cve,link,title,description,vendor,products,score,severity,epss,cisa,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2021-2457,https://securityvulnerability.io/vulnerability/CVE-2021-2457,,Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Request Management & Workflow). The supported version that is affected is 11.1.2.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Identity Manager accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).,Oracle,Identity Manager,5.3,MEDIUM,0.0009699999936856329,false,false,false,false,,false,false,2021-07-21T00:15:00.000Z,0 CVE-2021-2458,https://securityvulnerability.io/vulnerability/CVE-2021-2458,,"Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Identity Console). Supported versions that are affected are 11.1.2.2.0, 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Identity Manager, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Identity Manager accessible data as well as unauthorized update, insert or delete access to some of Identity Manager accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",Oracle,Identity Manager,7.6,HIGH,0.0007099999929778278,false,false,false,false,,false,false,2021-07-21T00:15:00.000Z,0 CVE-2020-14874,https://securityvulnerability.io/vulnerability/CVE-2020-14874,,"Vulnerability in the Oracle Cloud Infrastructure Identity and Access Management product of Oracle Cloud Services. Easily exploitable vulnerability allows high privileged attacker with network access to compromise Oracle Cloud Infrastructure Identity and Access Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Cloud Infrastructure Identity and Access Management accessible data as well as unauthorized read access to a subset of Oracle Cloud Infrastructure Identity and Access Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Cloud Infrastructure Identity and Access Management.",Oracle,Oracle Cloud Infrastructure Identity And Access Management,4.7,MEDIUM,0.000910000002477318,false,false,false,false,,false,false,2020-12-22T21:40:14.000Z,0 CVE-2020-2728,https://securityvulnerability.io/vulnerability/CVE-2020-2728,,Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: OIM - LDAP user and role Synch). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Identity Manager accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).,Oracle,Identity Manager,7.5,HIGH,0.0036100000143051147,false,false,false,false,,false,false,2020-01-15T16:34:09.000Z,0 CVE-2020-2729,https://securityvulnerability.io/vulnerability/CVE-2020-2729,,"Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Advanced Console). Supported versions that are affected are 11.1.2.3.0 and 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Identity Manager accessible data as well as unauthorized read access to a subset of Identity Manager accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",Oracle,Identity Manager,5.4,MEDIUM,0.000539999979082495,false,false,false,false,,false,false,2020-01-15T16:34:09.000Z,0 CVE-2019-2858,https://securityvulnerability.io/vulnerability/CVE-2019-2858,,"Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Advanced Console). Supported versions that are affected are 11.1.2.3.0 and 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Identity Manager accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).",Oracle,Identity Manager,4.3,MEDIUM,0.000539999979082495,false,false,false,false,,false,false,2019-07-23T23:15:00.000Z,0 CVE-2018-3179,https://securityvulnerability.io/vulnerability/CVE-2018-3179,,"Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Advanced Console). Supported versions that are affected are 11.1.2.3.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. While the vulnerability is in Oracle Identity Manager, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Identity Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Identity Manager. CVSS 3.0 Base Score 7.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L).",Oracle,Identity Manager,7.2,HIGH,0.0006500000017695129,false,false,false,false,,false,false,2018-10-17T01:00:00.000Z,0 CVE-2017-10151,https://securityvulnerability.io/vulnerability/CVE-2017-10151,,"Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Default Account). Supported versions that are affected are 11.1.1.7, 11.1.2.3 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. While the vulnerability is in Oracle Identity Manager, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",Oracle,Identity Manager,10,CRITICAL,0.003100000089034438,false,false,false,false,,false,false,2017-10-30T20:00:00.000Z,0 CVE-2017-10270,https://securityvulnerability.io/vulnerability/CVE-2017-10270,,"Vulnerability in the Oracle Identity Manager Connector component of Oracle Fusion Middleware (subcomponent: Microsoft Active Directory). The supported version that is affected is 9.1.1.5.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager Connector accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Identity Manager Connector. CVSS 3.0 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H).",Oracle,Identity Manager Connector,8.2,HIGH,0.0007699999841861427,false,false,false,false,,false,false,2017-10-19T17:00:00.000Z,0 CVE-2017-3553,https://securityvulnerability.io/vulnerability/CVE-2017-3553,,"Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Rules Engine). The supported version that is affected is 11.1.2.3.0. Easily ""exploitable"" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. While the vulnerability is in Oracle Identity Manager, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.0 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",Oracle,Identity Manager,9.9,CRITICAL,0.001979999942705035,false,false,false,false,,false,false,2017-04-24T19:00:00.000Z,0 CVE-2016-5506,https://securityvulnerability.io/vulnerability/CVE-2016-5506,,Unspecified vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware allows local users to affect confidentiality and integrity via vectors related to App Server.,Oracle,Identity Manager,3.1,LOW,0.000539999979082495,false,false,false,false,,false,false,2016-10-25T14:00:00.000Z,0 CVE-2014-2880,https://securityvulnerability.io/vulnerability/CVE-2014-2880,,"Open redirect vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backUrl parameter in a changepwd action to identity/faces/firstlogin.",Oracle,Identity Manager,,,0.024450000375509262,false,false,false,false,,false,false,2014-04-17T14:00:00.000Z,0 CVE-2014-2411,https://securityvulnerability.io/vulnerability/CVE-2014-2411,,"Unspecified vulnerability in the Oracle Identity Analytics component in Oracle Fusion Middleware Oracle Identity Analytics 11.1.1.5 and Sun Role Manager 5.0 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Security.",Oracle,"Sun Role Manager,Identity Analytics",,,0.08728999644517899,false,false,false,false,,false,false,2014-04-16T02:05:00.000Z,0 CVE-2013-5815,https://securityvulnerability.io/vulnerability/CVE-2013-5815,,"Unspecified vulnerability in the Oracle Identity Analytics component in Oracle Fusion Middleware Oracle Identity Analytics 11.1.1.5 and Sun Role Manager 4.1 and 5.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security.",Oracle,"Sun Role Manager,Identity Analytics",,,0.010649999603629112,false,false,false,false,,false,false,2013-10-16T17:55:00.000Z,0 CVE-2009-1079,https://securityvulnerability.io/vulnerability/CVE-2009-1079,,"Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs 19659, 19660, and 19683.",Oracle,Java System Identity Manager,,,0.004889999981969595,false,false,false,false,,false,false,2009-03-25T15:30:00.000Z,0 CVE-2009-1081,https://securityvulnerability.io/vulnerability/CVE-2009-1081,,"Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs 19595 and 19661.",Oracle,Java System Identity Manager,,,0.004889999981969595,false,false,false,false,,false,false,2009-03-25T15:30:00.000Z,0 CVE-2009-1080,https://securityvulnerability.io/vulnerability/CVE-2009-1080,,"Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID 19033.",Oracle,Java System Identity Manager,,,0.004889999981969595,false,false,false,false,,false,false,2009-03-25T15:30:00.000Z,0 CVE-2009-1083,https://securityvulnerability.io/vulnerability/CVE-2009-1083,,"Sun Java System Identity Manager (IdM) 7.0 through 8.0 on Linux, AIX, Solaris, and HP-UX permits ""control characters"" in the passwords of user accounts, which allows remote attackers to execute arbitrary commands via vectors involving ""resource adapters.""",Oracle,Java System Identity Manager,,,0.004519999958574772,false,false,false,false,,false,false,2009-03-25T15:30:00.000Z,0 CVE-2009-1074,https://securityvulnerability.io/vulnerability/CVE-2009-1074,,"Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not use SSL in all expected circumstances, which makes it easier for remote attackers to obtain sensitive information by sniffing the network, related to ""ssl termination devices"" and lack of support for relative URLs.",Oracle,Java System Identity Manager,,,0.005969999823719263,false,false,false,false,,false,false,2009-03-25T15:30:00.000Z,0 CVE-2009-1075,https://securityvulnerability.io/vulnerability/CVE-2009-1075,,"Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the Forgot Password feature depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.",Oracle,Java System Identity Manager,,,0.036720000207424164,false,false,false,false,,false,false,2009-03-25T15:30:00.000Z,0 CVE-2009-1076,https://securityvulnerability.io/vulnerability/CVE-2009-1076,,"Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the end-user question-based login feature depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.",Oracle,Java System Identity Manager,,,0.009920000098645687,false,false,false,false,,false,false,2009-03-25T15:30:00.000Z,0 CVE-2009-1077,https://securityvulnerability.io/vulnerability/CVE-2009-1077,,"The Change My Password implementation in the admin interface in Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the RequiresChallenge property setting, which allows remote authenticated users to change the passwords of other users, as demonstrated by changing the administrator's password.",Oracle,Java System Identity Manager,,,0.010339999571442604,false,false,false,false,,false,false,2009-03-25T15:30:00.000Z,0 CVE-2009-1078,https://securityvulnerability.io/vulnerability/CVE-2009-1078,,"Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the expected privilege requirements for (1) deleting audit policies and (2) modifying workflows, which allows remote authenticated users to have an unspecified impact.",Oracle,Java System Identity Manager,,,0.00610999995842576,false,false,false,false,,false,false,2009-03-25T15:30:00.000Z,0 CVE-2009-1082,https://securityvulnerability.io/vulnerability/CVE-2009-1082,,"Sun Java System Identity Manager (IdM) 7.0 through 8.0 allows remote authenticated users to gain privileges by submitting crafted commands to the Admin Console, as demonstrated by privileges for account creation and other administrative capabilities, related to the saveNoValidate action and saveNoValidateAllowedFormsAndWorkflows IDs.",Oracle,Java System Identity Manager,,,0.0038300000596791506,false,false,false,false,,false,false,2009-03-25T15:30:00.000Z,0 CVE-2009-1084,https://securityvulnerability.io/vulnerability/CVE-2009-1084,,"Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not properly restrict access to the System Configuration object, which allows remote authenticated administrators and possibly remote attackers to have an unspecified impact by modifying this object.",Oracle,Java System Identity Manager,,,0.00203000009059906,false,false,false,false,,false,false,2009-03-25T15:00:00.000Z,0