cve,link,title,description,vendor,products,score,severity,epss,cisa,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2023-21824,https://securityvulnerability.io/vulnerability/CVE-2023-21824,,"Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications Applications (component: Customer, Config, Pricing Manager). Supported versions that are affected are 12.0.0.3.0-12.0.0.7.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications BRM - Elastic Charging Engine executes to compromise Oracle Communications BRM - Elastic Charging Engine. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications BRM - Elastic Charging Engine accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).",Oracle,Communications BRM - Elastic Charging Engine,4.4,MEDIUM,0.00044999999227002263,false,false,false,false,,false,false,2023-01-18T00:15:00.000Z,0 CVE-2021-2405,https://securityvulnerability.io/vulnerability/CVE-2021-2405,,"Vulnerability in the Oracle Engineering product of Oracle E-Business Suite (component: Change Management). Supported versions that are affected are 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Engineering. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Engineering accessible data as well as unauthorized access to critical data or complete access to all Oracle Engineering accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",Oracle,Engineering,8.1,HIGH,0.0009399999980814755,false,false,false,false,,false,false,2021-07-20T22:44:18.000Z,0 CVE-2021-2290,https://securityvulnerability.io/vulnerability/CVE-2021-2290,,"Vulnerability in the Oracle Engineering product of Oracle E-Business Suite (component: Change Management). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Engineering. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Engineering accessible data as well as unauthorized access to critical data or complete access to all Oracle Engineering accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",Oracle,Engineering,8.1,HIGH,0.0009399999980814755,false,false,false,false,,false,false,2021-04-22T21:54:00.000Z,0 CVE-2020-10775,https://securityvulnerability.io/vulnerability/CVE-2020-10775,,"An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary web sites and attempt phishing attacks. Once the target has opened the malicious URL in their browser, the critical part of the URL is no longer visible. The highest threat from this vulnerability is on confidentiality.",Oracle,Ovirt-engine,5.3,MEDIUM,0.0021899999119341373,false,false,false,false,,false,false,2020-08-24T16:13:00.000Z,0 CVE-2018-2632,https://securityvulnerability.io/vulnerability/CVE-2018-2632,,Vulnerability in the Siebel Engineering - Installer and Deployment component of Oracle Siebel CRM (subcomponent: Siebel Approval Manager). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Engineering - Installer and Deployment. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Siebel Engineering - Installer and Deployment accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).,Oracle,Siebel Engineering - Installer And Deployment,4.3,MEDIUM,0.0004900000058114529,false,false,false,false,,false,false,2018-01-18T02:00:00.000Z,0 CVE-2017-10161,https://securityvulnerability.io/vulnerability/CVE-2017-10161,,"Vulnerability in the Oracle Engineering Data Management component of Oracle Supply Chain Products Suite (subcomponent: Web Services Security). Supported versions that are affected are 6.1.3.0 and 6.2.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Engineering Data Management accessible data as well as unauthorized read access to a subset of Oracle Engineering Data Management accessible data. CVSS 3.0 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",Oracle,Agile Engineering Data Management,4.8,MEDIUM,0.0006799999973736703,false,false,false,false,,false,false,2017-10-19T17:00:00.000Z,0 CVE-2016-5518,https://securityvulnerability.io/vulnerability/CVE-2016-5518,,"Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.3.0 and 6.2.0.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to webfileservices.",Oracle,Agile Engineering Data Management,8.1,HIGH,0.0030799999367445707,false,false,false,false,,false,false,2016-10-25T14:00:00.000Z,0 CVE-2016-0635,https://securityvulnerability.io/vulnerability/CVE-2016-0635,,"Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 12.1.4, 12.2.2, and 12.3.2; the Oracle Health Sciences Information Manager component in Oracle Health Sciences Applications 1.2.8.3, 2.0.2.3, and 3.0.1.0; the Oracle Healthcare Master Person Index component in Oracle Health Sciences Applications 2.0.12, 3.0.0, and 4.0.1; the Oracle Documaker component in Oracle Insurance Applications before 12.5; the Oracle Insurance Calculation Engine component in Oracle Insurance Applications 9.7.1, 10.1.2, and 10.2.2; the Oracle Insurance Policy Administration J2EE and Oracle Insurance Rules Palette components in Oracle Insurance Applications 9.6.1, 9.7.1, 10.0.1, 10.1.2, 10.2.0, and 10.2.2; the Oracle Retail Integration Bus component in Oracle Retail Applications 15.0; the Oracle Retail Order Broker component in Oracle Retail Applications 5.1, 5.2, and 15.0; the Primavera Contract Management component in Oracle Primavera Products Suite 14.2; the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.2, 8.3, 8.4, 15.1, 15.2, and 16.1; the Oracle Financial Services Analytical Applications Infrastructure component in Oracle Financial Services Applications 8.0.0, 8.0.1, 8.0.2, and 8.0.3; the Oracle Commerce Guided Search / Oracle Commerce Experience Manager component in Oracle Commerce 3.1.1, 3.1.2, 11.0, 11.1, and 11.2; the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5; the Oracle Communications BRM - Elastic Charging Engine 11.2.0.0.0 and 11.3.0.0.0; the Oracle Enterprise Repository Enterprise Repository 12.1.3.0.0; the Oracle Financial Services Behavior Detection Platform 8.0.1 and 8.0.2; the Oracle Hyperion Essbase 12.2.1.1; the Oracle Tuxedo System and Applications Monitor (TSAM) 11.1.1.2.0, 11.1.1.2.1, 11.1.1.2.1, 12.1.1.1.0, 12.1.3.0.0, and 12.2.2.0.0; the Oracle Communications WebRTC Session Controller component of Oracle Communications Applications (subcomponent: Security (Spring)) 7.0, 7.1 and 7.2; the Oracle Endeca Information Discovery Integrator 3.2; the Converged Commerce component of Oracle Retail Applications 16.0.1; the Oracle Identity Manager 11.1.2.3.0; Oracle Enterprise Manager for MySQL Database 12.1.0.4; Oracle Retail Invoice Matching 12.0, 13.0, 13.1, 13.2, 14.0, and 14.1; Oracle Communications Performance Intelligence Center (PIC) Software Prior to 10.2.1 and the Oracle Knowledge component of Oracle Siebel CRM (subcomponent: AnswerFlow (Spring Framework)) version 8.5.1.0 - 8.5.1.7 and 8.6.0 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.",Oracle,"Documaker,Insurance Policy Administration J2ee,Insurance Calculation Engine,Insurance Rules Palette,Enterprise Manager Ops Center,Primavera P6 Enterprise Project Portfolio Management,Retail Order Broker Cloud Service,Primavera Contract Management,Health Sciences Information Manager,Healthcare Master Person Index,Retail Integration Bus",8.8,HIGH,0.0020600000862032175,false,false,false,false,,false,false,2016-07-21T10:00:00.000Z,0 CVE-2016-3468,https://securityvulnerability.io/vulnerability/CVE-2016-3468,,"Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.3.0 and 6.2.0.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Install.",Oracle,Agile Engineering Data Management,9.8,CRITICAL,0.006949999835342169,false,false,false,false,,false,false,2016-07-21T10:00:00.000Z,0 CVE-2016-3472,https://securityvulnerability.io/vulnerability/CVE-2016-3472,,"Unspecified vulnerability in the Siebel Engineering - Installer and Deployment component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote authenticated users to affect confidentiality via vectors related to Web Server.",Oracle,Siebel Engineering-installer And Deployment,5.7,MEDIUM,0.0011699999449774623,false,false,false,false,,false,false,2016-07-21T10:00:00.000Z,0 CVE-2016-3428,https://securityvulnerability.io/vulnerability/CVE-2016-3428,,Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.3.0 and 6.2.0.0 allows remote attackers to affect availability via vectors related to Engineering Communication Interface.,Oracle,Agile Engineering Data Management,3.1,LOW,0.0009899999713525176,false,false,false,false,,false,false,2016-04-21T10:00:00.000Z,0 CVE-2016-0497,https://securityvulnerability.io/vulnerability/CVE-2016-0497,,"Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.2.2, 6.1.3.0, and 6.2.0.0 allows remote attackers to affect integrity via unknown vectors related to Web Client.",Oracle,Agile Engineering Data Management,,,0.0008299999753944576,false,false,false,false,,false,false,2016-01-21T02:00:00.000Z,0 CVE-2016-0498,https://securityvulnerability.io/vulnerability/CVE-2016-0498,,"Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.2.2, 6.1.3.0, and 6.2.0.0 allows local users to affect confidentiality via unknown vectors related to Install.",Oracle,Agile Engineering Data Management,,,0.0006000000284984708,false,false,false,false,,false,false,2016-01-21T02:00:00.000Z,0 CVE-2009-0046,https://securityvulnerability.io/vulnerability/CVE-2009-0046,,"Sun GridEngine 5.3 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.",Oracle,Grid Engine,,,0.0030499999411404133,false,false,false,false,,false,false,2009-01-07T18:00:00.000Z,0 CVE-2008-1756,https://securityvulnerability.io/vulnerability/CVE-2008-1756,,Unspecified vulnerability in the Qmaster daemon in Sun N1 Grid Engine 6.1 allows local users to cause a denial of service (daemon crash) via unspecified vectors.,Oracle,N1 Grid Engine,,,0.0004400000034365803,false,false,false,false,,false,false,2008-04-11T20:28:00.000Z,0 CVE-2006-3941,https://securityvulnerability.io/vulnerability/CVE-2006-3941,,Unspecified vulnerability in the daemons for Sun N1 Grid Engine 5.3 and N1 Grid Engine 6.0 allows local users to cause a denial of service (grid service shutdown) and possibly execute arbitrary code using buffer overflows via unknown vectors that cause (1) qmaster or (2) execd to terminate.,Oracle,N1 Grid Engine,,,0.0032599999103695154,false,false,false,false,,false,false,2006-07-31T23:04:00.000Z,0 CVE-2006-2930,https://securityvulnerability.io/vulnerability/CVE-2006-2930,,"Unspecified vulnerability in Sun Grid Engine 5.3 and Sun N1 Grid Engine 6.0, when configured in Certificate Security Protocol (CSP) Mode, allows local users to shut down the grid service or gain access, even if access is denied.",Oracle,"N1 Grid Engine,Grid Engine",,,0.0004400000034365803,false,false,false,false,,false,false,2006-06-09T10:00:00.000Z,0 CVE-2006-1506,https://securityvulnerability.io/vulnerability/CVE-2006-1506,,Unspecified vulnerability in rsh in Sun Microsystems Sun Grid Engine 5.3 before 20060327 and N1 Grid Engine 6.0 before 20060327 allows local users to gain root privileges.,Oracle,"N1 Grid Engine,Grid Engine",,,0.0004400000034365803,false,false,false,false,,false,false,2006-03-30T01:00:00.000Z,0 CVE-2006-0408,https://securityvulnerability.io/vulnerability/CVE-2006-0408,,"rsh utility in Sun Grid Engine (SGE) before 6.0u7_1 allows local users to gain privileges and execute arbitrary code via unspecified vectors, possibly involving command line arguments.",Oracle,Grid Engine,,,0.0006300000241026282,false,false,false,false,,false,false,2006-01-25T02:00:00.000Z,0