit:  https://github.com/JoakimBulow/CVE-2026-1337","exploit_maturity":"Proof of concept only","published":"2026-02-06","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-13881","description":"A flaw was found in Keycloak Admin API. This vulnerability allows an administrator with limited privileges to retrieve sensitive custom attributes via the /unmanagedAttributes endpoint, bypassing User Profile visibility settings.","exploit_maturity":"No public exploit","published":"2026-02-02","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-24656","description":"Deserialization of Untrusted Data vulnerability in Apache Karaf Decanter.\n\n\nThe Decanter log socket collector exposes the port 4560, without authentication. If the collector exposes allowed classes property, this configuration can be bypassed.\nIt means that the log socket collector is vulnerable to deserialization of untrusted data, eventually causing DoS.\n\n\nNB: Decanter log socket collector is not installed by default. Users who have not installed Decanter log socket are not impacted by this issue.\n\nThis issue affects Apache Karaf Decanter before 2.12.0.\n\nUsers are recommended to upgrade to version 2.12.0, which fixes the issue.","exploit_maturity":"No public exploit","published":"2026-01-26","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2026-1190","description":"A flaw was found in Keycloak's SAML brokering functionality. When Keycloak is configured as a client in a Security Assertion Markup Language (SAML) setup, it fails to validate the `NotOnOrAfter` timestamp within the `SubjectConfirmationData`. This allows an attacker to delay the expiration of SAML responses, potentially extending the time a response is considered valid and leading to unexpected session durations or resource consumption.","exploit_maturity":"No public exploit","published":"2026-01-26","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-1225","description":"ACE vulnerability in configuration file processing  by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file.\n\n\n\n\nThe instantiation of a potentially malicious Java class requires that said class is present on the user's class-path. In addition, the attacker must  have write access to a \nconfiguration file. However, after successful instantiation, the instance is very likely to be discarded with no further ado.","exploit_maturity":"No public exploit","published":"2026-01-22","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-1035","description":"A flaw was found in the Keycloak server during refresh token processing, specifically in the TokenManager class responsible for enforcing refresh token reuse policies. When strict refresh token rotation is enabled, the validation and update of refresh token usage are not performed atomically. This allows concurrent refresh requests to bypass single-use enforcement and issue multiple access tokens from the same refresh token. As a result, Keycloak’s refresh token rotation hardening can be undermined.","exploit_maturity":"No public exploit","published":"2026-01-21","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-14083","description":"A flaw was found in the Keycloak Admin REST API. This vulnerability allows the exposure of backend schema and rules, potentially leading to targeted attacks or privilege escalation via improper access control.","exploit_maturity":"No public exploit","published":"2026-01-21","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-0858","description":"Versions of the package net.sourceforge.plantuml:plantuml before 1.2026.0 are vulnerable to Stored XSS due to insufficient sanitization of interactive attributes in GraphViz diagrams. As a result, a crafted PlantUML diagram can inject malicious JavaScript into generated SVG output, leading to arbitrary script execution in the context of applications that render the SVG.","exploit_maturity":"No public exploit","published":"2026-01-16","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2026-0976","description":"A flaw was found in Keycloak. This improper input validation vulnerability occurs because Keycloak accepts RFC-compliant matrix parameters in URL path segments, while common reverse proxy configurations may ignore or mishandle them. A remote attacker can craft requests to mask path segments, potentially bypassing proxy-level path filtering. This could expose administrative or sensitive endpoints that operators believe are not externally reachable.","exploit_maturity":"No public exploit","published":"2026-01-15","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-14518","description":"A vulnerability was identified in PowerJob up to 5.1.2. This vulnerability affects the function checkConnectivity of the file src/main/java/tech/powerjob/common/utils/net/PingPongUtils.java of the component Network Request Handler. The manipulation of the argument targetIp/targetPort leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.","exploit_maturity":"Proof of concept only","published":"2025-12-11","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-67639","description":"A cross-site request forgery (CSRF) vulnerability in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers to trick users into logging in to the attacker's account.","exploit_maturity":"No public exploit","published":"2025-12-10","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-14082","description":"A flaw was found in Keycloak Admin REST (Representational State Transfer) API. This vulnerability allows information disclosure of sensitive role metadata via insufficient authorization checks on the /admin/realms/{realm}/roles endpoint.","exploit_maturity":"No public exploit","published":"2025-12-10","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-13805","description":"A weakness has been identified in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This affects the function getInputStream of the file nutzcloud/nutzcloud-literpc/src/main/java/org/nutz/boot/starter/literpc/impl/endpoint/http/HttpServletRpcEndpoint.java of the component LiteRpc-Serializer. Executing a manipulation can lead to deserialization. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is reported as difficult. The exploit has been made available to the public and could be used for attacks.","exploit_maturity":"Proof of concept only","published":"2025-12-01","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2025-13804","description":"A security flaw has been discovered in nutzam NutzBoot up to 2.6.0-SNAPSHOT. The impacted element is an unknown function of the file nutzboot-demo/nutzboot-demo-simple/nutzboot-demo-simple-web3j/src/main/java/io/nutz/demo/simple/module/EthModule.java of the component Ethereum Wallet Handler. Performing a manipulation results in information disclosure. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.","exploit_maturity":"Proof of concept only","published":"2025-12-01","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-66372","description":"Mustang before 2.16.3 allows exfiltrating files via XXE attacks.","exploit_maturity":"No public exploit","published":"2025-11-28","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2025-13435","description":"A security vulnerability has been detected in Dreampie Resty up to 1.3.1.SNAPSHOT. This affects the function Request of the file /resty-httpclient/src/main/java/cn/dreampie/client/HttpClient.java of the component HttpClient Module. Such manipulation of the argument filename leads to path traversal. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is reported as difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","exploit_maturity":"Proof of concept only","published":"2025-11-20","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2025-10939","description":"A flaw was found in Keycloak. The Keycloak guides recommend to not expose /admin path to the outside in case the installation is using a proxy. The issue occurs at least via ha-proxy, as it can be tricked to using relative/non-normalized paths to access the /admin application path relative to /realms which is expected to be exposed.","exploit_maturity":"No public exploit","published":"2025-10-28","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-62255","description":"Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page in Liferay Portal 7.4.0 through 7.4.3.101, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92, and older unsupported versions  allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an attachment's filename.","exploit_maturity":"No public exploit","published":"2025-10-23","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-62247","description":"Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 allows instance users to read and select unauthorized Blueprints through the Collection Providers across instances.","exploit_maturity":"No public exploit","published":"2025-10-22","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-11966","description":"In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], when \"directory listing\" is enabled, file and directory names are inserted into generated HTML without proper escaping in the href, title, and link attributes. An attacker who can create or rename files or directories within a served path can craft filenames containing malicious script or HTML content, leading to stored cross-site scripting (XSS) that executes in the context of users viewing the affected directory listing.","exploit_maturity":"Proof of concept only","published":"2025-10-22","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-43798","description":"Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35 allows a time-based one-time password (TOTP) to be used multiple times during the validity period, which allows attackers with access to a user’s TOTP to authenticate as the user.","exploit_maturity":"No public exploit","published":"2025-09-15","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-43792","description":"Remote staging in Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not properly obtain the remote address of the live site from the database which, which allows remote authenticated users to exfiltrate data to an attacker controlled server (i.e., a fake “live site”) via the _com_liferay_exportimport_web_portlet_ExportImportPortlet_remoteAddress and _com_liferay_exportimport_web_portlet_ExportImportPortlet_remotePort parameters. To successfully exploit this vulnerability, an attacker must also successfully obtain the staging server’s shared secret and add the attacker controlled server to the staging server’s whitelist.","exploit_maturity":"No public exploit","published":"2025-09-15","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-43789","description":"JSON Web Services in Liferay Portal 7.4.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.9, 7.4 GA through update 92 published to OSGi are registered and invoked directly as classes which allows Service Access Policies get executed.","exploit_maturity":"No public exploit","published":"2025-09-12","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-58056","description":"Netty is an asynchronous event-driven network application framework for development of maintainable high performance protocol servers and clients. In versions 4.1.124.Final, and 4.2.0.Alpha3 through 4.2.4.Final, Netty incorrectly accepts standalone newline characters (LF) as a chunk-size line terminator, regardless of a preceding carriage return (CR), instead of requiring CRLF per HTTP/1.1 standards. When combined with reverse proxies that parse LF differently (treating it as part of the chunk extension), attackers can craft requests that the proxy sees as one request but Netty processes as two, enabling request smuggling attacks. This is fixed in versions 4.1.125.Final and 4.2.5.Final.","exploit_maturity":"No public exploit","published":"2025-09-03","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-55202","description":"Opencast is a free, open-source platform to support the management of educational audio and video content. In version 18.0 and versions before 17.7, the protections against path traversal attacks in the UI config module are insufficient, still partially allowing for attacks in very specific cases. The path is checked without checking for the file separator. This could allow attackers access to files within another folder which starts with the same path. This issue has been fixed in versions 17.7 and 18.1. To mitigate this issue, check for folders that start with the same path as the ui-config folder.","exploit_maturity":"No public exploit","published":"2025-08-29","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2025-9264","description":"A vulnerability was found in Xuxueli xxl-job up to 3.1.1. Affected by this issue is the function remove of the file /src/main/java/com/xxl/job/admin/controller/JobInfoController.java of the component Jobs Handler. Performing manipulation of the argument ID results in improper control of resource identifiers. Remote exploitation of the attack is possible. The exploit has been made public and could be used.","exploit_maturity":"Proof of concept only","published":"2025-08-21","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-43753","description":"A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.32 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.7, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.16 and 7.4 update 32 through update 92 allows an remote authenticated user to inject JavaScript into the embedded message field from the form container.","exploit_maturity":"No public exploit","published":"2025-08-21","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-9263","description":"A vulnerability has been found in Xuxueli xxl-job up to 3.1.1. Affected by this vulnerability is the function getJobsByGroup of the file /src/main/java/com/xxl/job/admin/controller/JobLogController.java. Such manipulation of the argument jobGroup leads to improper control of resource identifiers. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.","exploit_maturity":"Proof of concept only","published":"2025-08-20","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-43733","description":"A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.7 allows a remote authenticated attacker to inject JavaScript code via the content page's name field. This malicious payload is then reflected and executed within the user's browser when viewing the \"document View Usages\" page.","exploit_maturity":"No public exploit","published":"2025-08-18","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-3639","description":"Liferay Portal 7.3.0 through 7.4.3.132, and Liferay DXP 2025.Q1 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 GA through update 92 and 7.3 GA through update 36 allows unauthenticated users with valid credentials to bypass the login process by changing the POST method to GET, once the site has MFA enabled.","exploit_maturity":"No public exploit","published":"2025-08-18","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-9092","description":"Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java - BC-FJA 2.1.0 bc-fips (API modules) allows Excessive Allocation. This vulnerability is associated with program files org.Bouncycastle.Crypto.Fips.NativeLoader.\n\nThis issue affects Bouncy Castle for Java - BC-FJA 2.1.0: from BC-FJA 2.1.0 through 2.1.0.","exploit_maturity":"No public exploit","published":"2025-08-16","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-4599","description":"The fragment preview functionality in Liferay Portal 7.4.3.61 through 7.4.3.132, and Liferay DXP 2024.Q4.1 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.13 and 7.4 update 61 through update 92 was found to be vulnerable to postMessage-based XSS because it allows a remote non-authenticated attacker to inject JavaScript into the fragment portlet URL.","exploit_maturity":"No public exploit","published":"2025-08-04","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2025-7789","description":"A vulnerability was found in Xuxueli xxl-job up to 3.1.1 and classified as problematic. Affected by this issue is the function makeToken of the file src/main/java/com/xxl/job/admin/controller/IndexController.java of the component Token Generation. The manipulation leads to password hash with insufficient computational effort. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.","exploit_maturity":"Proof of concept only","published":"2025-07-18","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-7787","description":"A vulnerability, which was classified as critical, was found in Xuxueli xxl-job up to 3.1.1. Affected is the function httpJobHandler of the file src\\main\\java\\com\\xxl\\job\\executor\\service\\jobhandler\\SampleXxlJob.java. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.","exploit_maturity":"Proof of concept only","published":"2025-07-18","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-50065","description":"Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Native Image).   The supported version that is affected is Oracle GraalVM for JDK: 24.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM for JDK.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GraalVM for JDK. CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2025-07-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2025-6701","description":"A vulnerability, which was classified as problematic, has been found in Xuxueli xxl-sso 1.1.0. This issue affects some unknown processing of the file /xxl-sso-server/doLogin. The manipulation of the argument redirect_url leads to open redirect. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","exploit_maturity":"Proof of concept only","published":"2025-06-26","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-6700","description":"A vulnerability classified as problematic was found in Xuxueli xxl-sso 1.1.0. This vulnerability affects unknown code of the file /xxl-sso-server/login. The manipulation of the argument errorMsg leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","exploit_maturity":"Proof of concept only","published":"2025-06-26","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-5416","description":"A vulnerability has been identified in Keycloak that could lead to unauthorized information disclosure. While it requires an already authenticated user, the /admin/serverinfo endpoint can inadvertently provide sensitive environment information.","exploit_maturity":"No public exploit","published":"2025-06-20","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-48059","description":"PowSyBl (Power System Blocks) is a framework to build power system oriented software. In com.powsybl:powsybl-iidm-criteria versions 6.3.0 to before 6.7.2 and com.powsybl:powsybl-contingency-api versions 5.0.0 to before 6.3.0, there is a a potential polynomial Regular Expression Denial of Service (ReDoS) vulnerability in the RegexCriterion class. This class compiles and evaluates an unvalidated, user-supplied regular expression against the identifier of an Identifiable object via Pattern.compile(regex).matcher(id).find(). If successfully exploited, a malicious actor can cause significant CPU exhaustion through repeated or recursive filter(...) calls — especially if performed over large network models or filtering operations. This issue has been patched in com.powsybl:powsybl-iidm-criteria 6.7.2.","exploit_maturity":"No public exploit","published":"2025-06-20","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-47293","description":"PowSyBl (Power System Blocks) is a framework to build power system oriented software. Prior to version 6.7.2, in certain places, powsybl-core XML parsing is vulnerable to an XML external entity (XXE) attack and to a server-side request forgery (SSRF) attack. This allows an attacker to elevate their privileges to read files that they do not have permissions to, including sensitive files on the system. The vulnerable class is com.powsybl.commons.xml.XmlReader which is considered to be untrusted in use cases where untrusted users can submit their XML to the vulnerable methods. This can be a multi-tenant application that hosts many different users perhaps with different privilege levels. This issue has been patched in com.powsybl:powsybl-commons: 6.7.2.","exploit_maturity":"No public exploit","published":"2025-06-19","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2025-48382","description":"Fess is a deployable Enterprise Search Server. Prior to version 14.19.2, the createTempFile() method in org.codelibs.fess.helper.SystemHelper creates temporary files without explicitly setting restrictive permissions. This could lead to potential information disclosure, allowing unauthorized local users to access sensitive data contained in these files. This issue primarily affects environments where Fess is deployed in a shared or multi-user context. Typical single-user or isolated deployments have minimal or negligible practical impact. This issue has been patched in version 14.19.2. A workaround for this issue involves ensuring local access to the environment running Fess is restricted to trusted users only.","exploit_maturity":"No public exploit","published":"2025-05-27","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-22233","description":"CVE-2024-38820 ensured Locale-independent, lowercase conversion for both the configured disallowedFields patterns and for request parameter names. However, there are still cases where it is possible to bypass the disallowedFields checks.\n\nAffected Spring Products and Versions\n\nSpring Framework:\n  *  6.2.0 - 6.2.6\n\n  *  6.1.0 - 6.1.19\n\n  *  6.0.0 - 6.0.27\n\n  *  5.3.0 - 5.3.42\n  *  Older, unsupported versions are also affected\n\n\n\nMitigation\n\nUsers of affected versions should upgrade to the corresponding fixed version.\n\nAffected version(s)Fix Version Availability 6.2.x\n 6.2.7\nOSS6.1.x\n 6.1.20\nOSS6.0.x\n 6.0.28\n Commercial https://enterprise.spring.io/ 5.3.x\n 5.3.43\n Commercial https://enterprise.spring.io/ \nNo further mitigation steps are necessary.\n\n\nGenerally, we recommend using a dedicated model object with properties only for data binding, or using constructor binding since constructor arguments explicitly declare what to bind together with turning off setter binding through the declarativeBinding flag. See the Model Design section in the reference documentation.\n\nFor setting binding, prefer the use of allowedFields (an explicit list) over disallowedFields.\n\nCredit\n\nThis issue was responsibly reported by the TERASOLUNA Framework Development Team from NTT DATA Group Corporation.","exploit_maturity":"No public exploit","published":"2025-05-16","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-32971","description":"XWiki is a generic wiki platform. In versions starting from 4.5.1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to before 16.8.0-rc-1, the Solr script service doesn't take dropped programming rights into account. The Solr script service that is accessible in XWiki's scripting API normally requires programming rights to be called. Due to using the wrong API for checking rights, it doesn't take the fact into account that programming rights might have been dropped by calling `$xcontext.dropPermissions()`. If some code relies on this for the safety of executing Velocity code with the wrong author context, this could allow a user with script rights to either cause a high load by indexing documents or to temporarily remove documents from the search index. This issue has been patched in versions 15.10.13, 16.4.4, and 16.8.0-rc-1.","exploit_maturity":"Proof of concept only","published":"2025-04-30","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-3984","description":"A vulnerability was found in Apereo CAS 5.2.6 and classified as critical. Affected by this issue is the function saveService of the file cas-5.2.6\\webapp-mgmt\\cas-management-webapp-support\\src\\main\\java\\org\\apereo\\cas\\mgmt\\services\\web\\RegisteredServiceSimpleFormController.java of the component Groovy Code Handler. The manipulation leads to code injection. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","exploit_maturity":"No public exploit","published":"2025-04-27","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-30731","description":"Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Configuration).  Supported versions that are affected are 12.2.3-12.2.14. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Applications Technology Stack executes to compromise Oracle Applications Technology Stack.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Applications Technology Stack accessible data as well as  unauthorized read access to a subset of Oracle Applications Technology Stack accessible data. CVSS 3.1 Base Score 3.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N).","exploit_maturity":"No public exploit","published":"2025-04-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2025-27427","description":"A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type supported by that address even if said user doesn't have the createAddress permission for that particular address. When combined with the send permission and automatic queue creation a user could successfully send a message with a routing-type not supported by the address when that message should actually be rejected on the basis that the user doesn't have permission to change the routing-type of the address.\n\nThis issue affects Apache ActiveMQ Artemis from 2.0.0 through 2.39.0.\n\nUsers are recommended to upgrade to version 2.40.0 which fixes the issue.","exploit_maturity":"No public exploit","published":"2025-04-01","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-30197","description":"Jenkins Zoho QEngine Plugin 1.0.29.vfa_cc23396502 and earlier does not mask the QEngine API Key form field, increasing the potential for attackers to observe and capture it.","exploit_maturity":"No public exploit","published":"2025-03-19","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-27496","description":"Snowflake, a platform for using artificial intelligence in the context of cloud computing, has a vulnerability in the Snowflake JDBC driver (\"Driver\") in versions 3.0.13 through 3.23.0 of the driver. When the logging level was set to DEBUG, the Driver would log locally the client-side encryption master key of the target stage during the execution of GET/PUT commands. This key by itself does not grant access to any sensitive data without additional access authorizations,  and is not logged server-side by Snowflake. Snowflake fixed the issue in version 3.23.1.","exploit_maturity":"No public exploit","published":"2025-03-13","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2024-4028","description":"A vulnerability was found in Keycloak. This issue may allow a privileged attacker to use a malicious payload as the permission while creating items (Resource and Permissions) from the admin console, leading to a stored cross-site scripting (XSS) attack.","exploit_maturity":"No public exploit","published":"2025-02-18","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2025-0148","description":"Missing password field masking in the Zoom Jenkins Marketplace plugin before version 1.6 may allow an unauthenticated user to conduct a disclosure of information via adjacent network access.","exploit_maturity":"No public exploit","published":"2025-02-03","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2024-56512","description":"Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenced Parameter Providers, when creating new Process Groups.\n\nCreating a new Process Group can include binding to a Parameter Context, but in cases where the Process Group did not reference any Parameter values, the framework did not check user authorization for the bound Parameter Context. Missing authorization for a bound Parameter Context enabled clients to download non-sensitive Parameter values after creating the Process Group.\n\nCreating a new Process Group can also include referencing existing Controller Services or Parameter Providers. The framework did not check user authorization for referenced Controller Services or Parameter Providers, enabling clients to create Process Groups and use these components that were otherwise unauthorized.\n\nThis vulnerability is limited in scope to authenticated users authorized to create Process Groups. The scope is further limited to deployments with component-based authorization policies. Upgrading to Apache NiFi 2.1.0 is the recommended mitigation, which includes authorization checking for Parameter and Controller Service references on Process Group creation.","exploit_maturity":"Working exploit published","published":"2024-12-28","resolved":"MITIGATION-CANDIDATE","severity":"Low"},
  {"cve_id":"CVE-2024-12801","description":"Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 0.1 to 1.3.14 and 1.4.0 to 1.5.12  on the Java platform, allows an attacker to \nforge requests by compromising logback configuration files in XML.\n\n\n\nThe attacks involves the modification of DOCTYPE declaration in  XML configuration files.","exploit_maturity":"No public exploit","published":"2024-12-19","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2024-54140","description":"sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient verification for a situation where a bundle provides a invalid signature for a checkpoint. This bug impacts clients using any variation of KeylessVerifier.verify(). Currently checkpoints are only used to ensure the root hash of an inclusion proof was provided by the log in question. Failing to validate that means a bundle may provide an inclusion proof that doesn't actually correspond to the log in question. This may eventually lead a monitor/witness being unable to detect when a compromised logs are providing different views of themselves to different clients. There are other mechanisms right now that mitigate this, such as the signed entry timestamp. Sigstore-java currently requires a valid signed entry timestamp. By correctly verifying the signed entry timestamp we can make certain assertions about the log signing the log entry (like the log was aware of the artifact signing event and signed it). Therefore the impact on clients that are not monitors/witnesses is very low. This vulnerability is fixed in 1.2.0.","exploit_maturity":"Proof of concept only","published":"2024-12-05","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2024-38829","description":"A vulnerability in Spring LDAP allows data exposure for case sensitive comparisons.This issue affects Spring LDAP: from 2.4.0 through 2.4.3, from 3.0.0 through 3.0.9, from 3.1.0 through 3.1.7, from 3.2.0 through 3.2.7, AND all versions prior to 2.4.0.\n\nThe usage of String.toLowerCase() and String.toUpperCase() has some Locale dependent exceptions that could potentially result in unintended columns from being queried\nRelated to  CVE-2024-38820 https://spring.io/security/cve-2024-38820","exploit_maturity":"No public exploit","published":"2024-12-04","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2024-52800","description":"veraPDF is an open source PDF/A validation library. Executing policy checks using custom schematron files via the CLI invokes an XSL transformation that may theoretically lead to a remote code execution (RCE) vulnerability. This doesn't affect the standard validation and policy checks functionality, veraPDF's common use cases. Most veraPDF users don't insert any custom XSLT code into policy profiles, which are based on Schematron syntax rather than direct XSL transforms. For users who do, only load custom policy files from sources you trust. This issue has not yet been patched. Users are advised to be cautious of XSLT code until a patch is available.","exploit_maturity":"No public exploit","published":"2024-11-29","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2024-10492","description":"A vulnerability was found in Keycloak. A user with high privileges could read sensitive information from a Vault file that is not within the expected context. This attacker must have previous high access to the Keycloak server in order to perform resource creation, for example, an LDAP provider configuration and set up a Vault read file, which will only inform whether that file exists or not.","exploit_maturity":"No public exploit","published":"2024-11-25","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2023-0657","description":"A flaw was found in Keycloak. This issue occurs due to improperly enforcing token types when validating signatures locally. This could allow an authenticated attacker to exchange a logout token for an access token and possibly gain access to data outside of enforced permissions.","exploit_maturity":"No public exploit","published":"2024-11-17","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2024-21257","description":"Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (component: UI and Visualization).   The supported version that is affected is 11.2.18.0.000. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion BI+ executes to compromise Oracle Hyperion BI+.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Hyperion BI+ accessible data. CVSS 3.1 Base Score 3.0 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2024-10-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2024-21217","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization).  Supported versions that are affected are Oracle Java SE: 8u421, 8u421-perf, 11.0.24, 17.0.12, 21.0.4, 23; Oracle GraalVM for JDK: 17.0.12, 21.0.4, 23; Oracle GraalVM Enterprise Edition: 20.3.15 and  21.3.11. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2024-10-15","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2024-21211","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Compiler).  Supported versions that are affected are Oracle Java SE: 23; Oracle GraalVM for JDK: 17.0.12, 21.0.4, 23; Oracle GraalVM Enterprise Edition: 20.3.15 and  21.3.11. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2024-10-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2024-21210","description":"Vulnerability in Oracle Java SE (component: Hotspot).  Supported versions that are affected are Oracle Java SE: 8u421, 8u421-perf, 11.0.24, 17.0.12, 21.0.4 and  23. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2024-10-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2024-21208","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking).  Supported versions that are affected are Oracle Java SE: 8u421, 8u421-perf, 11.0.24, 17.0.12, 21.0.4, 23; Oracle GraalVM for JDK: 17.0.12, 21.0.4, 23; Oracle GraalVM Enterprise Edition: 20.3.15 and  21.3.11. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2024-10-15","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2024-21144","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Concurrency).  Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23; Oracle GraalVM Enterprise Edition: 20.3.14 and  21.3.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2024-07-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2024-21138","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot).  Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM Enterprise Edition: 20.3.14 and  21.3.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2024-07-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2024-21131","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot).  Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM Enterprise Edition: 20.3.14 and  21.3.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2024-07-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2024-39458","description":"When Jenkins Structs Plugin 337.v1b_04ea_4df7c8 and earlier fails to configure a build step, it logs a warning message containing diagnostic information that may contain secrets passed as step parameters, potentially resulting in accidental exposure of secrets through the default system log.","exploit_maturity":"No public exploit","published":"2024-06-26","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2024-38364","description":"DSpace is an open source software is a turnkey repository application used by more than 2,000 organizations and institutions worldwide to provide durable access to digital resources. In DSpace 7.0 through 7.6.1, when an HTML, XML or JavaScript Bitstream is downloaded, the user's browser may execute any embedded JavaScript. If that embedded JavaScript is malicious, there is a risk of an XSS attack. This vulnerability has been patched in version 7.6.2.","exploit_maturity":"No public exploit","published":"2024-06-26","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2024-5967","description":"A vulnerability was found in Keycloak. The LDAP testing endpoint allows changing the Connection URL  independently without re-entering the currently configured LDAP bind credentials. This flaw allows an attacker with admin access (permission manage-realm) to change the LDAP host URL (\"Connection URL\") to a machine they control. The Keycloak server will connect to the attacker's host and try to authenticate with the configured credentials, thus leaking them to the attacker. As a consequence, an attacker who has compromised the admin console or compromised a user with sufficient privileges can leak domain credentials and attack the domain.","exploit_maturity":"No public exploit","published":"2024-06-18","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2024-21098","description":"Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Compiler).  Supported versions that are affected are Oracle GraalVM for JDK: 17.0.10, 21.0.2, 22; Oracle GraalVM Enterprise Edition: 20.3.13 and  21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2024-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2024-21094","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot).  Supported versions that are affected are Oracle Java SE: 8u401, 8u401-perf, 11.0.22, 17.0.10, 21.0.2, 22; Oracle GraalVM for JDK: 17.0.10, 21.0.2, 22; Oracle GraalVM Enterprise Edition: 20.3.13 and  21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2024-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2024-21085","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Concurrency).  Supported versions that are affected are Oracle Java SE: 8u401, 8u401-perf, 11.0.22; Oracle GraalVM Enterprise Edition: 20.3.13 and  21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2024-04-16","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2024-21068","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot).  Supported versions that are affected are Oracle Java SE: 8u401-perf, 11.0.22, 17.0.10, 21.0.2, 22; Oracle GraalVM for JDK: 17.0.10, 21.0.2 and  22; Oracle GraalVM Enterprise Edition: 21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2024-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2024-21011","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot).  Supported versions that are affected are Oracle Java SE: 8u401, 8u401-perf, 11.0.22, 17.0.10, 21.0.2, 22; Oracle GraalVM for JDK: 17.0.10, 21.0.2, 22;   Oracle GraalVM Enterprise Edition: 20.3.13 and  21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2024-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2024-21005","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX).  Supported versions that are affected are Oracle Java SE: 8u401; Oracle GraalVM Enterprise Edition: 20.3.13 and  21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2024-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2024-21004","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX).  Supported versions that are affected are Oracle Java SE: 8u401; Oracle GraalVM Enterprise Edition: 20.3.13 and  21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Java SE, Oracle GraalVM Enterprise Edition executes to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 2.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2024-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2024-21003","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX).  Supported versions that are affected are Oracle Java SE: 8u401; Oracle GraalVM Enterprise Edition: 20.3.13 and  21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2024-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2024-21002","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX).  Supported versions that are affected are Oracle Java SE: 8u401; Oracle GraalVM Enterprise Edition: 20.3.13 and  21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Java SE, Oracle GraalVM Enterprise Edition executes to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 2.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2024-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2024-20954","description":"Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Compiler).  Supported versions that are affected are Oracle GraalVM for JDK: 17.0.10, 21.0.2, 22; Oracle GraalVM Enterprise Edition: 20.3.13 and  21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2024-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2024-1979","description":"A vulnerability was found in Quarkus. In certain conditions related to the CI process, git credentials could be inadvertently published, which could put the git repository at risk.","exploit_maturity":"No public exploit","published":"2024-03-13","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2024-20925","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX).  Supported versions that are affected are Oracle Java SE: 8u391; Oracle GraalVM Enterprise Edition: 20.3.12 and  21.3.8. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2024-02-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2024-20923","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX).  Supported versions that are affected are Oracle Java SE: 8u391; Oracle GraalVM Enterprise Edition: 20.3.12 and  21.3.8. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2024-02-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2024-20905","description":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure SEC).  Supported versions that are affected are Prior to 9.2.8.0. Easily exploitable vulnerability allows high privileged attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 2.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2024-02-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2024-20957","description":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Package Build SEC).  Supported versions that are affected are Prior to 9.2.8.1. Easily exploitable vulnerability allows high privileged attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 2.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2024-01-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2024-20955","description":"Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Compiler).  Supported versions that are affected are Oracle GraalVM for JDK: 17.0.9, 21.0.1; Oracle GraalVM Enterprise Edition: 20.3.12, 21.3.8 and  22.3.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2024-01-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2024-20922","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX).  Supported versions that are affected are Oracle Java SE: 8u391; Oracle GraalVM Enterprise Edition: 20.3.12 and  21.3.8. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Java SE, Oracle GraalVM Enterprise Edition executes to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 2.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2024-01-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2023-49652","description":"Incorrect permission checks in Jenkins Google Compute Engine Plugin 4.550.vb_327fca_3db_11 and earlier allow attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate system-scoped credentials IDs of credentials stored in Jenkins and to connect to Google Cloud Platform using attacker-specified credentials IDs obtained through another method, to obtain information about existing projects. This fix has been backported to 4.3.17.1.","exploit_maturity":"No public exploit","published":"2023-11-29","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2023-36479","description":"Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in quotation marks. This wrapped command, plus an optional command prefix, will then be executed through a call to Runtime.exec. If the original binary name provided by the user contains a quotation mark followed by a space, the resulting command line will contain multiple tokens instead of one. This issue was patched in version 9.4.52, 10.0.16, 11.0.16 and 12.0.0-beta2.","exploit_maturity":"No public exploit","published":"2023-09-15","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2023-41946","description":"A cross-site request forgery (CSRF) vulnerability in Jenkins Frugal Testing Plugin 1.1 and earlier allows attackers to connect to Frugal Testing using attacker-specified credentials, and to retrieve test IDs and names from Frugal Testing, if a valid credential corresponds to the attacker-specified username.","exploit_maturity":"No public exploit","published":"2023-09-06","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2023-41044","description":"Graylog is a free and open log management platform. A partial path traversal vulnerability exists in Graylog's `Support Bundle` feature. The vulnerability is caused by incorrect user input validation in an HTTP API resource. Graylog's Support Bundle feature allows an attacker with valid Admin role credentials to download or delete files in sibling directories of the support bundle directory. The default `data_dir` in operating system packages (DEB, RPM) is set to `/var/lib/graylog-server`. The data directory for the Support Bundle feature is always `\u003cdata_dir\u003e/support-bundle`. Due to the partial path traversal vulnerability, an attacker with valid Admin role credentials can read or delete files in directories that start with a `/var/lib/graylog-server/support-bundle` directory name. The vulnerability would allow the download or deletion of files in the following example directories: `/var/lib/graylog-server/support-bundle-test` and `/var/lib/graylog-server/support-bundlesdirectory`. For the Graylog Docker images, the `data_dir` is set to `/usr/share/graylog/data` by default. This vulnerability is fixed in Graylog version 5.1.3 and later. Users are advised to upgrade. Users unable to upgrade should block all HTTP requests to the following HTTP API endpoints by using a reverse proxy server in front of Graylog. `GET /api/system/debug/support/bundle/download/{filename}` and `DELETE /api/system/debug/support/bundle/{filename}`.\n","exploit_maturity":"No public exploit","published":"2023-08-31","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2023-41041","description":"Graylog is a free and open log management platform. In a multi-node Graylog cluster, after a user has explicitly logged out, a user session may still be used for API requests until it has reached its original expiry time. Each node maintains an in-memory cache of user sessions. Upon a cache-miss, the session is loaded from the database. After that, the node operates solely on the cached session. Modifications to sessions will update the cached version as well as the session persisted in the database. However, each node maintains their isolated version of the session. When the user logs out, the session is removed from the node-local cache and deleted from the database. The other nodes will however still use the cached session. These nodes will only fail to accept the session id if they intent to update the session in the database. They will then notice that the session is gone. This is true for most API requests originating from user interaction with the Graylog UI because these will lead to an update of the session's \"last access\" timestamp. If the session update is however prevented by setting the `X-Graylog-No-Session-Extension:true` header in the request, the node will consider the (cached) session valid until the session is expired according to its timeout setting. No session identifiers are leaked. After a user has logged out, the UI shows the login screen again, which gives the user the impression that their session is not valid anymore. However, if the session becomes compromised later, it can still be used to perform API requests against the Graylog cluster. The time frame for this is limited to the configured session lifetime, starting from the time when the user logged out. This issue has been addressed in versions 5.0.9 and 5.1.3. Users are advised to upgrade.\n\n\n","exploit_maturity":"Proof of concept only","published":"2023-08-30","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2023-22049","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Libraries).  Supported versions that are affected are Oracle Java SE: 8u371, 8u371-perf, 11.0.19, 17.0.7, 20.0.1; Oracle GraalVM Enterprise Edition: 20.3.10, 21.3.6, 22.3.2; Oracle GraalVM for JDK: 17.0.7 and  20.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2023-07-18","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2023-22010","description":"Vulnerability in Oracle Essbase (component: Security and Provisioning).   The supported version that is affected is 21.4.3.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Essbase.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Essbase accessible data. CVSS 3.1 Base Score 2.2 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2023-07-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2023-37948","description":"Jenkins Oracle Cloud Infrastructure Compute Plugin 1.0.16 and earlier does not validate SSH host keys when connecting OCI clouds, enabling man-in-the-middle attacks.","exploit_maturity":"No public exploit","published":"2023-07-12","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2023-34442","description":"Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Camel.This issue affects Apache Camel: from 3.X through \u003c=3.14.8, from 3.18.X through \u003c=3.18.7, from 3.20.X through \u003c= 3.20.5, from 4.X through \u003c= 4.0.0-M3.\n\nUsers should upgrade to 3.14.9, 3.18.8, 3.20.6 or 3.21.0 and for users on Camel 4.x update to 4.0.0-M1\n","exploit_maturity":"No public exploit","published":"2023-07-10","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2023-32994","description":"Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 and earlier unconditionally disables SSL/TLS certificate validation for connections to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to intercept these connections.","exploit_maturity":"No public exploit","published":"2023-05-16","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2023-21968","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).  Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and  22.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2023-04-18","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2023-21938","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).  Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.8, 21.3.4 and  22.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2023-04-18","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2023-21937","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking).  Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and  22.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2023-04-18","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2022-41862","description":"In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.","exploit_maturity":"No public exploit","published":"2023-03-03","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2023-0481","description":"In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user.","exploit_maturity":"No public exploit","published":"2023-02-24","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2023-23847","description":"A cross-site request forgery (CSRF) vulnerability in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.","exploit_maturity":"No public exploit","published":"2023-02-15","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2023-21843","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Sound).  Supported versions that are affected are Oracle Java SE: 8u351, 8u351-perf, 11.0.17, 17.0.5, 19.0.1; Oracle GraalVM Enterprise Edition: 20.3.8, 21.3.4 and  22.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2023-01-18","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2023-0091","description":"A flaw was found in Keycloak, where it did not properly check client tokens for possible revocation in its client credential flow. This flaw allows an attacker to access or modify potentially sensitive information.","exploit_maturity":"No public exploit","published":"2023-01-13","resolved":"MITIGATION-CANDIDATE","severity":"Low"},
  {"cve_id":"CVE-2022-41954","description":"MPXJ is an open source library to read and write project plans from a variety of file formats and databases. On Unix-like operating systems (not Windows or macos), MPXJ's use of `File.createTempFile(..)` results in temporary files being created with the permissions `-rw-r--r--`. This means that any other user on the system can read the contents of this file. When MPXJ is reading a schedule file which requires the creation of a temporary file or directory, a knowledgeable local user could locate these transient files while they are in use and would then be able to read the schedule being processed by MPXJ. The problem has been patched, MPXJ version 10.14.1 and later includes the necessary changes. Users unable to upgrade may set `java.io.tmpdir` to a directory to which only the user running the application has access will prevent other users from accessing these temporary files.","exploit_maturity":"No public exploit","published":"2022-11-25","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2022-45393","description":"A cross-site request forgery (CSRF) vulnerability in Jenkins Delete log Plugin 1.0 and earlier allows attackers to delete build logs.","exploit_maturity":"No public exploit","published":"2022-11-15","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2022-39409","description":"Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Business Process Automation). Supported versions that are affected are 6.4.3 and 6.5.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Transportation Management. CVSS 3.1 Base Score 2.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2022-10-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2022-21624","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JNDI). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2022-10-18","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2022-21619","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2022-10-18","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2021-43980","description":"The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18, 9.0.0-M1 to 9.0.60 and 8.5.0 to 8.5.77 that could cause client connections to share an Http11Processor instance resulting in responses, or part responses, to be received by the wrong client.","exploit_maturity":"No public exploit","published":"2022-09-28","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2022-31679","description":"Applications that allow HTTP PATCH access to resources exposed by Spring Data REST in versions 3.6.0 - 3.5.5, 3.7.0 - 3.7.2, and older unsupported versions, if an attacker knows about the structure of the underlying domain model, they can craft HTTP requests that expose hidden entity attributes.","exploit_maturity":"No public exploit","published":"2022-09-21","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2022-2256","description":"A Stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single Sign-On 7. This flaw allows a privileged attacker to execute malicious scripts in the admin console, abusing the default roles functionality.","exploit_maturity":"No public exploit","published":"2022-09-01","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2021-3644","description":"A flaw was found in wildfly-core in all versions. If a vault expression is in the form of a single attribute that contains multiple expressions, a user who was granted access to the management interface can potentially access a vault expression they should not be able to access and possibly retrieve the item which was stored in the vault. The highest threat from this vulnerability is data confidentiality and integrity.","exploit_maturity":"No public exploit","published":"2022-08-26","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2022-2047","description":"In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid input as a hostname. This can lead to failures in a Proxy scenario.","exploit_maturity":"No public exploit","published":"2022-07-07","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2022-33879","description":"The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insufficient, and we found a separate, new regex DoS in a different regex in the StandardsExtractingContentHandler. These are now fixed in 1.28.4 and 2.4.1.","exploit_maturity":"No public exploit","published":"2022-06-27","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2022-29253","description":"XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting with version 8.3-rc-1 and prior to versions 12.10.3 and 14.0, one can ask for any file located in the classloader using the template API and a path with \"..\" in it. The issue is patched in versions 14.0 and 13.10.3. There is no easy workaround for this issue.","exploit_maturity":"No public exploit","published":"2022-05-25","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2022-21443","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2022-04-19","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2022-0861","description":"A XML Extended entity vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote administrator attacker to upload a malicious XML file through the extension import functionality. The impact is limited to some access to confidential information and some ability to alter data.","exploit_maturity":"No public exploit","published":"2022-03-23","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2022-21388","description":"Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications Applications (component: On Premise Install). Supported versions that are affected are 12.0.0.3.0 and 12.0.0.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Pricing Design Center executes to compromise Oracle Communications Pricing Design Center. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Communications Pricing Design Center accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2022-01-19","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2022-21268","description":"Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Pipeline Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Billing and Revenue Management executes to compromise Oracle Communications Billing and Revenue Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Communications Billing and Revenue Management accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2022-01-19","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2022-21267","description":"Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Pipeline Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Billing and Revenue Management executes to compromise Oracle Communications Billing and Revenue Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Communications Billing and Revenue Management accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2022-01-19","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2022-21248","description":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2022-01-19","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2022-23114","description":"Jenkins Publish Over SSH Plugin 1.22 and earlier stores password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.","exploit_maturity":"No public exploit","published":"2022-01-12","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2021-35603","description":"Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2021-10-20","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2021-35588","description":"Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 7u311, 8u301; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2021-10-20","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2021-2480","description":"Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported version that is affected is 11.1.1.9.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HTTP Server accessible data. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2021-10-20","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2021-2448","description":"Vulnerability in the Oracle Financial Services Crime and Compliance Investigation Hub product of Oracle Financial Services Applications (component: Reports). The supported version that is affected is 20.1.2. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Financial Services Crime and Compliance Investigation Hub executes to compromise Oracle Financial Services Crime and Compliance Investigation Hub. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Crime and Compliance Investigation Hub, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Crime and Compliance Investigation Hub accessible data as well as unauthorized read access to a subset of Oracle Financial Services Crime and Compliance Investigation Hub accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N).","exploit_maturity":"No public exploit","published":"2021-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2021-2432","description":"Vulnerability in the Java SE product of Oracle Java SE (component: JNDI). The supported version that is affected is Java SE: 7u301. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2021-07-21","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2021-2341","description":"Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u301, 8u291, 11.0.11, 16.0.1; Oracle GraalVM Enterprise Edition: 20.3.2 and 21.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2021-07-21","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2021-33604","description":"URL encoding error in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.6.1 (Vaadin 14.0.0 through 14.6.1), 3.0.0 through 6.0.9 (Vaadin 15.0.0 through 19.0.8) allows local user to execute arbitrary JavaScript code by opening crafted URL in browser.","exploit_maturity":"No public exploit","published":"2021-06-24","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2021-34428","description":"For Eclipse Jetty versions \u003c= 9.4.40, \u003c= 10.0.2, \u003c= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.","exploit_maturity":"No public exploit","published":"2021-06-22","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2021-3200","description":"Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which could cause a denial of service","exploit_maturity":"No public exploit","published":"2021-05-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2021-2159","description":"Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Frameworks). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 3.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2021-04-22","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2021-2158","description":"Vulnerability in the Hyperion Financial Management product of Oracle Hyperion (component: Task Automation). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Hyperion Financial Management accessible data as well as unauthorized read access to a subset of Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Hyperion Financial Management. CVSS 3.1 Base Score 3.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L).","exploit_maturity":"No public exploit","published":"2021-04-22","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2021-2141","description":"Vulnerability in the Oracle FLEXCUBE Direct Banking product of Oracle Financial Services Applications (component: Pre Login). Supported versions that are affected are 12.0.2 and 12.0.3. Difficult to exploit vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle FLEXCUBE Direct Banking. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Direct Banking accessible data. CVSS 3.1 Base Score 2.0 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2021-04-22","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2021-28163","description":"In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory.","exploit_maturity":"No public exploit","published":"2021-04-01","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2019-14850","description":"A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and cause it to perform a large amount of work in initializing backend plugins, by simply opening a connection to the service. This vulnerability could cause resource consumption and degradation of service in nbdkit, depending on the plugins configured on the server-side.","exploit_maturity":"No public exploit","published":"2021-03-18","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2021-21331","description":"The Java client for the Datadog API before version 1.0.0-beta.9 has a local information disclosure of sensitive information downloaded via the API using the API Client. The Datadog API is executed on a unix-like system with multiple users. The API is used to download a file containing sensitive information. This sensitive information is exposed locally to other users. This vulnerability exists in the API Client for version 1 and 2. The method `prepareDownloadFilecreates` creates a temporary file with the permissions bits of `-rw-r--r--` on unix-like systems. On unix-like systems, the system temporary directory is shared between users. As such, the contents of the file downloaded via the `downloadFileFromResponse` method will be visible to all other users on the local system. Analysis of the finding determined that the affected code was unused, meaning that the exploitation likelihood is low. The unused code has been removed, effectively mitigating this issue. This issue has been patched in version 1.0.0-beta.9. As a workaround one may specify `java.io.tmpdir` when starting the JVM with the flag `-Djava.io.tmpdir`, specifying a path to a directory with `drw-------` permissions owned by `dd-agent`.","exploit_maturity":"No public exploit","published":"2021-03-03","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2020-1717","description":"A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.","exploit_maturity":"No public exploit","published":"2021-02-11","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2020-10734","description":"A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection. Versions shipped with Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes are believed to be vulnerable.","exploit_maturity":"No public exploit","published":"2021-02-11","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2021-1996","description":"Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 2.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2021-01-20","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2020-14341","description":"The \"Test Connection\" available in v7.x of the Red Hat Single Sign On application console can permit an authorized user to cause SMTP connections to be attempted to arbitrary hosts and ports of the user's choosing, and originating from the RHSSO installation. By observing differences in the timings of these scans, an attacker may glean information about hosts and ports which they do not have access to scan directly.","exploit_maturity":"No public exploit","published":"2021-01-12","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2020-8920","description":"An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where an overoptimization with the FilteredRepository wrapper skips the verification of access on All-Users repositories, allowing an attacker to get read access to all users' personal information associated with their accounts.","exploit_maturity":"No public exploit","published":"2020-12-10","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2020-8908","description":"A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable (readable by an attacker with access to the system). The method in question has been marked @Deprecated in versions 30.0 and later and should not be used. For Android developers, we recommend choosing a temporary directory API provided by Android, such as context.getCacheDir(). For other Java developers, we recommend migrating to the Java 7 API java.nio.file.Files.createTempDirectory() which explicitly configures permissions of 700, or configuring the Java runtime's java.io.tmpdir system property to point to a location whose permissions are appropriately configured.","exploit_maturity":"No public exploit","published":"2020-12-10","resolved":"MITIGATION-CANDIDATE","severity":"Low"},
  {"cve_id":"CVE-2020-28923","description":"An issue was discovered in Play Framework 2.8.0 through 2.8.4. Carefully crafted JSON payloads sent as a form field lead to Data Amplification. This affects users migrating from a Play version prior to 2.8.0 that used the Play Java API to serialize classes with protected or private fields to JSON.","exploit_maturity":"No public exploit","published":"2020-12-03","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2020-7020","description":"Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain complex queries. This could result in the search disclosing the existence of documents the attacker should not be able to view. This could result in an attacker gaining additional insight into potentially sensitive indices.","exploit_maturity":"No public exploit","published":"2020-10-22","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2020-14847","description":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Query). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2020-10-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2020-14798","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2020-10-21","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2020-14797","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2020-10-21","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2020-14796","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2020-10-21","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2020-14781","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JNDI). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2020-10-21","resolved":"MITIGATION-CANDIDATE","severity":"Low"},
  {"cve_id":"CVE-2020-14779","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2020-10-21","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2020-14770","description":"Vulnerability in the Hyperion BI+ product of Oracle Hyperion (component: IQR-Foundation service). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise Hyperion BI+. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Hyperion BI+ accessible data. CVSS 3.1 Base Score 2.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2020-10-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2020-14732","description":"Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Promotions). The supported version that is affected is 19.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Customer Management and Segmentation Foundation. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Retail Customer Management and Segmentation Foundation accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2020-10-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2020-14731","description":"Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Segment). Supported versions that are affected are 18.0 and 19.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Customer Management and Segmentation Foundation. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Retail Customer Management and Segmentation Foundation accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2020-10-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2020-2297","description":"Jenkins SMS Notification Plugin 1.2 and earlier stores an access token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.","exploit_maturity":"No public exploit","published":"2020-10-08","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2020-2291","description":"Jenkins couchdb-statistics Plugin 0.3 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.","exploit_maturity":"No public exploit","published":"2020-10-08","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2020-4629","description":"IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local user with specialized access to obtain sensitive information from a detailed technical error message. This information could be used in further attacks against the system. IBM X-Force ID: 185370.","exploit_maturity":"No public exploit","published":"2020-09-30","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2020-2249","description":"Jenkins Team Foundation Server Plugin 5.157.1 and earlier stores a webhook secret unencrypted in its global configuration file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.","exploit_maturity":"No public exploit","published":"2020-09-01","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2020-14616","description":"Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (component: Reporting). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hospitality Reporting and Analytics. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hospitality Reporting and Analytics accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2020-07-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2020-14590","description":"Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Page Request). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2020-07-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2020-14581","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2020-07-15","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2020-14579","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u261 and 8u251; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2020-07-15","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2020-14578","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u261 and 8u251; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2020-07-15","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2020-14577","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2020-07-15","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2020-14573","description":"Vulnerability in the Java SE product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 11.0.7 and 14.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2020-07-15","resolved":"MITIGATION-CANDIDATE","severity":"Low"},
  {"cve_id":"CVE-2020-14564","description":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Environment Mgmt Console). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 2.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2020-07-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2020-14548","description":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 3.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2020-07-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2020-14541","description":"Vulnerability in the Hyperion Financial Close Management product of Oracle Hyperion (component: Close Manager). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Financial Close Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Hyperion Financial Close Management accessible data. CVSS 3.1 Base Score 2.0 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2020-07-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2020-14533","description":"Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Supported versions that are affected are 11.1, 11.2 and prior to 11.3.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Platform accessible data as well as unauthorized read access to a subset of Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 3.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N).","exploit_maturity":"No public exploit","published":"2020-07-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2020-2218","description":"Jenkins HP ALM Quality Center Plugin 1.6 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.","exploit_maturity":"No public exploit","published":"2020-07-02","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2020-2900","description":"Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: Tools). Supported versions that are affected are 19.3.1 and 20.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle GraalVM Enterprise Edition accessible data. CVSS 3.0 Base Score 3.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N).","exploit_maturity":"No public exploit","published":"2020-04-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2020-2773","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2020-04-15","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2020-2769","description":"Vulnerability in the Hyperion Financial Reporting product of Oracle Hyperion (component: Web Based Report Designer). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Hyperion Financial Reporting accessible data. CVSS 3.0 Base Score 2.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2020-04-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2020-2757","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2020-04-15","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2020-2756","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2020-04-15","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2020-2755","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Scripting). Supported versions that are affected are Java SE: 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2020-04-15","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2020-2754","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Scripting). Supported versions that are affected are Java SE: 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2020-04-15","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2020-2659","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u241 and 8u231; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2020-01-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2020-2654","description":"Vulnerability in the Java SE product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2020-01-15","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2020-2649","description":"Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Internal Operations). The supported version that is affected is 16.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Retail Customer Management and Segmentation Foundation executes to compromise Oracle Retail Customer Management and Segmentation Foundation. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Retail Customer Management and Segmentation Foundation accessible data. CVSS 3.0 Base Score 3.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2020-01-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2020-2590","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2020-01-15","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2020-2583","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2020-01-15","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2020-2531","description":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: BI Platform Security). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.0 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2020-01-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-2148","description":"An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores java security policies","exploit_maturity":"No public exploit","published":"2019-12-06","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2019-2992","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2019-10-16","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2019-2988","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2019-10-16","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2019-2987","description":"Vulnerability in the Java SE product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 11.0.4 and 13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2019-10-16","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2019-2983","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2019-10-16","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2019-2981","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2019-10-16","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2019-2978","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2019-10-16","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2019-2973","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2019-10-16","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2019-2964","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2019-10-16","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2019-2962","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2019-10-16","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2019-2945","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2019-10-16","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2019-2933","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2019-10-16","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2019-2899","description":"Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: OAM). Supported versions that are affected are 11.1.1.9.0, 11.1.2.4.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle JDeveloper and ADF. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle JDeveloper and ADF accessible data. CVSS 3.0 Base Score 2.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2019-10-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2019-2894","description":"Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2019-10-16","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2019-2872","description":"Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Point of Sale). Supported versions that are affected are 17.0.3, 18.0.1 and 19.0.0. Difficult to exploit vulnerability allows physical access to compromise Oracle Retail Xstore Point of Service. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Retail Xstore Point of Service accessible data as well as unauthorized read access to a subset of Oracle Retail Xstore Point of Service accessible data. CVSS 3.0 Base Score 2.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:P/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N).","exploit_maturity":"No public exploit","published":"2019-10-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2019-10450","description":"Jenkins ElasticBox CI Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users with access to the master file system.","exploit_maturity":"No public exploit","published":"2019-10-16","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2019-10433","description":"Jenkins Dingding[钉钉] Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.","exploit_maturity":"No public exploit","published":"2019-10-01","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2019-4271","description":"IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin console is vulnerable to a Client-side HTTP parameter pollution vulnerability. IBM X-Force ID: 160243.","exploit_maturity":"No public exploit","published":"2019-09-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2019-10397","description":"Jenkins Aqua Security Serverless Scanner Plugin 1.0.4 and earlier transmitted configured passwords in plain text as part of job configuration forms, potentially resulting in their exposure.","exploit_maturity":"No public exploit","published":"2019-09-12","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2015-7559","description":"It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.","exploit_maturity":"No public exploit","published":"2019-08-01","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2019-10343","description":"Jenkins Configuration as Code Plugin 1.24 and earlier did not properly apply masking to values expected to be hidden when logging the configuration being applied.","exploit_maturity":"No public exploit","published":"2019-07-31","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2019-2845","description":"Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1, 12.0.3, 12.0.4, 12.1.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle FLEXCUBE Investor Servicing. CVSS 3.0 Base Score 3.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2019-07-23","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2019-2842","description":"Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JCE). The supported version that is affected is Java SE: 8u212. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2019-07-23","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2019-2818","description":"Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 11.0.3 and 12.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2019-07-23","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2019-2793","description":"Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1-12.0.3, 12.1.0-12.4.0 and 14.0.0-14.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle FLEXCUBE Universal Banking. CVSS 3.0 Base Score 3.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2019-07-23","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2019-2786","description":"Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2019-07-23","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2019-2766","description":"Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2019-07-23","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2019-2761","description":"Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Attachments / File Upload). Supported versions that are affected are 12.1.3 and 12.2.3 - 12.2.8. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Application Object Library accessible data. CVSS 3.0 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2019-07-23","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2019-2735","description":"Vulnerability in the Oracle Hyperion Workspace component of Oracle Hyperion (subcomponent: UI and Visualization). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Workspace. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Workspace accessible data. CVSS 3.0 Base Score 2.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2019-07-23","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2019-11808","description":"Ratpack versions before 1.6.1 generate a session ID using a cryptographically weak PRNG in the JDK's ThreadLocalRandom. This means that if an attacker can determine a small window for the server start time and obtain a session ID value, they can theoretically determine the sequence of session IDs.","exploit_maturity":"No public exploit","published":"2019-05-07","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2019-3868","description":"Keycloak up to version 6.0.0 allows the end user token (access or id token JWT) to be used as the session cookie for browser sessions for OIDC. As a result an attacker with access to service provider backend could hijack user’s browser session.","exploit_maturity":"No public exploit","published":"2019-04-24","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2019-2720","description":"Vulnerability in the Oracle Data Integrator component of Oracle Fusion Middleware (subcomponent: ODI Tools). Supported versions that are affected are 11.1.1.9.0 and 12.2.1.3.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Data Integrator. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Data Integrator accessible data. CVSS 3.0 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2019-04-23","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2019-2605","description":"Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Web Catalog). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.0 Base Score 3.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2019-04-23","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2019-2493","description":"Vulnerability in the PeopleSoft Enterprise CS Campus Community component of Oracle PeopleSoft Products (subcomponent: Frameworks). Supported versions that are affected are 9.0 and 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.0 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2019-01-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2019-2426","description":"Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u201, 8u192 and 11.0.1; Java SE Embedded: 8u191. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2019-01-16","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2019-2422","description":"Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u201, 8u192 and 11.0.1; Java SE Embedded: 8u191. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2019-01-16","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2018-3184","description":"Vulnerability in the Hyperion BI+ component of Oracle Hyperion (subcomponent: IQR - Foundation Services). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion BI+. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Hyperion BI+ accessible data. CVSS 3.0 Base Score 2.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2018-10-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2018-3157","description":"Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Sound). The supported version that is affected is Java SE: 11. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE accessible data. Note: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2018-10-17","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2018-3150","description":"Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Utility). The supported version that is affected is Java SE: 11. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data. Note: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2018-10-17","resolved":"MITIGATION-CANDIDATE","severity":"Low"},
  {"cve_id":"CVE-2018-3139","description":"Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and 11; Java SE Embedded: 8u181. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g. code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g. code installed by an administrator). CVSS 3.0 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2018-10-17","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2018-3136","description":"Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and 11; Java SE Embedded: 8u181. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g. code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g. code installed by an administrator). CVSS 3.0 Base Score 3.4 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2018-10-17","resolved":"MITIGATION-CANDIDATE","severity":"Low"},
  {"cve_id":"CVE-2017-2651","description":"jenkins-mailer-plugin before version 1.20 is vulnerable to an information disclosure while using the feature to send emails to a dynamically created list of users based on the changelogs. This could in some cases result in emails being sent to people who have no user account in Jenkins, and in rare cases even people who were not involved in whatever project was being built, due to some mapping based on the local-part of email addresses.","exploit_maturity":"No public exploit","published":"2018-07-27","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2018-3076","description":"Vulnerability in the PeopleSoft Enterprise CS Financial Aid component of Oracle PeopleSoft Products (subcomponent: ISIR Processing). Supported versions that are affected are 9.0 and 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Financial Aid. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise CS Financial Aid accessible data. CVSS 3.0 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2018-07-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2018-3069","description":"Vulnerability in the Oracle Agile Product Lifecycle Management for Process component of Oracle Supply Chain Products Suite (subcomponent: Installation). The supported version that is affected is 6.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Agile Product Lifecycle Management for Process accessible data. CVSS 3.0 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2018-07-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2018-2952","description":"Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Concurrency). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171; JRockit: R28.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2018-07-18","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2016-1000346","description":"In the Bouncy Castle JCE Provider version 1.55 and earlier the other party DH public key is not fully validated. This can cause issues as invalid keys can be used to reveal details about the other party's private key where static Diffie-Hellman is in use. As of release 1.56 the key parameters are checked on agreement calculation.","exploit_maturity":"No public exploit","published":"2018-06-04","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2017-2603","description":"Jenkins before versions 2.44, 2.32.2 is vulnerable to a user data leak in disconnected agents' config.xml API. This could leak sensitive data such as API tokens (SECURITY-362).","exploit_maturity":"No public exploit","published":"2018-05-15","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2018-2790","description":"Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2018-04-19","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2018-1315","description":"In Apache Hive 2.1.0 to 2.3.2, when 'COPY FROM FTP' statement is run using HPL/SQL extension to Hive, a compromised/malicious FTP server can cause the file to be written to an arbitrary location on the cluster where the command is run from. This is because FTP client code in HPL/SQL does not verify the destination location of the downloaded file. This does not affect hive cli user and hiveserver2 user as hplsql is a separate command line script and needs to be invoked differently.","exploit_maturity":"No public exploit","published":"2018-04-05","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2018-1284","description":"In Apache Hive 0.6.0 to 2.3.2, malicious user might use any xpath UDFs (xpath/xpath_string/xpath_boolean/xpath_number/xpath_double/xpath_float/xpath_long/xpath_int/xpath_short) to expose the content of a file on the machine running HiveServer2 owned by HiveServer2 user (usually hive) if hive.server2.enable.doAs=false.","exploit_maturity":"No public exploit","published":"2018-04-05","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2018-1000150","description":"An exposure of sensitive information vulnerability exists in Jenkins Reverse Proxy Auth Plugin 1.5 and older in ReverseProxySecurityRealm#authContext that allows attackers with local file system access to obtain a list of authorities for logged in users.","exploit_maturity":"No public exploit","published":"2018-04-05","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2017-15709","description":"When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.","exploit_maturity":"No public exploit","published":"2018-02-13","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2017-1000401","description":"The Jenkins 2.73.1 and earlier, 2.83 and earlier default form control for passwords and other secrets, \u003cf:password/\u003e, supports form validation (e.g. for API keys). The form validation AJAX requests were sent via GET, which could result in secrets being logged to a HTTP access log in non-default configurations of Jenkins, and made available to users with access to these log files. Form validation for \u003cf:password/\u003e is now always sent via POST, which is typically not logged.","exploit_maturity":"No public exploit","published":"2018-01-26","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2018-2579","description":"Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded, JRockit accessible data. Note: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2018-01-18","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2017-1000242","description":"Jenkins Git Client Plugin 2.4.2 and earlier creates temporary file with insecure permissions resulting in information disclosure","exploit_maturity":"No public exploit","published":"2017-11-01","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2017-10426","description":"Vulnerability in the PeopleSoft Enterprise FSCM component of Oracle PeopleSoft Products (subcomponent: Staffing Front Office). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FSCM. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise FSCM accessible data. CVSS 3.0 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2017-10-19","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2017-10399","description":"Vulnerability in the Oracle Hospitality Cruise Fleet Management component of Oracle Hospitality Applications (subcomponent: GangwayActivityWebApp). The supported version that is affected is 9.0.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Cruise Fleet Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hospitality Cruise Fleet Management. CVSS 3.0 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2017-10-19","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2017-10345","description":"Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L).","exploit_maturity":"No public exploit","published":"2017-10-19","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2017-10341","description":"Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java Advanced Management Console. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java Advanced Management Console accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2017-10-19","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2017-10308","description":"Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Performance). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows physical access to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data as well as unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.0 Base Score 3.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).","exploit_maturity":"No public exploit","published":"2017-10-19","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2017-10166","description":"Vulnerability in the Oracle Security Service component of Oracle Fusion Middleware (subcomponent: C Oracle SSL API). Supported versions that are affected are FMW: 11.1.1.9.0 and 12.1.3.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Security Service. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Security Service accessible data. CVSS 3.0 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2017-10-19","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2017-10014","description":"Vulnerability in the Oracle Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite8/RESTAPI). The supported version that is affected is 1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Hotel Mobile. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hospitality Hotel Mobile accessible data. CVSS 3.0 Base Score 3.5 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2017-10-19","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2017-1000114","description":"The Datadog Plugin stores an API key to access the Datadog service in the global Jenkins configuration. While the API key is stored encrypted on disk, it was transmitted in plain text as part of the configuration form. This could result in exposure of the API key for example through browser extensions or cross-site scripting vulnerabilities. The Datadog Plugin now encrypts the API key transmitted to administrators viewing the global configuration form.","exploit_maturity":"No public exploit","published":"2017-10-05","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2017-12973","description":"Nimbus JOSE+JWT before 4.39 proceeds improperly after detection of an invalid HMAC in authenticated AES-CBC decryption, which allows attackers to conduct a padding oracle attack.","exploit_maturity":"No public exploit","published":"2017-08-20","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2017-10254","description":"Vulnerability in the PeopleSoft Enterprise FSCM component of Oracle PeopleSoft Products (subcomponent: Staffing Front Office). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FSCM. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise FSCM accessible data. CVSS 3.0 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2017-08-08","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2017-10193","description":"Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2017-08-08","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2017-10088","description":"Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile PLM executes to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data as well as unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.0 Base Score 3.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).","exploit_maturity":"No public exploit","published":"2017-08-08","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2017-1381","description":"IBM WebSphere Application Server Proxy Server or On-demand-router (ODR) 7.0, 8.0, 8.5, 9.0 and could allow a local attacker to obtain sensitive information, caused by stale data being cached and then served. IBM X-Force ID: 127152.","exploit_maturity":"No public exploit","published":"2017-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-3189","description":"With Cloud Foundry Runtime cf-release versions v208 or earlier, UAA Standalone versions 2.2.5 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier, old Password Reset Links are not expired after the user changes their current email address to a new one. This vulnerability is applicable only when using the UAA internal user store for authentication. Deployments enabled for integration via SAML or LDAP are not affected.","exploit_maturity":"No public exploit","published":"2017-05-25","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2017-3626","description":"Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Java Server Faces). The supported version that is affected is 3.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GlassFish Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle GlassFish Server accessible data. CVSS 3.0 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2017-04-24","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2017-3603","description":"Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle WebCenter Sites accessible data. CVSS 3.0 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2017-04-24","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2017-3598","description":"Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle WebCenter Sites accessible data. CVSS 3.0 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2017-04-24","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2017-3544","description":"Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTP to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded, JRockit accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2017-04-24","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2017-3539","description":"Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2017-04-24","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2017-3533","description":"Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via FTP to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded, JRockit accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2017-04-24","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2017-3490","description":"Vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component of Oracle Financial Services Applications (subcomponent: Limits and Collateral). Supported versions that are affected are 12.0.0 and 12.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Enterprise Limits and Collateral Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle FLEXCUBE Enterprise Limits and Collateral Management accessible data. CVSS 3.0 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).","exploit_maturity":"No public exploit","published":"2017-04-24","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2017-3487","description":"Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Unit Trust). Supported versions that are affected are 12.0.1, 12.0.2, 12.0.3, 12.0.4, 12.1.0, 12.2.0 and 12.3.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Investor Servicing accessible data. CVSS 3.0 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N).","exploit_maturity":"No public exploit","published":"2017-04-24","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2017-3264","description":"Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: Open UI). The supported version that is affected is 16.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Siebel UI Framework accessible data. CVSS v3.0 Base Score 3.1 (Integrity impacts).","exploit_maturity":"No public exploit","published":"2017-01-27","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2017-3239","description":"Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Administration). Supported versions that are affected are 3.0.1 and 3.1.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GlassFish Server executes to compromise Oracle GlassFish Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle GlassFish Server accessible data. CVSS v3.0 Base Score 3.3 (Confidentiality impacts).","exploit_maturity":"No public exploit","published":"2017-01-27","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2017-3235","description":"Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0 and 12.2.0. Easily exploitable vulnerability allows physical access to compromise Oracle FLEXCUBE Universal Banking. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Universal Banking accessible data as well as unauthorized read access to a subset of Oracle FLEXCUBE Universal Banking accessible data. CVSS v3.0 Base Score 3.5 (Confidentiality and Integrity impacts).","exploit_maturity":"No public exploit","published":"2017-01-27","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-8328","description":"Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java Mission Control). The supported version that is affected is Java SE: 8u112. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data. Note: Applies to Java Mission Control Installation. CVSS v3.0 Base Score 3.7 (Integrity impacts).","exploit_maturity":"No public exploit","published":"2017-01-27","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2016-8314","description":"Vulnerability in the Oracle FLEXCUBE Core Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 5.1.0, 5.2.0 and 11.5.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Core Banking. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle FLEXCUBE Core Banking accessible data. CVSS v3.0 Base Score 3.1 (Confidentiality impacts).","exploit_maturity":"No public exploit","published":"2017-01-27","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-8305","description":"Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0 and 12.2.0. Easily exploitable vulnerability allows physical access to compromise Oracle FLEXCUBE Universal Banking. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle FLEXCUBE Universal Banking accessible data. CVSS v3.0 Base Score 2.1 (Confidentiality impacts).","exploit_maturity":"No public exploit","published":"2017-01-27","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-5509","description":"Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 12.0.1, 12.0.2,12.0.4,12.1.0 and 12.3.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle FLEXCUBE Investor Servicing accessible data. CVSS v3.0 Base Score 3.1 (Confidentiality impacts).","exploit_maturity":"No public exploit","published":"2017-01-27","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-0378","description":"IBM WebSphere Application Server (WAS) Liberty before 16.0.0.3, when the installation lacks a default error page, allows remote attackers to obtain sensitive information by triggering an exception.","exploit_maturity":"No public exploit","published":"2016-11-24","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-5618","description":"Unspecified vulnerability in the Oracle Data Integrator component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, 12.1.2.0.0, 12.1.3.0.0, 12.2.1.0.0, and 12.2.1.1.0 allows remote authenticated users to affect confidentiality via vectors related to Code Generation Engine.","exploit_maturity":"No public exploit","published":"2016-10-25","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-5542","description":"Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors related to Libraries.","exploit_maturity":"No public exploit","published":"2016-10-25","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2016-5506","description":"Unspecified vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware allows local users to affect confidentiality and integrity via vectors related to App Server.","exploit_maturity":"No public exploit","published":"2016-10-25","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-5490","description":"Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.4.0 allows local users to affect confidentiality via vectors related to INFRA.","exploit_maturity":"No public exploit","published":"2016-10-25","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-2960","description":"IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.0.x before 8.0.0.13, 8.5.0.x before 8.5.5.10, 8.5.0.x and 16.0.0.x Liberty before Liberty Fix Pack 16.0.0.3, and 9.0.0.x before 9.0.0.1 allows remote attackers to cause a denial of service via crafted SIP messages.","exploit_maturity":"No public exploit","published":"2016-08-08","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-5473","description":"Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect confidentiality via vectors related to File Folders / Attachment, a different vulnerability than CVE-2016-3537.","exploit_maturity":"No public exploit","published":"2016-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-5466","description":"Unspecified vulnerability in the Siebel Core - Server Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote attackers to affect confidentiality via vectors related to Services, a different vulnerability than CVE-2016-3450 and CVE-2016-5460.","exploit_maturity":"No public exploit","published":"2016-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-5462","description":"Unspecified vulnerability in the Siebel Core - Server Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote administrators to affect confidentiality via vectors related to Workspaces.","exploit_maturity":"No public exploit","published":"2016-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-5460","description":"Unspecified vulnerability in the Siebel Core - Server Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote attackers to affect confidentiality via vectors related to Services, a different vulnerability than CVE-2016-3450 and CVE-2016-5466.","exploit_maturity":"No public exploit","published":"2016-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-3531","description":"Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect confidentiality via vectors related to PC / Notification.","exploit_maturity":"No public exploit","published":"2016-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-3516","description":"Unspecified vulnerability in the Oracle Enterprise Communications Broker component in Oracle Communications Applications before PCz 2.0.0m4p1 allows remote authenticated users to affect confidentiality via vectors related to GUI, a different vulnerability than CVE-2016-3514.","exploit_maturity":"No public exploit","published":"2016-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-3490","description":"Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.4.0, and 6.4.1 allows remote authenticated users to affect confidentiality via vectors related to Database.","exploit_maturity":"No public exploit","published":"2016-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-3482","description":"Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.9 and 12.1.3.0 allows remote attackers to affect confidentiality via vectors related to SSL/TLS Module.","exploit_maturity":"No public exploit","published":"2016-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-3474","description":"Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote attackers to affect confidentiality via vectors related to Security.","exploit_maturity":"No public exploit","published":"2016-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-3469","description":"Unspecified vulnerability in the Siebel Core - Server Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows local users to affect confidentiality via vectors related to Services.","exploit_maturity":"No public exploit","published":"2016-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-3450","description":"Unspecified vulnerability in the Siebel Core - Server Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote attackers to affect confidentiality via vectors related to Services, a different vulnerability than CVE-2016-5460 and CVE-2016-5466.","exploit_maturity":"No public exploit","published":"2016-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-3428","description":"Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.3.0 and 6.2.0.0 allows remote attackers to affect availability via vectors related to Engineering Communication Interface.","exploit_maturity":"No public exploit","published":"2016-04-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-3426","description":"Unspecified vulnerability in Oracle Java SE 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality via vectors related to JCE.","exploit_maturity":"No public exploit","published":"2016-04-21","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2016-0688","description":"Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via vectors related to Core Components.","exploit_maturity":"No public exploit","published":"2016-04-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-0671","description":"Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 12.1.2.0 allows remote attackers to affect confidentiality via vectors related to OSSL Module.","exploit_maturity":"No public exploit","published":"2016-04-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-0498","description":"Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.2.2, 6.1.3.0, and 6.2.0.0 allows local users to affect confidentiality via unknown vectors related to Install.","exploit_maturity":"No public exploit","published":"2016-01-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-0474","description":"Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote authenticated users to affect integrity via vectors related to PIA Core Technology.","exploit_maturity":"No public exploit","published":"2016-01-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-0473","description":"Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote authenticated users to affect integrity via unknown vectors related to Fluid Core.","exploit_maturity":"No public exploit","published":"2016-01-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-0454","description":"Unspecified vulnerability in the Oracle Mobile Application Servlet component in Oracle E-Business Suite 12.1 and 12.2 allows local users to affect confidentiality via vectors related to MWA Server Manager.","exploit_maturity":"No public exploit","published":"2016-01-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-0453","description":"Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 3.1.2 allows remote attackers to affect integrity via unknown vectors related to Embedded Server.","exploit_maturity":"No public exploit","published":"2016-01-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-0446","description":"Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 11.2.0.4, 12.1.0.4, and 12.1.0.5 allows local users to affect confidentiality via unknown vectors related to Agent Next Gen.","exploit_maturity":"No public exploit","published":"2016-01-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-0438","description":"Unspecified vulnerability in the Oracle Retail Point-of-Service component in Oracle Retail Applications 13.4, 14.0, and 14.1 allows local users to affect confidentiality via vectors related to Mobile POS, a different vulnerability than CVE-2016-0434, CVE-2016-0436, and CVE-2016-0437.","exploit_maturity":"No public exploit","published":"2016-01-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-0437","description":"Unspecified vulnerability in the Oracle Retail Point-of-Service component in Oracle Retail Applications 13.4, 14.0, and 14.1 allows local users to affect confidentiality via vectors related to Mobile POS, a different vulnerability than CVE-2016-0434, CVE-2016-0436, and CVE-2016-0438.","exploit_maturity":"No public exploit","published":"2016-01-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-0436","description":"Unspecified vulnerability in the Oracle Retail Point-of-Service component in Oracle Retail Applications 13.4, 14.0, and 14.1 allows local users to affect confidentiality via vectors related to Mobile POS, a different vulnerability than CVE-2016-0434, CVE-2016-0437, and CVE-2016-0438.","exploit_maturity":"No public exploit","published":"2016-01-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-0435","description":"Unspecified vulnerability in the Oracle Retail Point-of-Service component in Oracle Retail Applications 13.4, 14.0, and 14.1 allows local users to affect confidentiality and integrity via vectors related to Mobile POS.","exploit_maturity":"No public exploit","published":"2016-01-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-0434","description":"Unspecified vulnerability in the Oracle Retail Point-of-Service component in Oracle Retail Applications 13.4, 14.0, and 14.1 allows local users to affect confidentiality via vectors related to Mobile POS, a different vulnerability than CVE-2016-0436, CVE-2016-0437, and CVE-2016-0438.","exploit_maturity":"No public exploit","published":"2016-01-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-0432","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2015-4808, CVE-2015-6013, CVE-2015-6014, and CVE-2015-6015.","exploit_maturity":"No public exploit","published":"2016-01-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2016-0412","description":"Unspecified vulnerability in the PeopleSoft Enterprise SCM eProcurement component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect integrity via unknown vectors related to Manage Requisition Status.","exploit_maturity":"No public exploit","published":"2016-01-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-4926","description":"Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.1, and 12.2 allows remote attackers to affect integrity via vectors related to UIX.","exploit_maturity":"No public exploit","published":"2016-01-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-4924","description":"Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.1.1, 9.3.1.2, 9.3.2, and 9.3.3 allows remote authenticated users to affect integrity via vectors related to Security.","exploit_maturity":"No public exploit","published":"2016-01-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-4808","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via vectors related to Outside In Filters, a different vulnerability than CVE-2015-6013, CVE-2015-6014, CVE-2015-6015, and CVE-2016-0432.","exploit_maturity":"No public exploit","published":"2016-01-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-5304","description":"Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.5 does not properly authorize access to shut down the server, which allows remote authenticated users with the Monitor, Deployer, or Auditor role to cause a denial of service via unspecified vectors.","exploit_maturity":"No public exploit","published":"2015-12-16","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2015-4917","description":"Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 allows remote authenticated users to affect integrity via unknown vectors related to Security, a different vulnerability than CVE-2015-4892.","exploit_maturity":"No public exploit","published":"2015-10-22","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-4914","description":"Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 10.1.3.5, 11.1.1.7, 11.1.1.9, 12.1.2.0, and 12.1.3.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Web Listener.","exploit_maturity":"No public exploit","published":"2015-10-22","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-4892","description":"Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 allows remote authenticated users to affect integrity via unknown vectors related to Security, a different vulnerability than CVE-2015-4917.","exploit_maturity":"No public exploit","published":"2015-10-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-4878","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2015-4877.","exploit_maturity":"Working exploit published","published":"2015-10-21","resolved":"MITIGATION-CANDIDATE","severity":"Low"},
  {"cve_id":"CVE-2015-4877","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2015-4878.","exploit_maturity":"Working exploit published","published":"2015-10-21","resolved":"MITIGATION-CANDIDATE","severity":"Low"},
  {"cve_id":"CVE-2015-4865","description":"Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 12.1.3, 12.2.3, and 12.2.4 allows remote authenticated users to affect confidentiality via vectors related to Business Objects - BC4J.","exploit_maturity":"No public exploit","published":"2015-10-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-4846","description":"Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote authenticated users to affect confidentiality and integrity via vectors related to SQL Extensions.  NOTE: the previous information is from the October 2015 CPU. Oracle has not commented on third-party claims that this issue is a SQL injection vulnerability, which allows remote authenticated users to execute arbitrary SQL commands via a request involving the afamexts.sql SQL extension.","exploit_maturity":"No public exploit","published":"2015-10-21","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2015-4825","description":"Unspecified vulnerability in the PeopleSoft Enterprise FIN Expenses component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Expense Report General.","exploit_maturity":"No public exploit","published":"2015-10-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-4824","description":"Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.","exploit_maturity":"No public exploit","published":"2015-10-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-4823","description":"Unspecified vulnerability in the Hyperion Installation Technology component in Oracle Hyperion 11.1.2.3 allows local users to affect confidentiality via unknown vectors related to Essbase Rapid Deploy.","exploit_maturity":"No public exploit","published":"2015-10-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-4812","description":"Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.9 allows remote attackers to affect confidentiality via vectors related to OSSL Module.","exploit_maturity":"No public exploit","published":"2015-10-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-4811","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via vectors related to Outside In PDF Export SDKutside In PDF Export SDK, a different vulnerability than CVE-2015-4809.","exploit_maturity":"No public exploit","published":"2015-10-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-4809","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via vectors related to Outside In PDF Export SDK, a different vulnerability than CVE-2015-4811.","exploit_maturity":"No public exploit","published":"2015-10-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-4797","description":"Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.3 allows remote authenticated users to affect integrity via unknown vectors related to Security.","exploit_maturity":"No public exploit","published":"2015-10-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-2633","description":"Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 12.1.0.1 and 12.2.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Ops Center.","exploit_maturity":"No public exploit","published":"2015-10-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-1808","description":"Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users to cause a denial of service (improper plug-in and tool installation) via crafted update center data.","exploit_maturity":"No public exploit","published":"2015-10-16","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2015-4765","description":"Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 12.1.3, 12.2.3, and 12.2.4 allows remote authenticated users to affect integrity via vectors related to OAM Dashboard.","exploit_maturity":"No public exploit","published":"2015-07-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-4763","description":"Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Security.","exploit_maturity":"No public exploit","published":"2015-07-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-4744","description":"Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2; and the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.1.0, 12.1.2.0, and 12.1.3.0 allows remote attackers to affect integrity via unknown vectors related to Java Server Faces.","exploit_maturity":"No public exploit","published":"2015-07-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-4741","description":"Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 12.2.4 allows remote authenticated users to affect integrity via unknown vectors related to Dialog popup.","exploit_maturity":"No public exploit","published":"2015-07-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-4739","description":"Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2 allows remote authenticated users to affect integrity via unknown vectors related to Help screens.","exploit_maturity":"No public exploit","published":"2015-07-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-2660","description":"Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 allows remote authenticated users to affect confidentiality and integrity via vectors related to Oracle Agile PLM Framework.","exploit_maturity":"No public exploit","published":"2015-07-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-2649","description":"Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1, 8.22, and 15.0 allows remote authenticated users to affect confidentiality via vectors related to UIF Open UI.","exploit_maturity":"No public exploit","published":"2015-07-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-2645","description":"Unspecified vulnerability in the Oracle Web Applications Desktop Integrator component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote authenticated users to affect integrity via unknown vectors.","exploit_maturity":"No public exploit","published":"2015-07-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-2618","description":"Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote authenticated users to affect integrity via unknown vectors related to Input validation.","exploit_maturity":"No public exploit","published":"2015-07-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-2600","description":"Unspecified vulnerability in the Siebel Core - Server OM Svcs component in Oracle Siebel CRM 8.1.1, 8.2.2, and 15.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.","exploit_maturity":"No public exploit","published":"2015-07-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-2598","description":"Unspecified vulnerability in the mobile app in Oracle Business Intelligence Enterprise Edition in Oracle Fusion Middleware before 11.1.1.7.0 (11.6.39) allows remote authenticated users to affect integrity via unknown vectors related to Mobile - iPad.","exploit_maturity":"No public exploit","published":"2015-07-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-2592","description":"Unspecified vulnerability in the Hyperion Enterprise Performance Management Architect component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect integrity via unknown vectors related to Security, a different vulnerability than CVE-2015-2584.","exploit_maturity":"No public exploit","published":"2015-07-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-3586","description":"The default configuration for the Command Line Interface in Red Hat Enterprise Application Platform before 6.4.0 and WildFly (formerly JBoss Application Server) uses weak permissions for .jboss-cli-history, which allows local users to obtain sensitive information via unspecified vectors.","exploit_maturity":"No public exploit","published":"2015-04-21","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2015-2579","description":"Unspecified vulnerability in the Oracle Health Sciences Argus Safety component in Oracle Health Sciences Applications 8.0 allows local users to affect confidentiality via vectors related to BIP Installer.","exploit_maturity":"No public exploit","published":"2015-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-0504","description":"Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6 and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Error Messages.","exploit_maturity":"No public exploit","published":"2015-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-0493","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.1, 8.5.0, and 8.5.1 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2015-0474.","exploit_maturity":"Working exploit published","published":"2015-04-16","resolved":"MITIGATION-CANDIDATE","severity":"Low"},
  {"cve_id":"CVE-2015-0489","description":"Unspecified vulnerability in the Application Management Pack for Oracle E-Business Suite component in Oracle E-Business Suite AMP 121030 and 121020 allows local users to affect confidentiality via vectors related to EBS Plugin.","exploit_maturity":"No public exploit","published":"2015-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-0485","description":"Unspecified vulnerability in the PeopleSoft Enterprise SCM Strategic Sourcing component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.","exploit_maturity":"No public exploit","published":"2015-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-0474","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.1, 8.5.0, and 8.5.1 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2015-0493.","exploit_maturity":"Working exploit published","published":"2015-04-16","resolved":"MITIGATION-CANDIDATE","severity":"Low"},
  {"cve_id":"CVE-2015-0472","description":"Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 and 8.54 allows remote authenticated users to affect integrity via vectors related to PIA Core Technology, a different vulnerability than CVE-2015-0487.","exploit_maturity":"No public exploit","published":"2015-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-0453","description":"Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 and 8.54 allows remote attackers to affect confidentiality via vectors related to PORTAL.","exploit_maturity":"No public exploit","published":"2015-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-0451","description":"Unspecified vulnerability in the Oracle OpenSSO component in Oracle Fusion Middleware 3.0-04 allows remote authenticated users to affect confidentiality via vectors related to OpenSSO Web Agents.","exploit_maturity":"No public exploit","published":"2015-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-0005","description":"PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2 and JBoss BRMS before 6.0.3 roll up patch 2, allows remote authenticated users to read and modify the application sever configuration and state by deploying a crafted application.","exploit_maturity":"No public exploit","published":"2015-02-20","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-7827","description":"The org.jboss.security.plugins.mapping.JBossMappingManager implementation in JBoss Security in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 uses the default security domain when a security domain is undefined, which allows remote authenticated users to bypass intended access restrictions by leveraging credentials on the default domain for a role that is also on the application domain.","exploit_maturity":"No public exploit","published":"2015-02-13","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-0416","description":"Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.3 allows remote authenticated users to affect integrity via unknown vectors related to Roles \u0026 Privileges.","exploit_maturity":"No public exploit","published":"2015-01-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-0414","description":"Unspecified vulnerability in the Oracle SOA Suite component in Oracle Fusion Middleware 11.1.1.7 and 12.1.3.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Fabric Layer.","exploit_maturity":"No public exploit","published":"2015-01-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-0413","description":"Unspecified vulnerability in Oracle Java SE 7u72 and 8u25 allows local users to affect integrity via unknown vectors related to Serviceability.","exploit_maturity":"No public exploit","published":"2015-01-21","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2015-0389","description":"Unspecified vulnerability in the Oracle OpenSSO component in Oracle Fusion Middleware 8.0 Update 2 Patch 5 allows remote authenticated users to affect integrity via vectors related to SAML, a different vulnerability than CVE-2014-6592.","exploit_maturity":"No public exploit","published":"2015-01-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-0384","description":"Unspecified vulnerability in the Siebel Public Sector component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect integrity via unknown vectors related to Public Sector Portal.","exploit_maturity":"No public exploit","published":"2015-01-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2015-0364","description":"Unspecified vulnerability in the Siebel Core - EAI component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect availability via unknown vectors related to Integration Business Services.","exploit_maturity":"No public exploit","published":"2015-01-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-6599","description":"Unspecified vulnerability in the Siebel Core - Common Components component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Email.","exploit_maturity":"No public exploit","published":"2015-01-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-6592","description":"Unspecified vulnerability in the Oracle OpenSSO component in Oracle Fusion Middleware 8.0 Update 2 Patch 5 allows remote authenticated users to affect integrity via vectors related to SAML, a different vulnerability than CVE-2015-0389.","exploit_maturity":"No public exploit","published":"2015-01-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-6591","description":"Unspecified vulnerability in the Java SE component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to 2D, a different vulnerability than CVE-2014-6585.","exploit_maturity":"No public exploit","published":"2015-01-21","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2014-6585","description":"Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to 2D, a different vulnerability than CVE-2014-6591.","exploit_maturity":"No public exploit","published":"2015-01-21","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2014-6525","description":"Unspecified vulnerability in the Oracle Web Applications Desktop Integrator component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote authenticated users to affect integrity via unknown vectors related to Templates.","exploit_maturity":"No public exploit","published":"2015-01-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-4279","description":"Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 allows remote authenticated users to affect integrity via vectors related to PIA Core Technology.","exploit_maturity":"No public exploit","published":"2015-01-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-0059","description":"JBoss SX and PicketBox, as used in Red Hat JBoss Enterprise Application Platform (EAP) before 6.2.3, use world-readable permissions on audit.log, which allows local users to obtain sensitive information by reading this file.","exploit_maturity":"No public exploit","published":"2014-11-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-0228","description":"Apache Hive before 0.13.1, when in SQL standards based authorization mode, does not properly check the file permissions for (1) import and (2) export statements, which allows remote authenticated users to obtain sensitive information via a crafted URI.","exploit_maturity":"No public exploit","published":"2014-11-16","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2014-2068","description":"The doIndex function in hudson/util/RemotingDiagnostics.java in CloudBees Jenkins before 1.551 and LTS before 1.532.2 allows remote authenticated users with the ADMINISTER permission to obtain sensitive information via vectors related to heapDump.","exploit_maturity":"No public exploit","published":"2014-10-17","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2014-6558","description":"Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20; Java SE Embedded 7u60; and JRockit R27.8.3 and JRockit R28.3.3 allows remote attackers to affect integrity via unknown vectors related to Security.","exploit_maturity":"No public exploit","published":"2014-10-15","resolved":"MITIGATION-CANDIDATE","severity":"Low"},
  {"cve_id":"CVE-2014-6543","description":"Unspecified vulnerability in the Agile PLM component in Oracle Supply Chain Products Suite 9.3.3 allows remote authenticated users to affect confidentiality and integrity via vectors related to ITEM (Item \u0026 BOM).","exploit_maturity":"No public exploit","published":"2014-10-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-6536","description":"Unspecified vulnerability in the Agile PLM component in Oracle Supply Chain Products Suite 9.3.3 allows remote authenticated users to affect integrity via unknown vectors related to Security.","exploit_maturity":"No public exploit","published":"2014-10-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-6502","description":"Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20, and Java SE Embedded 7u60, allows remote attackers to affect integrity via unknown vectors related to Libraries.","exploit_maturity":"No public exploit","published":"2014-10-15","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2014-6487","description":"Unspecified vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote authenticated users to affect integrity via unknown vectors related to End User Self Service.","exploit_maturity":"No public exploit","published":"2014-10-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-6475","description":"Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52, 8.53, and 8.54 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.","exploit_maturity":"No public exploit","published":"2014-10-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-4770","description":"Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 allows remote authenticated administrators to inject arbitrary web script or HTML via a crafted URL.","exploit_maturity":"No public exploit","published":"2014-09-23","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-3075","description":"Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.0.x allows remote authenticated users to inject arbitrary web script or HTML via an uploaded file.","exploit_maturity":"No public exploit","published":"2014-09-04","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-4251","description":"Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.7.0 and 12.1.2.0 allows remote authenticated users to affect integrity via vectors related to plugin 1.1.","exploit_maturity":"No public exploit","published":"2014-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-4250","description":"Unspecified vulnerability in the Siebel Core - Server OM Frwks component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Object Manager.","exploit_maturity":"No public exploit","published":"2014-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-4248","description":"Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, and 12.2.3 allows local users to affect confidentiality via unknown vectors related to Logging.","exploit_maturity":"No public exploit","published":"2014-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-4246","description":"Unspecified vulnerability in the Hyperion Analytic Provider Services component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect confidentiality via vectors related to SVP.","exploit_maturity":"No public exploit","published":"2014-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-4235","description":"Unspecified vulnerability in the Oracle iStore component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, and 12.2.3 allows remote authenticated users to affect integrity via unknown vectors.","exploit_maturity":"No public exploit","published":"2014-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-4222","description":"Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.7.0 and 12.1.2.0 allows remote authenticated users to affect confidentiality via vectors related to plugin 1.1.","exploit_maturity":"No public exploit","published":"2014-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-4206","description":"Unspecified vulnerability in the Hyperion Enterprise Performance Management Architect component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows local users to affect integrity and availability via unknown vectors related to Data Synchronizer.","exploit_maturity":"No public exploit","published":"2014-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-4204","description":"Unspecified vulnerability in the PeopleSoft Enterprise PT PeopleTools component in Oracle PeopleSoft Products 8.53 allows remote authenticated users to affect integrity via vectors related to PIA Core Technology.","exploit_maturity":"No public exploit","published":"2014-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-2495","description":"Unspecified vulnerability in the PeopleSoft Enterprise SCM Purchasing component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Purchasing.","exploit_maturity":"No public exploit","published":"2014-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-2485","description":"Unspecified vulnerability in the Siebel Core - EAI component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows local users to affect confidentiality via unknown vectors related to Integration Business Services.","exploit_maturity":"No public exploit","published":"2014-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-6372","description":"The Subversion plugin before 1.54 for Jenkins stores credentials using base64 encoding, which allows local users to obtain passwords and SSH private keys by reading a subversion.credentials file.","exploit_maturity":"No public exploit","published":"2014-05-08","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2013-6323","description":"Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0.0.9, and 8.5.x before 8.5.5.2, and WebSphere Virtual Enterprise 7.x before 7.0.0.5, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.","exploit_maturity":"No public exploit","published":"2014-05-01","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-0085","description":"JBoss Fuse did not enable encrypted passwords by default in its usage of Apache Zookeeper. This permitted sensitive information disclosure via logging to local users. Note: this description has been updated; previous text mistakenly identified the source of the flaw as Zookeeper. Previous text: Apache Zookeeper logs cleartext admin passwords, which allows local users to obtain sensitive information by reading the log.","exploit_maturity":"No public exploit","published":"2014-04-17","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2014-2467","description":"Unspecified vulnerability in the Oracle Agile PLM Framework component in Oracle Supply Chain Products Suite 9.3.3 allows remote authenticated users to affect integrity via unknown vectors related to Security, a different vulnerability than CVE-2014-2445.","exploit_maturity":"No public exploit","published":"2014-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-2466","description":"Unspecified vulnerability in the Oracle Agile PLM Framework component in Oracle Supply Chain Products Suite 9.3.3 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.","exploit_maturity":"No public exploit","published":"2014-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-2464","description":"Unspecified vulnerability in the Oracle Agile PLM Framework component in Oracle Supply Chain Products Suite 9.3.3.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.","exploit_maturity":"No public exploit","published":"2014-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-2459","description":"Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.3.2 and 6.3.3 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Security.","exploit_maturity":"No public exploit","published":"2014-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-2445","description":"Unspecified vulnerability in the Oracle Agile PLM Framework component in Oracle Supply Chain Products Suite 9.3.3 allows remote authenticated users to affect integrity via unknown vectors related to Security, a different vulnerability than CVE-2014-2467.","exploit_maturity":"No public exploit","published":"2014-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-2398","description":"Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and JRockit R27.8.1 and R28.3.1 allows remote authenticated users to affect integrity via unknown vectors related to Javadoc.","exploit_maturity":"No public exploit","published":"2014-04-16","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2014-0465","description":"Unspecified vulnerability in the Oracle OpenSSO component in Oracle Fusion Middleware 8.0 Update 2 Patch 5 allows remote authenticated users to affect integrity via unknown vectors related to Admin Console.","exploit_maturity":"No public exploit","published":"2014-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-2033","description":"Cross-site scripting (XSS) vulnerability in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1.466.x before 1.466.14.1 and 1.480.x before 1.480.4.1 allows remote authenticated users with write permission to inject arbitrary web script or HTML via unspecified vectors.","exploit_maturity":"No public exploit","published":"2014-04-10","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2012-0032","description":"Red Hat JBoss Operations Network (JON) before 3.0.1 uses 0777 permissions for the root directory when installing a remote client, which allows local users to read or modify subdirectories and files within the root directory, as demonstrated by obtaining JON credentials.","exploit_maturity":"No public exploit","published":"2014-04-01","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2011-4573","description":"Red Hat JBoss Operations Network (JON) before 2.4.2 does not properly enforce \"modify resource\" permissions for remote authenticated users when deleting a plug-in configuration update from the group connection properties history, which prevents such activities from being recorded in the audit trail.","exploit_maturity":"No public exploit","published":"2014-04-01","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2014-2067","description":"Cross-site scripting (XSS) vulnerability in java/hudson/model/Cause.java in Jenkins before 1.551 and LTS before 1.532.2 allows remote authenticated users to inject arbitrary web script or HTML via a \"remote cause note.\"","exploit_maturity":"No public exploit","published":"2014-03-01","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2014-0058","description":"The security audit functionality in Red Hat JBoss Enterprise Application Platform (EAP) 6.x before 6.2.1 logs request parameters in plaintext, which might allow local users to obtain passwords by reading the log files.","exploit_maturity":"No public exploit","published":"2014-02-26","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-0346","description":"Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor has stated \"The tomcat log directory does not contain any sensitive information.\"","exploit_maturity":"No public exploit","published":"2014-02-15","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2014-0018","description":"Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.0 and JBoss WildFly Application Server, when run under a security manager, do not properly restrict access to the Modular Service Container (MSC) service registry, which allows local users to modify the server via a crafted deployment.","exploit_maturity":"No public exploit","published":"2014-02-14","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2012-3427","description":"EC2 Amazon Machine Image (AMI) in JBoss Enterprise Application Platform (EAP) 5.1.2 uses 755 permissions for /var/cache/jboss-ec2-eap/, which allows local users to read sensitive information such as Amazon Web Services (AWS) credentials by reading files in the directory.","exploit_maturity":"No public exploit","published":"2014-02-02","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-2192","description":"The RPC protocol implementation in Apache Hadoop 2.x before 2.0.6-alpha, 0.23.x before 0.23.9, and 1.x before 1.2.1, when the Kerberos security features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information by forcing a downgrade to simple authentication.","exploit_maturity":"No public exploit","published":"2014-01-24","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2013-6725","description":"Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server 7.x before 7.0.0.31, 8.0.x before 8.0.0.8, and 8.5.x before 8.5.5.2 allows remote authenticated administrators to inject arbitrary web script or HTML via a crafted URL.","exploit_maturity":"No public exploit","published":"2014-01-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-6330","description":"IBM WebSphere Application Server 7.x before 7.0.0.31, when simpleFileServlet static file caching is enabled, allows remote authenticated users to obtain sensitive information via unspecified vectors.","exploit_maturity":"No public exploit","published":"2014-01-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-0444","description":"Unspecified vulnerability in the Oracle AutoVue Electro-Mechanical Professional component in Oracle Supply Chain Products Suite 20.1.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Web General, a different vulnerability than CVE-2013-5868 and CVE-2013-5871.","exploit_maturity":"No public exploit","published":"2014-01-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-0383","description":"Unspecified vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.2.0 and 11.1.2.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Identity Console.","exploit_maturity":"No public exploit","published":"2014-01-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-0381","description":"Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52 and 8.53 allows remote attackers to affect integrity via vectors related to PIA Core Technology, a different vulnerability than CVE-2014-0445.","exploit_maturity":"No public exploit","published":"2014-01-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-0371","description":"Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0.x, 7.3.1.x, 12.2.0, 12.2.1, and 12.2.2 allows remote authenticated users to affect integrity via unknown vectors related to DM Others.","exploit_maturity":"No public exploit","published":"2014-01-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2014-0370","description":"Unspecified vulnerability in the Siebel Life Sciences component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect availability via unknown vectors related to Clinical Trip Report.","exploit_maturity":"No public exploit","published":"2014-01-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-5874","description":"Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, and 12.2.2 allows local users to affect confidentiality via unknown vectors related to Logging.","exploit_maturity":"No public exploit","published":"2014-01-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-5871","description":"Unspecified vulnerability in the Oracle AutoVue Electro-Mechanical Professional component in Oracle Supply Chain Products Suite 20.1.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Web General, a different vulnerability than CVE-2013-5868 and CVE-2014-0444.","exploit_maturity":"No public exploit","published":"2014-01-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-5868","description":"Unspecified vulnerability in the Oracle AutoVue Electro-Mechanical Professional component in Oracle Supply Chain Products Suite 20.1.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Web General, a different vulnerability than CVE-2013-5871 and CVE-2014-0444.","exploit_maturity":"No public exploit","published":"2014-01-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-5808","description":"Unspecified vulnerability in the Oracle iPlanet Web Proxy Server component in Oracle Fusion Middleware 4.0 allows remote attackers to affect confidentiality via unknown vectors related to Administration.","exploit_maturity":"No public exploit","published":"2014-01-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-4452","description":"Red Hat JBoss Operations Network 3.1.2 uses world-readable permissions for the (1) server and (2) agent configuration files, which allows local users to obtain authentication credentials and other unspecified sensitive information by reading these files.","exploit_maturity":"No public exploit","published":"2013-12-24","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-5763","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.0 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Maintenance.  NOTE: the original disclosure of this issue erroneously mapped it to CVE-2013-3624.","exploit_maturity":"No public exploit","published":"2013-12-12","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-6374","description":"Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.5.1 for Jenkins allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.","exploit_maturity":"No public exploit","published":"2013-11-25","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2013-5418","description":"Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.","exploit_maturity":"No public exploit","published":"2013-11-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-5414","description":"The migration functionality in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 does not properly support the distinction between the admin role and the adminsecmanager role, which allows remote authenticated users to gain privileges in opportunistic circumstances by accessing resources in between a migration and a role evaluation.","exploit_maturity":"No public exploit","published":"2013-11-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-2102","description":"The default configuration of Red Hat JBoss Portal before 6.1.0 enables the JGroups diagnostics service with no authentication when a JGroups channel is started, which allows remote attackers to obtain sensitive information (diagnostics) by accessing the service.","exploit_maturity":"No public exploit","published":"2013-10-28","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2012-4572","description":"Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the implementation of a custom authorization module for a new application when an implementation is already loaded and the modules share class names, which allows local users to control certain applications' authorization decisions via a crafted application.","exploit_maturity":"No public exploit","published":"2013-10-28","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-4373","description":"The storeFiles method in JPADriftServerBean in Red Hat JBoss Operations Network (JON) 3.1.2 allows local users to load arbitrary drift files into a server by writing the files to the temporary directory that is used to unpack zip files.","exploit_maturity":"No public exploit","published":"2013-10-24","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2013-4293","description":"The server in Red Hat JBoss Operations Network (JON) 3.1.2 logs passwords in plaintext, which allows local users to obtain sensitive information by reading the log files.","exploit_maturity":"No public exploit","published":"2013-10-24","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2013-5857","description":"Unspecified vulnerability in the Oracle Health Sciences InForm component in Oracle Industry Applications 4.5 SP3, 4.5 SP3a-k, 4.6 SP0, 4.6 SP0a-c, 4.6 SP1, 4.6 SP1a-c, 4.6 SP2, 4.6 SP2a-c, 5.0 SP0, 5.0 SP0a, 5.0 SP1, and 5.0 SP1a-b allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Web.","exploit_maturity":"No public exploit","published":"2013-10-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-5856","description":"Unspecified vulnerability in the Oracle Health Sciences InForm component in Oracle Industry Applications 4.5 SP3, 4.5 SP3a-k, 4.6 SP0, 4.6 SP0a-c, 4.6 SP1, 4.6 SP1a-c, 4.6 SP2, 4.6 SP2a-c, 5.0 SP0, 5.0 SP0a, 5.0 SP1, 5.0 SP1a-b, 5.5 SP0, 5.5 SP0b, 5.5.1, and 6.0.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Web.","exploit_maturity":"No public exploit","published":"2013-10-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-5854","description":"Unspecified vulnerability in Oracle Java SE 7u40 and earlier and JavaFX 2.2.40 and earlier allows remote attackers to affect confidentiality via unknown vectors.","exploit_maturity":"No public exploit","published":"2013-10-16","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2013-5837","description":"Unspecified vulnerability in the Oracle Health Sciences InForm component in Oracle Industry Applications 4.6 SP0, 4.6 SP0a-c, 4.6 SP1, 4.6 SP1a-c, 4.6 SP2, 4.6 SP2a-c, 5.0 SP0, 5.0 SP0a, 5.0 SP1, 5.0 SP1a-b, 5.0.3, and 5.0.4 allows remote authenticated users to affect confidentiality via unknown vectors related to Cognos.","exploit_maturity":"No public exploit","published":"2013-10-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-5811","description":"Unspecified vulnerability in the Oracle Health Sciences InForm component in Oracle Industry Applications 4.5 SP3, 4.5 SP3a-k, 4.6 SP0, 4.6 SP0a-c, 4.6 SP1, 4.6 SP1a-c, 4.6 SP2, 4.6 SP2a-c, 5.0 SP0, 5.0 SP0a, 5.0 SP1, and 5.0 SP1a-b allows remote authenticated users to affect confidentiality via unknown vectors related to Web.","exploit_maturity":"No public exploit","published":"2013-10-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-5797","description":"Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and JavaFX 2.2.40 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Javadoc.","exploit_maturity":"No public exploit","published":"2013-10-16","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2013-5791","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.0 and 8.4.1 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters.  NOTE: the previous information is from the October 2013 CPU. Oracle has not commented on claims from a third party that the issue is a stack-based buffer overflow in the Microsoft Access 1.x parser in vsacs.dll before 8.4.0.108 and before 8.4.1.52, which allows attackers to execute arbitrary code via a long field (aka column) name.","exploit_maturity":"Working exploit published","published":"2013-10-16","resolved":"MITIGATION-CANDIDATE","severity":"Low"},
  {"cve_id":"CVE-2013-5772","description":"Unspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u40 and earlier and Java SE 6u60 and earlier allows remote attackers to affect integrity via unknown vectors related to jhat.","exploit_maturity":"No public exploit","published":"2013-10-16","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2013-5762","description":"Unspecified vulnerability in the Oracle Siebel CTMS component in Oracle Industry Applications 8.1.1.x allows local users to affect confidentiality and availability via unknown vectors related to SC-OC Integration.","exploit_maturity":"No public exploit","published":"2013-10-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-3836","description":"Unspecified vulnerability in the Oracle Web Cache component in Oracle Fusion Middleware 11.1.1.6 and 11.1.1.7 allows remote authenticated users to affect confidentiality via vectors related to ESI/Partial Page Caching.","exploit_maturity":"No public exploit","published":"2013-10-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-5679","description":"The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ESAPI) for Java 2.x before 2.1.0 does not properly resist tampering with serialized ciphertext, which makes it easier for remote attackers to bypass intended cryptographic protection mechanisms via an attack against authenticity in the default configuration, involving a null MAC and a zero MAC length.","exploit_maturity":"No public exploit","published":"2013-09-30","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2013-1921","description":"PicketBox, as used in Red Hat JBoss Enterprise Application Platform before 6.1.1, allows local users to obtain the admin encryption key by reading the Vault data file.","exploit_maturity":"No public exploit","published":"2013-09-28","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2013-4005","description":"Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified fields.","exploit_maturity":"No public exploit","published":"2013-08-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-4004","description":"Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 8.0 before 8.0.0.7 and 8.5 before 8.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.","exploit_maturity":"No public exploit","published":"2013-08-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-2976","description":"The Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.0 does not properly perform caching, which allows local users to obtain sensitive information via unspecified vectors.","exploit_maturity":"No public exploit","published":"2013-08-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-0597","description":"Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.29, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.0, when OAuth is used, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.","exploit_maturity":"No public exploit","published":"2013-08-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-3803","description":"Unspecified vulnerability in the Hyperion BI+ component in Oracle Hyperion 11.1.1.3, 11.1.1.4.107 and earlier, 11.1.2.1.129 and earlier, and 11.1.2.2.305 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Intelligence Service.","exploit_maturity":"Working exploit published","published":"2013-07-17","resolved":"MITIGATION-CANDIDATE","severity":"Low"},
  {"cve_id":"CVE-2013-3749","description":"Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote authenticated users to affect confidentiality via unknown vectors related to Logging.  NOTE: the previous information is from the July 2013 CPU. Oracle has not commented on claims from a third party that the issue is due to storage of credentials in the (1) FND_LOG_MESSAGES database table or (2) log files by \"native login pages.\"","exploit_maturity":"No public exploit","published":"2013-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-2451","description":"Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier, and OpenJDK 7, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Networking.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to improper enforcement of exclusive port binds when running on Windows, which allows attackers to bind to ports that are already in use.","exploit_maturity":"No public exploit","published":"2013-06-18","resolved":"MITIGATION-CANDIDATE","severity":"Low"},
  {"cve_id":"CVE-2013-1500","description":"Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows local users to affect confidentiality and integrity via unknown vectors related to 2D.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to weak permissions for shared memory.","exploit_maturity":"No public exploit","published":"2013-06-18","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2013-0540","description":"IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.0.2, when SSL is not enabled, does not properly validate authentication cookies, which allows remote authenticated users to bypass intended access restrictions via an HTTP session.","exploit_maturity":"No public exploit","published":"2013-04-24","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-2423","description":"Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from the original researcher that this vulnerability allows remote attackers to bypass permission checks by the MethodHandles method and modify arbitrary public final fields using reflection and type confusion, as demonstrated using integer and double fields to disable the security manager.","exploit_maturity":"Exploited in the wild","published":"2013-04-17","resolved":"MITIGATION-CANDIDATE","severity":"Low"},
  {"cve_id":"CVE-2013-2415","description":"Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows local users to affect confidentiality via vectors related to JAX-WS.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to \"processing of MTOM attachments\" and the creation of temporary files with weak permissions.","exploit_maturity":"No public exploit","published":"2013-04-17","resolved":"MITIGATION-CANDIDATE","severity":"Low"},
  {"cve_id":"CVE-2013-2406","description":"Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote authenticated users to affect integrity via vectors related to PIA Core Technology.","exploit_maturity":"No public exploit","published":"2013-04-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-2403","description":"Unspecified vulnerability in the Siebel Enterprise Application Integration component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Web Services, a different vulnerability than CVE-2013-0416.","exploit_maturity":"No public exploit","published":"2013-04-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-2401","description":"Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote authenticated users to affect integrity via unknown vectors related to Portal.","exploit_maturity":"No public exploit","published":"2013-04-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-2393","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 and 8.4.0 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters.","exploit_maturity":"No public exploit","published":"2013-04-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-2387","description":"Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 4.1.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to BASE.","exploit_maturity":"No public exploit","published":"2013-04-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-2382","description":"Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 12.0.1 allows local users to affect confidentiality via vectors related to BASE.","exploit_maturity":"No public exploit","published":"2013-04-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-2379","description":"Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 12.0.1 allows remote authenticated users to affect integrity via unknown vectors related to RT.","exploit_maturity":"No public exploit","published":"2013-04-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-2377","description":"Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 4.1.0 allows remote authenticated users to affect confidentiality via unknown vectors related to My Services.","exploit_maturity":"No public exploit","published":"2013-04-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-1560","description":"Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 4.1.0 allows remote authenticated users to affect confidentiality via vectors related to BASE, a different vulnerability than CVE-2013-2385.","exploit_maturity":"No public exploit","published":"2013-04-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-1556","description":"Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 12.0.1 allows remote authenticated users to affect integrity via vectors related to OTH.","exploit_maturity":"No public exploit","published":"2013-04-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-1549","description":"Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 5.3.3, 6.0.1, and 12.0.0 allows remote authenticated users to affect integrity via vectors related to BASE.","exploit_maturity":"No public exploit","published":"2013-04-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-1547","description":"Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 12.0.1 allows remote authenticated users to affect integrity via vectors related to BASE.","exploit_maturity":"No public exploit","published":"2013-04-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-1546","description":"Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 3.1.0 and 5.0.2 through 12.0.1 allows local users to affect confidentiality via vectors related to BASE.","exploit_maturity":"No public exploit","published":"2013-04-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-1541","description":"Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 3.1.0, 5.0.2 through 5.0.5, and 5.3.0 through 5.3.4 allows remote authenticated users to affect confidentiality via vectors related to BASE.","exploit_maturity":"No public exploit","published":"2013-04-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-1539","description":"Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 3.1.0, 5.0.2 through 5.0.5, and 5.3.0 through 5.3.4 allows remote authenticated users to affect confidentiality via vectors related to CTF.","exploit_maturity":"No public exploit","published":"2013-04-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-1517","description":"Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect confidentiality via unknown vectors related to Diagnostics.","exploit_maturity":"No public exploit","published":"2013-04-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-1503","description":"Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote authenticated users to affect integrity via unknown vectors related to Content Server.","exploit_maturity":"No public exploit","published":"2013-04-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-4303","description":"Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 11.1.1.6.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Content Server.","exploit_maturity":"No public exploit","published":"2013-04-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-0248","description":"The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.","exploit_maturity":"No public exploit","published":"2013-03-15","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2013-0158","description":"Unspecified vulnerability in Jenkins before 1.498, Jenkins LTS before 1.480.2, and Jenkins Enterprise 1.447.x before 1.447.6.1 and 1.466.x before 1.466.12.1, when a slave is attached and anonymous read access is enabled, allows remote attackers to obtain the master cryptographic key via unknown vectors.","exploit_maturity":"No public exploit","published":"2013-02-24","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2012-6074","description":"Cross-site scripting (XSS) vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x before 1.447.4.1, and 1.466.x before 1.466.10.1 allows remote authenticated users with write access to inject arbitrary web script or HTML via unspecified vectors.","exploit_maturity":"No public exploit","published":"2013-02-24","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2013-0218","description":"The GUI installer in JBoss Enterprise Application Platform (EAP) and Enterprise Web Platform (EWP) 5.2.0 and possibly 5.1.2 uses world-readable permissions for the auto-install XML file, which allows local users to obtain the administrator password and the sucker password by reading this file.","exploit_maturity":"No public exploit","published":"2013-02-05","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2012-0034","description":"The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5.1.2 and 5.2.0, Web Platform (EWP) 5.1.2 and 5.2.0, and BRMS Platform before 5.3.1 logs the username and password in cleartext when an exception is thrown, which allows local users to obtain sensitive information by reading the log file.","exploit_maturity":"No public exploit","published":"2013-02-05","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2013-0390","description":"Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote authenticated users to affect integrity via unknown vectors related to Bookmarkable Pages.","exploit_maturity":"No public exploit","published":"2013-01-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2013-0370","description":"Unspecified vulnerability in the Oracle Agile PLM Framework component in Oracle Supply Chain Products Suite 9.3.1.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.","exploit_maturity":"No public exploit","published":"2013-01-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-3192","description":"Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Products 8.51 and 8.52 allows remote authenticated users to affect integrity, related to Rich Text Editor (RTE).","exploit_maturity":"No public exploit","published":"2013-01-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-1678","description":"Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 8.98, 9.1, and 24 allows remote authenticated users to affect confidentiality, related to Enterprise Infrastructure SEC.","exploit_maturity":"No public exploit","published":"2013-01-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-4534","description":"org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the connection during the reading of a response.","exploit_maturity":"No public exploit","published":"2012-12-19","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-2377","description":"JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups channel, which allows remote attackers in adjacent networks to read diagnostics information via a crafted IP multicast.","exploit_maturity":"No public exploit","published":"2012-11-23","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2012-5065","description":"Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2, and 11.1.1.6.0 allows local users to affect integrity via unknown vectors related to ImagePicker.","exploit_maturity":"No public exploit","published":"2012-10-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-5064","description":"Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0, 10.0.2, 10.1.0, 10.2.0, 10.2.2, 10.3.0, 10.5.0, and 11.0.0 through 11.2.0 allows remote authenticated users to affect confidentiality, related to BASE.","exploit_maturity":"No public exploit","published":"2012-10-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-3227","description":"Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0, 10.0.2, 10.1.0, 10.2.0, 10.2.2, 10.3.0, 10.5.0, and 11.0.0 through 11.2.0 allows remote authenticated users to affect integrity, related to BASE, a different vulnerability than CVE-2012-3141.","exploit_maturity":"No public exploit","published":"2012-10-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-3225","description":"Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.3.0 through 5.3.4 allows remote authenticated users to affect confidentiality and integrity, related to BASE.","exploit_maturity":"No public exploit","published":"2012-10-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-3224","description":"Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.1.0, 5.2.0, and 5.3.0 through 5.3.4 allows remote authenticated users to affect confidentiality, related to BASE.","exploit_maturity":"No public exploit","published":"2012-10-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-3223","description":"Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.0.5, 5.1.0, 5.2.0, 5.3.0 through 5.3.4, and 6.0.1 allows remote authenticated users to affect confidentiality, related to BASE.","exploit_maturity":"No public exploit","published":"2012-10-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-3217","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7.0 allows context-dependent attackers to affect availability, related to Outside In HTML Export SDK.","exploit_maturity":"No public exploit","published":"2012-10-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-3214","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7.0 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters.","exploit_maturity":"No public exploit","published":"2012-10-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-3193","description":"Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 10.3.4.2, 11.1.1.5.0, 11.1.1.6.0, and 11.1.1.6.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Administration.","exploit_maturity":"No public exploit","published":"2012-10-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-3191","description":"Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect availability via unknown vectors related to Data Mover.","exploit_maturity":"No public exploit","published":"2012-10-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-3188","description":"Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50 and 8.51 allows remote authenticated users to affect integrity, related to PIA Core Technology.","exploit_maturity":"No public exploit","published":"2012-10-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-3179","description":"Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect integrity via unknown vectors related to Tree Manager.","exploit_maturity":"No public exploit","published":"2012-10-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-3176","description":"Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52 allows remote authenticated users to affect integrity via unknown vectors related to Panel Processor.","exploit_maturity":"No public exploit","published":"2012-10-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-3164","description":"Unspecified vulnerability in the Oracle Marketing component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote authenticated users to affect integrity via unknown vectors related to Publish Item.","exploit_maturity":"No public exploit","published":"2012-10-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-5085","description":"Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier allows remote authenticated users to have an unspecified impact via unknown vectors related to Networking.  NOTE: the Oracle CPU states that this issue has a 0.0 CVSS score. If so, then this is not a vulnerability and this issue should not be included in CVE.","exploit_maturity":"No public exploit","published":"2012-10-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-5077","description":"Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Security.","exploit_maturity":"No public exploit","published":"2012-10-16","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2012-3216","description":"Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Libraries.","exploit_maturity":"No public exploit","published":"2012-10-16","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2012-3162","description":"Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows local users to affect confidentiality, related to MDS loading.","exploit_maturity":"No public exploit","published":"2012-10-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-3157","description":"Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.0.5, 5.1.0, 5.2.0, 5.3.0 through 5.3.4, 6.0.1, 6.2.0, and 12 allows remote authenticated users to affect integrity, related to BASE.","exploit_maturity":"No public exploit","published":"2012-10-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-3148","description":"Unspecified vulnerability in the Oracle Field Service component in Oracle E-Business Suite 12.1.3 allows remote authenticated users to affect integrity, related to Wireless/WAP upload.","exploit_maturity":"No public exploit","published":"2012-10-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-3145","description":"Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.0.5, 5.1.0, 5.2.0, 5.3.0 through 5.3.4, and 6.2.0 allows local users to affect confidentiality, related to BASE.","exploit_maturity":"No public exploit","published":"2012-10-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-3142","description":"Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.5, 5.1.0, 5.2.0, and 5.3.0 through 5.3.4 allows remote authenticated users to affect confidentiality, related to BASE.","exploit_maturity":"No public exploit","published":"2012-10-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-0108","description":"Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10.1.3.6.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Web, a different vulnerability than CVE-2012-0086 and CVE-2012-0095.","exploit_maturity":"No public exploit","published":"2012-10-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-0095","description":"Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10.1.3.6.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Web, a different vulnerability than CVE-2012-0086 and CVE-2012-0108.","exploit_maturity":"No public exploit","published":"2012-10-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-0092","description":"Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10.1.3.6.0 allows remote authenticated users to affect integrity via unknown vectors related to Web, a different vulnerability than CVE-2012-0090.","exploit_maturity":"No public exploit","published":"2012-10-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-0090","description":"Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10.1.3.6.0 allows remote authenticated users to affect integrity via unknown vectors related to Web, a different vulnerability than CVE-2012-0092.","exploit_maturity":"No public exploit","published":"2012-10-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-0086","description":"Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10.1.3.6.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Web, a different vulnerability than CVE-2012-0095 and CVE-2012-0108.","exploit_maturity":"No public exploit","published":"2012-10-16","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-3311","description":"IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 on z/OS, in certain configurations involving Federated Repositories for IIOP connections and Optimized Local Adapters, does not perform CBIND checks, which allows local users to bypass intended access restrictions, and read or modify application data, via unspecified vectors.","exploit_maturity":"No public exploit","published":"2012-09-25","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-0547","description":"Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier, and 6 Update 34 and earlier, has no impact and remote attack vectors involving AWT and \"a security-in-depth issue that is not directly exploitable but which can be used to aggravate security vulnerabilities that can be directly exploited.\" NOTE: this identifier was assigned by the Oracle CNA, but CVE is not intended to cover defense-in-depth issues that are only exposed by the presence of other vulnerabilities.  NOTE: Oracle has not commented on claims from a downstream vendor that this issue is related to \"toolkit internals references.\"","exploit_maturity":"Working exploit published","published":"2012-08-30","resolved":"MITIGATION-CANDIDATE","severity":"Low"},
  {"cve_id":"CVE-2009-5066","description":"twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing the process and its arguments.","exploit_maturity":"No public exploit","published":"2012-08-13","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-3116","description":"Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 5.5.06, 6.0, 6.1, and 6.2 allows local users to affect confidentiality via unknown vectors.","exploit_maturity":"No public exploit","published":"2012-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-3111","description":"Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect integrity, related to TECH, a different vulnerability than CVE-2012-1762.","exploit_maturity":"No public exploit","published":"2012-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-3110","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-1766, CVE-2012-1767, CVE-2012-1769, CVE-2012-1770, CVE-2012-1771, CVE-2012-1772, CVE-2012-1773, CVE-2012-3106, CVE-2012-3107, and CVE-2012-3108.","exploit_maturity":"No public exploit","published":"2012-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-3109","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-1768.","exploit_maturity":"No public exploit","published":"2012-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-3108","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-1766, CVE-2012-1767, CVE-2012-1769, CVE-2012-1770, CVE-2012-1771, CVE-2012-1772, CVE-2012-1773, CVE-2012-3106, CVE-2012-3107, and CVE-2012-3110.","exploit_maturity":"No public exploit","published":"2012-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-3107","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-1766, CVE-2012-1767, CVE-2012-1769, CVE-2012-1770, CVE-2012-1771, CVE-2012-1772, CVE-2012-1773, CVE-2012-3106, CVE-2012-3108, and CVE-2012-3110.","exploit_maturity":"No public exploit","published":"2012-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-3106","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-1766, CVE-2012-1767, CVE-2012-1769, CVE-2012-1770, CVE-2012-1771, CVE-2012-1772, CVE-2012-1773, CVE-2012-3107, CVE-2012-3108, and CVE-2012-3110.","exploit_maturity":"No public exploit","published":"2012-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-1773","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-1766, CVE-2012-1767, CVE-2012-1769, CVE-2012-1770, CVE-2012-1771, CVE-2012-1772, CVE-2012-3106, CVE-2012-3107, CVE-2012-3108, and CVE-2012-3110.","exploit_maturity":"No public exploit","published":"2012-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-1772","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-1766, CVE-2012-1767, CVE-2012-1769, CVE-2012-1770, CVE-2012-1771, CVE-2012-1773, CVE-2012-3106, CVE-2012-3107, CVE-2012-3108, and CVE-2012-3110.","exploit_maturity":"No public exploit","published":"2012-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-1771","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-1766, CVE-2012-1767, CVE-2012-1769, CVE-2012-1770, CVE-2012-1772, CVE-2012-1773, CVE-2012-3106, CVE-2012-3107, CVE-2012-3108, and CVE-2012-3110.","exploit_maturity":"No public exploit","published":"2012-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-1770","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-1766, CVE-2012-1767, CVE-2012-1769, CVE-2012-1771, CVE-2012-1772, CVE-2012-1773, CVE-2012-3106, CVE-2012-3107, CVE-2012-3108, and CVE-2012-3110.","exploit_maturity":"Working exploit published","published":"2012-07-17","resolved":"MITIGATION-CANDIDATE","severity":"Low"},
  {"cve_id":"CVE-2012-1769","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-1766, CVE-2012-1767, CVE-2012-1770, CVE-2012-1771, CVE-2012-1772, CVE-2012-1773, CVE-2012-3106, CVE-2012-3107, CVE-2012-3108, and CVE-2012-3110.","exploit_maturity":"Working exploit published","published":"2012-07-17","resolved":"MITIGATION-CANDIDATE","severity":"Low"},
  {"cve_id":"CVE-2012-1768","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-3109.","exploit_maturity":"No public exploit","published":"2012-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-1767","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-1766, CVE-2012-1769, CVE-2012-1770, CVE-2012-1771, CVE-2012-1772, CVE-2012-1773, CVE-2012-3106, CVE-2012-3107, CVE-2012-3108, and CVE-2012-3110.","exploit_maturity":"No public exploit","published":"2012-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-1766","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-1767, CVE-2012-1769, CVE-2012-1770, CVE-2012-1771, CVE-2012-1772, CVE-2012-1773, CVE-2012-3106, CVE-2012-3107, CVE-2012-3108, and CVE-2012-3110.","exploit_maturity":"No public exploit","published":"2012-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-1764","description":"Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect integrity, related to MCF.","exploit_maturity":"No public exploit","published":"2012-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-1762","description":"Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect integrity, related to TECH, a different vulnerability than CVE-2012-3111.","exploit_maturity":"No public exploit","published":"2012-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-1744","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent users to affect availability via unknown vectors related to Outside In Filters.","exploit_maturity":"Working exploit published","published":"2012-07-17","resolved":"MITIGATION-CANDIDATE","severity":"Low"},
  {"cve_id":"CVE-2012-1743","description":"Unspecified vulnerability in the Oracle Clinical Remote Data Capture Option component in Oracle Industry Applications 4.6.0.x, 4.6.2, and 4.6.3 allows remote authenticated users to affect confidentiality, related to HTML Surround.","exploit_maturity":"No public exploit","published":"2012-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-1739","description":"Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.0.4, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote authenticated users to affect integrity via unknown vectors related to Financials Business Intelligence.","exploit_maturity":"No public exploit","published":"2012-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-1733","description":"Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect confidentiality via unknown vectors related to CM.","exploit_maturity":"No public exploit","published":"2012-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-1727","description":"Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.4, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote authenticated users to affect integrity via unknown vectors related to Document Repository.","exploit_maturity":"No public exploit","published":"2012-07-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-0717","description":"IBM WebSphere Application Server 7.0 before 7.0.0.23, when a certain SSLv2 configuration with client authentication is used, allows remote attackers to bypass X.509 client-certificate authentication via unspecified vectors.","exploit_maturity":"No public exploit","published":"2012-06-20","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-2672","description":"Oracle Mojarra 2.1.7 does not properly \"clean up\" the FacesContext reference during startup, which allows local users to obtain context information an access resources from another WAR file by calling the FacesContext.getCurrentInstance function.","exploit_maturity":"No public exploit","published":"2012-06-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-1717","description":"Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows local users to affect confidentiality via unknown vectors related to printing on Solaris or Linux.","exploit_maturity":"No public exploit","published":"2012-06-16","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2012-1704","description":"Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Core-Base, a different vulnerability than CVE-2012-1707.","exploit_maturity":"No public exploit","published":"2012-05-03","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-1679","description":"Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect integrity via unknown vectors related to Core-Base.","exploit_maturity":"No public exploit","published":"2012-05-03","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-1676","description":"Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Virtual Banking.","exploit_maturity":"No public exploit","published":"2012-05-03","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-0579","description":"Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0 through 10.5.0 and 11.0.0 through 11.4.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Core.","exploit_maturity":"No public exploit","published":"2012-05-03","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-0577","description":"Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0 through 10.5.0 and 11.0.0 through 11.4.0 allows remote authenticated users to affect availability via unknown vectors related to Core.","exploit_maturity":"No public exploit","published":"2012-05-03","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-0561","description":"Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect integrity, related to PIA Core Technology.","exploit_maturity":"No public exploit","published":"2012-05-03","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-0546","description":"Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0 through 10.5.0 and 11.0.0 through 11.2.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Core, a different vulnerability than CVE-2012-0545 and CVE-2012-0567.","exploit_maturity":"No public exploit","published":"2012-05-03","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-0545","description":"Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0 through 10.5.0 and 11.0.0 through 11.2.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Core, a different vulnerability than CVE-2012-0546 and CVE-2012-0567.","exploit_maturity":"No public exploit","published":"2012-05-03","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-0544","description":"Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0 through 10.5.0 and 11.0.0 through 11.4.0 allows remote authenticated users to affect integrity via unknown vectors related to Core, a different vulnerability than CVE-2012-0571.","exploit_maturity":"No public exploit","published":"2012-05-03","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-0542","description":"Unspecified vulnerability in the Oracle iStore component in Oracle E-Business Suite 11.5.10.2, 12.0.4, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Runtime Catalog.","exploit_maturity":"No public exploit","published":"2012-05-03","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-0541","description":"Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Core-My Services.","exploit_maturity":"No public exploit","published":"2012-05-03","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-0531","description":"Unspecified vulnerability in the PeopleSoft Enterprise Portal component in Oracle PeopleSoft Products 9.1 allows remote authenticated users to affect integrity via unknown vectors related to Enterprise Portal.","exploit_maturity":"No public exploit","published":"2012-05-03","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-0529","description":"Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51 allows remote authenticated users to affect integrity via unknown vectors related to core.","exploit_maturity":"No public exploit","published":"2012-05-03","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-0524","description":"Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows local users to affect confidentiality and integrity via unknown vectors related to File Processing.","exploit_maturity":"No public exploit","published":"2012-05-03","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-0513","description":"Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6 and 12.1.3 allows remote attackers to affect integrity, related to REST Services.","exploit_maturity":"No public exploit","published":"2012-05-03","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-0509","description":"Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2 and 5.3.0 through 5.3.4 allows remote authenticated users to affect integrity via unknown vectors related to Core-Base.","exploit_maturity":"No public exploit","published":"2012-05-03","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-0091","description":"Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52.05 allows remote authenticated users to affect integrity and availability via unknown vectors related to Upgrade Change Assistance.","exploit_maturity":"No public exploit","published":"2012-01-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-0084","description":"Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 7.5.2, 10.1.3.5.1, 11.1.1.3, 11.1.1.4, and 11.1.1.5 allows remote authenticated users to affect integrity via unknown vectors related to Content Server.","exploit_maturity":"No public exploit","published":"2012-01-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2012-0077","description":"Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.2.4, 10.0.2, 10.3.3, 10.3.4, and 10.3.5 allows remote authenticated users to affect integrity, related to WLS-Console.","exploit_maturity":"No public exploit","published":"2012-01-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2011-3574","description":"Unspecified vulnerability in Oracle Communications Unified 7.0 allows local users to affect confidentiality and integrity via unknown vectors related to Calendar Server.","exploit_maturity":"No public exploit","published":"2012-01-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2011-3570","description":"Unspecified vulnerability in Oracle Communications Unified 7.0 allows local users to affect confidentiality via unknown vectors related to Calendar Server.","exploit_maturity":"No public exploit","published":"2012-01-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2011-2271","description":"Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2 allows remote authenticated users to affect integrity via unknown vectors related to Attachments / File Upload.","exploit_maturity":"No public exploit","published":"2012-01-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2011-5066","description":"The SibRaRecoverableSiXaResource class in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 does not properly handle a Service Integration Bus (SIB) dump operation involving the First Failure Data Capture (FFDC) introspection code, which allows local users to obtain sensitive information by reading the FFDC log file.","exploit_maturity":"No public exploit","published":"2012-01-15","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2011-4344","description":"Cross-site scripting (XSS) vulnerability in Jenkins Core in Jenkins before 1.438, and 1.409 LTS before 1.409.3 LTS, when a stand-alone container is used, allows remote attackers to inject arbitrary web script or HTML via vectors related to error messages.","exploit_maturity":"No public exploit","published":"2011-12-01","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2011-4457","description":"OWASP HTML Sanitizer (aka owasp-java-html-sanitizer) before 88, when JavaScript is disabled, allows user-assisted remote attackers to obtain potentially sensitive information via a crafted FORM element within a NOSCRIPT element.","exploit_maturity":"No public exploit","published":"2011-11-17","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2011-3553","description":"Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JRockit R28.1.4 and earlier allows remote authenticated users to affect confidentiality, related to JAXWS.","exploit_maturity":"No public exploit","published":"2011-10-19","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2011-3552","description":"Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote attackers to affect integrity via unknown vectors related to Networking.","exploit_maturity":"No public exploit","published":"2011-10-19","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2011-3541","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows local users to affect availability via unknown vectors related to Outside In Filters.","exploit_maturity":"No public exploit","published":"2011-10-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2011-3523","description":"Unspecified vulnerability in the Oracle Web Services Manager component in Oracle Fusion Middleware 10.1.3.5.0 and 10.1.3.5.1 allows remote authenticated users to affect integrity, related to WSM Console, a different vulnerability than CVE-2011-2237.","exploit_maturity":"No public exploit","published":"2011-10-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2011-3520","description":"Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.49, 8.50, and 8.51 allows remote authenticated users to affect integrity via unknown vectors related to Personalization.","exploit_maturity":"No public exploit","published":"2011-10-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2011-3519","description":"Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 12.1.2 and 12.1.3 allows remote authenticated users to affect confidentiality, related to REST Services.","exploit_maturity":"No public exploit","published":"2011-10-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2011-2318","description":"Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.2.4.0, 10.0.2.0, 10.3.3.0, 10.3.4.0, and 10.3.5.0 allows local users to affect confidentiality, related to WLS Security.","exploit_maturity":"No public exploit","published":"2011-10-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2011-2303","description":"Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.2, and 12.1.3 allows remote authenticated users to affect integrity via unknown vectors related to Attachments / File Upload.","exploit_maturity":"No public exploit","published":"2011-10-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2011-2237","description":"Unspecified vulnerability in the Oracle Web Services Manager component in Oracle Fusion Middleware 10.1.3.5.0 and 10.1.3.5.1 allows remote authenticated users to affect integrity, related to WSM Console, a different vulnerability than CVE-2011-3523.","exploit_maturity":"No public exploit","published":"2011-10-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2011-2282","description":"Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50.20 and 8.51.11 allows remote authenticated users to affect integrity via unknown vectors.","exploit_maturity":"No public exploit","published":"2011-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2011-2274","description":"Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.49.31, 8.50.20, and 8.51.11 allows remote authenticated users to affect integrity via unknown vectors, a different vulnerability than CVE-2011-2280.","exploit_maturity":"No public exploit","published":"2011-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2011-2267","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.2.0 and 8.3.5.0 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters.","exploit_maturity":"No public exploit","published":"2011-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2011-1356","description":"IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.19 allows local users to obtain sensitive stack-trace information via a crafted Administration Console request.","exploit_maturity":"No public exploit","published":"2011-07-19","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2011-2204","description":"Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to obtain sensitive information by reading a log file.","exploit_maturity":"No public exploit","published":"2011-06-29","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2011-0865","description":"Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect integrity via unknown vectors related to Deserialization.","exploit_maturity":"No public exploit","published":"2011-06-14","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2011-1772","description":"Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the action attribute of an s:submit element, or (3) the method attribute of an s:submit element.","exploit_maturity":"Working exploit published","published":"2011-05-13","resolved":"MITIGATION-CANDIDATE","severity":"Low"},
  {"cve_id":"CVE-2011-0836","description":"Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Tools 8.9 GA through 8.98.4.1 and OneWorld Tools through 24.1.3 allows remote authenticated users to affect integrity, related to Web Runtime SEC.","exploit_maturity":"Working exploit published","published":"2011-04-20","resolved":"MITIGATION-CANDIDATE","severity":"Low"},
  {"cve_id":"CVE-2011-0827","description":"Unspecified vulnerability in the PeopleSoft Enterprise component in Oracle PeopleSoft Products 8.50 GA through 8.50.17 and 8.51 GA through 8.51.07 allows remote authenticated users to affect integrity via unknown vectors related to PeopleTools.","exploit_maturity":"No public exploit","published":"2011-04-20","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2011-0826","description":"Unspecified vulnerability in Oracle PeopleSoft Enterprise 8.8 Bundle #13, 8.9 Bundle #7, 9.0 Bundle #7, and 9.1 Bundle #4 allows remote authenticated users to affect integrity via unknown vectors related to Application Portal.","exploit_maturity":"No public exploit","published":"2011-04-20","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2011-0797","description":"Unspecified vulnerability in the Applications Install component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote authenticated users to affect confidentiality via unknown vectors.","exploit_maturity":"No public exploit","published":"2011-04-20","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2011-0796","description":"Unspecified vulnerability in the Applications Install component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows local users to affect confidentiality via unknown vectors.","exploit_maturity":"No public exploit","published":"2011-04-20","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2011-0795","description":"Unspecified vulnerability in the Single Sign On component in Oracle Fusion Middleware 10.1.2.3 allows remote authenticated users to affect integrity via unknown vectors related to Administration and Monitoring.","exploit_maturity":"No public exploit","published":"2011-04-20","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2011-1310","description":"The Administrative Scripting Tools component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15, when tracing is enabled, places wsadmin command parameters into the (1) wsadmin.traceout and (2) trace.log files, which allows local users to obtain potentially sensitive information by reading these files.","exploit_maturity":"No public exploit","published":"2011-03-08","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2011-1307","description":"The installer in IBM WebSphere Application Server (WAS) before 7.0.0.15 uses 777 permissions for a temporary log directory, which allows local users to have unintended access to log files via standard filesystem operations, a different vulnerability than CVE-2009-1173.","exploit_maturity":"No public exploit","published":"2011-03-08","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2010-4474","description":"Unspecified vulnerability in the Java DB component in Oracle Java SE and Java for Business 6 Update 23, and, and earlier allows local users to affect confidentiality via unknown vectors related to Security, a similar vulnerability to CVE-2009-4269.","exploit_maturity":"No public exploit","published":"2011-02-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2010-4472","description":"Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier allows remote attackers to affect availability, related to XML Digital Signature and unspecified APIs.  NOTE: the previous information was obtained from the February 2011 CPU.  Oracle has not commented on claims from a downstream vendor that this issue involves the replacement of the \"XML DSig Transform or C14N algorithm implementations.\"","exploit_maturity":"No public exploit","published":"2011-02-17","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2010-4450","description":"Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier for Solaris and Linux; 5.0 Update 27 and earlier for Solaris and Linux; and 1.4.2_29 and earlier for Solaris and Linux allows local standalone applications to affect confidentiality, integrity, and availability via unknown vectors related to Launcher.  NOTE: the previous information was obtained from the February 2011 CPU.  Oracle has not commented on claims from a downstream vendor that this issue is an untrusted search path vulnerability involving an empty LD_LIBRARY_PATH environment variable.","exploit_maturity":"No public exploit","published":"2011-02-17","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2010-4448","description":"Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect integrity via unknown vectors related to Networking.  NOTE: the previous information was obtained from the February 2011 CPU.  Oracle has not commented on claims from a downstream vendor that this issue involves \"DNS cache poisoning by untrusted applets.\"","exploit_maturity":"No public exploit","published":"2011-02-17","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2010-3718","description":"Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.","exploit_maturity":"No public exploit","published":"2011-02-10","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2010-4432","description":"Unspecified vulnerability in the Oracle Transportation Manager component in Oracle Supply Chain Products Suite 5.5.06, 6.0, 6.1, and 6.2 allows remote authenticated users to affect confidentiality via unknown vectors related to UI Infrastructure.","exploit_maturity":"No public exploit","published":"2011-01-19","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2010-4429","description":"Unspecified vulnerability in the Agile Core component in Oracle Supply Chain Products Suite 9.3.0.2 and 9.3.1 allows remote authenticated users to affect integrity via unknown vectors related to Web Client, a different vulnerability than CVE-2010-3505.","exploit_maturity":"No public exploit","published":"2011-01-19","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2010-4427","description":"Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 10.1.3.4.0, 10.1.3.4.1, and 11.1.1.3 allows remote authenticated users to affect integrity via unknown vectors related to Web Server.","exploit_maturity":"No public exploit","published":"2011-01-19","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2010-4425","description":"Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 10.1.3.3.2, 10.1.3.4.0, and 10.1.3.4.1 allows remote authenticated users to affect integrity via unknown vectors related to Web Server.","exploit_maturity":"No public exploit","published":"2011-01-19","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2010-3597","description":"Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.0 allows local users to affect availability, related to Outside In Viewer SDK.","exploit_maturity":"No public exploit","published":"2011-01-19","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2010-3505","description":"Unspecified vulnerability in the Agile Core component in Oracle Supply Chain Products Suite 9.3.0.2 and 9.3.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Folders, Files \u0026 Attachments, a different vulnerability than CVE-2010-4429.","exploit_maturity":"No public exploit","published":"2011-01-19","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2010-4265","description":"The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 through 4.3.0.CP09 allows remote attackers to cause a denial of service (daemon outage) by establishing a bisocket control connection TCP session, and then not sending any application data, related to a missing CVE-2010-3862 patch.  NOTE: this can be considered a duplicate of CVE-2010-3862 because a missing patch should not be assigned a separate CVE identifier.","exploit_maturity":"No public exploit","published":"2010-12-30","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2010-3862","description":"The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 through 4.3.0.CP09, and 5.1.0; and JBoss Enterprise Web Platform (aka JBEWP) 5.1.0; allows remote attackers to cause a denial of service (daemon outage) by establishing a bisocket control connection TCP session, and then not sending any application data.","exploit_maturity":"No public exploit","published":"2010-12-30","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2010-3560","description":"Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality via unknown vectors.","exploit_maturity":"No public exploit","published":"2010-10-19","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"},
  {"cve_id":"CVE-2010-3581","description":"Unspecified vulnerability in the BPEL Console component in Oracle Fusion Middleware 11.1.1.1.0 and 11.1.1.2.0 allows remote authenticated users to affect integrity via unknown vectors.","exploit_maturity":"Working exploit published","published":"2010-10-14","resolved":"MITIGATION-CANDIDATE","severity":"Low"},
  {"cve_id":"CVE-2010-2404","description":"Unspecified vulnerability in the Oracle iRecruitment component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote authenticated users to affect integrity via unknown vectors related to Account.","exploit_maturity":"No public exploit","published":"2010-10-14","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2009-4269","description":"The password hash generation algorithm in the BUILTIN authentication functionality for Apache Derby before 10.6.1.0 performs a transformation that reduces the size of the set of inputs to SHA-1, which produces a small search space that makes it easier for local and possibly remote attackers to crack passwords by generating hash collisions, related to password substitution.","exploit_maturity":"No public exploit","published":"2010-08-16","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2010-2474","description":"JBoss Enterprise Service Bus (ESB) before 4.7 CP02 in JBoss Enterprise SOA Platform before 5.0.2 does not properly consider the security domain with which a service is secured, which might allow remote attackers to gain privileges by executing a service.","exploit_maturity":"No public exploit","published":"2010-08-10","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2010-2403","description":"Unspecified vulnerability in the PeopleSoft Enterprise Campus Solutions component in Oracle PeopleSoft and JDEdwards Suite Campus Solutions 9.0 Bundle #17 allows remote authenticated users to affect confidentiality via unknown vectors.","exploit_maturity":"No public exploit","published":"2010-07-13","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2010-2381","description":"Unspecified vulnerability in the Application Server Control component in Oracle Fusion Middleware 10.1.2.3 and 10.1.4.0.1 allows remote authenticated users to affect integrity via unknown vectors, a different vulnerability than CVE-2010-0081.","exploit_maturity":"No public exploit","published":"2010-07-13","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2010-2378","description":"Unspecified vulnerability in the PeopleSoft Enterprise CRM component in Oracle PeopleSoft and JDEdwards Suite CRM 9.0 Bundle #28 and CRM 9.1 Bundle #4 allows local users to affect confidentiality and integrity via unknown vectors.","exploit_maturity":"No public exploit","published":"2010-07-13","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2010-2371","description":"Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1.1 allows local users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2010-2372.","exploit_maturity":"No public exploit","published":"2010-07-13","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2010-0909","description":"Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote authenticated users to affect confidentiality via unknown vectors.","exploit_maturity":"No public exploit","published":"2010-07-13","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2010-0836","description":"Unspecified vulnerability in the Oracle Knowledge Management component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote attackers to affect integrity via unknown vectors.","exploit_maturity":"No public exploit","published":"2010-07-13","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2010-0081","description":"Unspecified vulnerability in the Application Server Control component in Oracle Fusion Middleware 10.1.2.3 and 10.1.4.0.1 allows remote authenticated users to affect integrity via unknown vectors, a different vulnerability than CVE-2010-2381.","exploit_maturity":"No public exploit","published":"2010-07-13","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2010-0777","description":"The Web Container in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 does not properly handle long filenames and consequently sends an incorrect file in some responses, which allows remote attackers to obtain sensitive information by reading the retrieved file.","exploit_maturity":"No public exploit","published":"2010-05-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2010-1651","description":"IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.31 and 7.0.x before 7.0.0.11, when Basic authentication and SIP tracing (aka full trace logging for SIP) are enabled, logs the entirety of all inbound and outbound SIP messages, which allows local users to obtain sensitive information by reading the trace log.","exploit_maturity":"No public exploit","published":"2010-05-03","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2010-1650","description":"IBM WebSphere Application Server (WAS) 6.0.x before 6.0.2.41, 6.1.x before 6.1.0.31, and 7.0.x before 7.0.0.11, when the -trace option (aka debugging mode) is enabled, executes debugging statements that print string representations of unspecified objects, which allows attackers to obtain sensitive information by reading the trace output.","exploit_maturity":"No public exploit","published":"2010-05-03","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2010-1157","description":"Apache Tomcat 5.5.0 through 5.5.29 and 6.0.0 through 6.0.26 might allow remote attackers to discover the server's hostname or IP address by sending a request for a resource that requires (1) BASIC or (2) DIGEST authentication, and then reading the realm field in the WWW-Authenticate header in the reply.","exploit_maturity":"Working exploit published","published":"2010-04-23","resolved":"MITIGATION-CANDIDATE","severity":"Low"},
  {"cve_id":"CVE-2010-0858","description":"Unspecified vulnerability in the E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote authenticated users to affect integrity via unknown vectors.","exploit_maturity":"No public exploit","published":"2010-04-13","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2010-0857","description":"Unspecified vulnerability in the Oracle Workflow Cartridge component in Oracle E-Business Suite 11.5.10.2 allows remote authenticated users to affect integrity via unknown vectors.","exploit_maturity":"No public exploit","published":"2010-04-13","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2010-0684","description":"Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue action.","exploit_maturity":"No public exploit","published":"2010-04-05","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2010-0769","description":"IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 does not properly define wsadmin scripting J2CConnectionFactory objects, which allows local users to discover a KeyRingPassword password by reading a cleartext field in the resources.xml file.","exploit_maturity":"No public exploit","published":"2010-04-01","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2009-3554","description":"Twiddle in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP08 and 4.3 before 4.3.0.CP07 writes the JMX password, and other command-line arguments, to the twiddle.log file, which allows local users to obtain sensitive information by reading this file.","exploit_maturity":"No public exploit","published":"2009-12-15","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2009-3409","description":"Unspecified vulnerability in the PeopleSoft Enterprise HCM (TAM) component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 9.0 Bundle 10 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.","exploit_maturity":"No public exploit","published":"2009-10-22","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2009-3406","description":"Unspecified vulnerability in the JD Edwards Tools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.98.2.1 allows remote authenticated users to affect confidentiality via unknown vectors.","exploit_maturity":"No public exploit","published":"2009-10-22","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2009-3402","description":"Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.1 allows remote authenticated users to affect confidentiality via unknown vectors.","exploit_maturity":"No public exploit","published":"2009-10-22","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2009-3401","description":"Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.1 allows local users to affect confidentiality via unknown vectors.","exploit_maturity":"No public exploit","published":"2009-10-22","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2009-2743","description":"IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27, and 7.0 before 7.0.0.7, does not properly handle an exception occurring after use of wsadmin scripts and configuration of JAAS-J2C Authentication Data, which allows local users to obtain sensitive information by reading the First Failure Data Capture (FFDC) log file.","exploit_maturity":"No public exploit","published":"2009-09-21","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2009-2089","description":"The Migration component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, when tracing is enabled and a 6.1 to 7.0 migration has occurred, allows remote authenticated users to obtain sensitive information by reading a Migration Trace file.","exploit_maturity":"No public exploit","published":"2009-08-13","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2009-2087","description":"The Web Services functionality in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, in certain circumstances involving the ibm-webservicesclient-bind.xmi file and custom password encryption, uses weak password obfuscation, which allows local users to cause a denial of service (deployment failure) via unspecified vectors.","exploit_maturity":"No public exploit","published":"2009-08-13","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2009-1986","description":"Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality via unknown vectors.","exploit_maturity":"No public exploit","published":"2009-07-14","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2009-1981","description":"Unspecified vulnerability in the Highly Interactive Client component in Siebel Product Suite 7.5.3, 7.7.2, 7.8.2, 8.0.0.5, and 8.1.0 allows local users to affect confidentiality and integrity via unknown vectors.","exploit_maturity":"No public exploit","published":"2009-07-14","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2009-1173","description":"IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3 uses weak permissions (777) for files associated with unspecified \"interim fixes,\" which allows attackers to modify files that would not have been accessible if the intended 755 permissions were used.","exploit_maturity":"No public exploit","published":"2009-03-31","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2008-4308","description":"The doRead method in Apache Tomcat 4.1.32 through 4.1.34 and 5.5.10 through 5.5.20 does not return a -1 to indicate when a certain error condition has occurred, which can cause Tomcat to send POST content from one request to a different request.","exploit_maturity":"No public exploit","published":"2009-02-26","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2009-0504","description":"WSPolicy in the Web Services component in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.1 does not properly recognize the IDAssertion.isUsed binding property, which allows local users to discover a password by reading a SOAP message.","exploit_maturity":"No public exploit","published":"2009-02-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2009-0437","description":"The Installation Factory installation process for IBM WebSphere Application Server (WAS) 6.0.2 on Windows, when WAS is registered as a Windows service, allows local users to obtain sensitive information by reading the logs/instconfigifwas6.log log file.","exploit_maturity":"No public exploit","published":"2009-02-10","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2009-0434","description":"PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 6.0.x before 6.0.2.31, 6.1.x before 6.1.0.21, and 7.0.x before 7.0.0.1, when Performance Monitoring Infrastructure (PMI) is enabled, allows local users to obtain sensitive information by reading the (1) systemout.log and (2) ffdc files.  NOTE: this is probably a duplicate of CVE-2008-5413.","exploit_maturity":"No public exploit","published":"2009-02-10","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2009-0433","description":"Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1.x before 5.1.1.19, 6.0.x before 6.0.2.29, and 6.1.x before 6.1.0.19, when Web Server plug-in content buffering is enabled, allows attackers to cause a denial of service (daemon crash) via unknown vectors, related to a mishandling of client read failures in which clients receive many 500 HTTP error responses and backend servers are incorrectly labeled as down.","exploit_maturity":"No public exploit","published":"2009-02-10","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2008-5450","description":"Unspecified vulnerability in the Oracle Applications Platform Engineering component in Oracle E-Business Suite 11.5.10 CU2 and 12.0.6 allows local users to affect confidentiality via unknown vectors.","exploit_maturity":"No public exploit","published":"2009-01-14","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2008-5446","description":"Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10 CU2 and 12.0.6 allows remote authenticated users to affect confidentiality via unknown vectors.  NOTE: the previous information was obtained from the January 2009 CPU.  Oracle has not commented on reliable researcher claims that this issue is related to unrestricted guest access to the \"About Us Page\" in the Oracle Applications Framework (OAF), which allows attackers to obtain sensitive system and application environment information.","exploit_maturity":"No public exploit","published":"2009-01-14","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2008-2623","description":"Unspecified vulnerability in the Oracle JDeveloper component in Oracle Application Server 10.1.2.3 allows local users to affect confidentiality via unknown vectors.","exploit_maturity":"No public exploit","published":"2009-01-14","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2008-4004","description":"Unspecified vulnerability in the JDE EnterpriseOne Business Service Server component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.97.2.2 and 8.98.0.1 allows local users to affect confidentiality and integrity via unknown vectors.","exploit_maturity":"No public exploit","published":"2008-10-14","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2008-4002","description":"Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.18 and 8.49.14 allows remote authenticated users to affect confidentiality via unknown vectors.","exploit_maturity":"No public exploit","published":"2008-10-14","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2008-3993","description":"Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2 and 12.0.4 allows remote authenticated users to affect integrity via unknown vectors.","exploit_maturity":"No public exploit","published":"2008-10-14","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2008-2619","description":"Unspecified vulnerability in the Oracle Reports Developer component in Oracle Application Server 1.0.2.2, 9.0.4.3, and 10.1.2.2, and E-Business Suite 11.5.10.2, allows remote authenticated users to affect availability via unknown vectors.","exploit_maturity":"No public exploit","published":"2008-10-14","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2008-2588","description":"Unspecified vulnerability in the Oracle JDeveloper component in Oracle Application Server 10.1.2.2 allows local users to affect confidentiality via unknown vectors.","exploit_maturity":"No public exploit","published":"2008-10-14","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2008-0740","description":"IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) and 6.1 before Fix Pack 15 (6.1.0.15) writes unspecified cleartext information to http_plugin.log, which might allow local users to obtain sensitive information by reading this file.","exploit_maturity":"No public exploit","published":"2008-02-13","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2007-5461","description":"Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag.","exploit_maturity":"Working exploit published","published":"2007-10-15","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2007-5273","description":"Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when an HTTP proxy server is used, allows remote attackers to violate the security model for an applet's outbound connections via a multi-pin DNS rebinding attack in which the applet download relies on DNS resolution on the proxy server, but the applet's socket operations rely on DNS resolution on the local machine, a different issue than CVE-2007-5274. NOTE: this is similar to CVE-2007-5232.","exploit_maturity":"No public exploit","published":"2007-10-08","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2007-5238","description":"Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to obtain sensitive information (the Java Web Start cache location) via an untrusted application, aka \"three vulnerabilities.\"","exploit_maturity":"No public exploit","published":"2007-10-06","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2007-2450","description":"Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager and (2) Host Manager web applications in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote authenticated users to inject arbitrary web script or HTML via a parameter name to manager/html/upload, and other unspecified vectors.","exploit_maturity":"No public exploit","published":"2007-06-14","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2007-1358","description":"Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted \"Accept-Language headers that do not conform to RFC 2616\".","exploit_maturity":"No public exploit","published":"2007-05-10","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2007-0296","description":"Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.13, 8.47.11, and 8.48.06 has unknown impact and attack vectors in PeopleTools, aka PSE02.","exploit_maturity":"No public exploit","published":"2007-01-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2007-0294","description":"Unspecified vulnerability in Oracle Enterprise Manager 10.2.0.1 has unknown impact and attack vectors related to Database Cloning \u0026 Data Guard Management, aka EM06.","exploit_maturity":"No public exploit","published":"2007-01-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2007-0282","description":"Unspecified vulnerability in Oracle HTTP Server 9.0.1.5, Application Server 9.0.4.2 and 10.1.2.0.0, and Collaboration Suite 9.0.4.2 has unknown impact and attack vectors related to the Oracle Process Mgmt \u0026 Notification component, aka OPMN02.","exploit_maturity":"No public exploit","published":"2007-01-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2007-0275","description":"Cross-site scripting (XSS) vulnerability in Oracle Reports Web Cartridge (RWCGI60) in the Workflow Cartridge component, as used in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; Collaboration Suite 10.1.2; and Oracle E-Business Suite and Applications 11.5.10CU2; allows remote authenticated users to inject arbitrary HTML or web script via the genuser parameter to rwcgi60, aka OWF01.","exploit_maturity":"No public exploit","published":"2007-01-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2006-3933","description":"Cross-site scripting (XSS) vulnerability in Alkacon OpenCms before 6.2.2 allows remote authenticated users to inject arbitrary web script or HTML via the message body.","exploit_maturity":"No public exploit","published":"2006-07-31","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2006-3225","description":"Cross-site scripting (XSS) vulnerability in Sun ONE Application Server 7 before Update 9, Java System Application Server 7 2004Q2 before Update 5, and Java System Application Server Enterprise Edition 8.1 2005 Q1 allows remote attackers to inject arbitrary HTML or web script via unknown vectors.","exploit_maturity":"No public exploit","published":"2006-06-26","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2006-2571","description":"Cross-site scripting (XSS) vulnerability in search.html in Alkacon OpenCms 6.0.0, 6.0.2, and 6.0.3 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search action.","exploit_maturity":"No public exploit","published":"2006-05-24","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2005-3164","description":"The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when \"unsuitable request body data\" is used for a different request, possibly related to Java Servlet pages.","exploit_maturity":"No public exploit","published":"2005-10-06","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2005-2292","description":"Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 stores cleartext passwords in (1) IDEConnections.xml, (2) XSQLConfig.xml and (3) settings.xml, which allows local users to obtain sensitive information.","exploit_maturity":"No public exploit","published":"2005-07-18","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2004-1877","description":"The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO allows remote attackers to spoof the login page, which could allow users to inadvertently reveal their username and password.","exploit_maturity":"No public exploit","published":"2004-03-30","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2003-1447","description":"IBM WebSphere Advanced Server Edition 4.0.4 uses a weak encryption algorithm (XOR and base64 encoding), which allows local users to decrypt passwords when the configuration file is exported to XML.","exploit_maturity":"No public exploit","published":"2003-12-31","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-1999-0497","description":"Anonymous FTP is enabled.","exploit_maturity":"No public exploit","published":"1999-01-01","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"Low"}
]
