cve,link,title,description,vendor,products,score,severity,epss,cisa,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2024-21246,https://securityvulnerability.io/vulnerability/CVE-2024-21246,Remote Code Execution Vulnerability in Oracle Service Bus,"A serious vulnerability has been identified in the Oracle Service Bus, specifically within the OSB Core Functionality of Oracle Fusion Middleware version 12.2.1.4.0. This flaw can be easily exploited by an unauthenticated attacker who has network access through HTTP. If successfully executed, this vulnerability could grant the attacker unauthorized access to sensitive and critical data stored within the Oracle Service Bus environment. The potential for complete data access emphasizes the urgent need for organizations using the affected version to implement the recommended security patches to safeguard their data integrity and confidentiality.",Oracle,Oracle Service Bus,7.5,HIGH,0.001019999966956675,false,false,false,false,,false,false,2024-10-15T19:52:49.910Z,0 CVE-2024-21205,https://securityvulnerability.io/vulnerability/CVE-2024-21205,Oracle Fusion Middleware Security Flaw in Service Bus Component,"A vulnerability exists in the Oracle Service Bus component of Oracle Fusion Middleware, specifically in the OSB Core Functionality. This vulnerability affects version 12.2.1.4.0 and can be exploited by an attacker with low privileges and network access through HTTP. If successfully exploited, it could allow the attacker to gain unauthorized access to sensitive data or potentially the entire dataset accessible via the Oracle Service Bus. Organizations using this version are urged to review their security measures and apply patches provided by Oracle to mitigate risks associated with this vulnerability.",Oracle,Oracle Service Bus,6.5,MEDIUM,0.00046999999904073775,false,false,false,false,,false,false,2024-10-15T19:52:39.956Z,0 CVE-2019-2576,https://securityvulnerability.io/vulnerability/CVE-2019-2576,,"Vulnerability in the Oracle Service Bus component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Service Bus. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Service Bus. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",Oracle,Service Bus,5.3,MEDIUM,0.0008299999753944576,false,false,false,false,,false,false,2019-04-23T18:16:39.000Z,0 CVE-2017-10119,https://securityvulnerability.io/vulnerability/CVE-2017-10119,,"Vulnerability in the Oracle Service Bus component of Oracle Fusion Middleware (subcomponent: OSB Web Console Design, Admin). The supported version that is affected is 11.1.1.9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Service Bus. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Service Bus, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Service Bus accessible data as well as unauthorized update, insert or delete access to some of Oracle Service Bus accessible data. CVSS 3.0 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",Oracle,Service Bus,7.6,HIGH,0.0011599999852478504,false,false,false,false,,false,false,2017-08-08T15:00:00.000Z,0 CVE-2017-3507,https://securityvulnerability.io/vulnerability/CVE-2017-3507,,"Vulnerability in the Oracle Service Bus component of Oracle Fusion Middleware (subcomponent: Web Console Design). Supported versions that are affected are 12.1.3.0.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily ""exploitable"" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Service Bus. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Service Bus accessible data as well as unauthorized read access to a subset of Oracle Service Bus accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Service Bus. CVSS 3.0 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",Oracle,Service Bus,7.3,HIGH,0.0013200000394135714,false,false,false,false,,false,false,2017-04-24T19:00:00.000Z,0 CVE-2016-0635,https://securityvulnerability.io/vulnerability/CVE-2016-0635,,"Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 12.1.4, 12.2.2, and 12.3.2; the Oracle Health Sciences Information Manager component in Oracle Health Sciences Applications 1.2.8.3, 2.0.2.3, and 3.0.1.0; the Oracle Healthcare Master Person Index component in Oracle Health Sciences Applications 2.0.12, 3.0.0, and 4.0.1; the Oracle Documaker component in Oracle Insurance Applications before 12.5; the Oracle Insurance Calculation Engine component in Oracle Insurance Applications 9.7.1, 10.1.2, and 10.2.2; the Oracle Insurance Policy Administration J2EE and Oracle Insurance Rules Palette components in Oracle Insurance Applications 9.6.1, 9.7.1, 10.0.1, 10.1.2, 10.2.0, and 10.2.2; the Oracle Retail Integration Bus component in Oracle Retail Applications 15.0; the Oracle Retail Order Broker component in Oracle Retail Applications 5.1, 5.2, and 15.0; the Primavera Contract Management component in Oracle Primavera Products Suite 14.2; the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.2, 8.3, 8.4, 15.1, 15.2, and 16.1; the Oracle Financial Services Analytical Applications Infrastructure component in Oracle Financial Services Applications 8.0.0, 8.0.1, 8.0.2, and 8.0.3; the Oracle Commerce Guided Search / Oracle Commerce Experience Manager component in Oracle Commerce 3.1.1, 3.1.2, 11.0, 11.1, and 11.2; the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5; the Oracle Communications BRM - Elastic Charging Engine 11.2.0.0.0 and 11.3.0.0.0; the Oracle Enterprise Repository Enterprise Repository 12.1.3.0.0; the Oracle Financial Services Behavior Detection Platform 8.0.1 and 8.0.2; the Oracle Hyperion Essbase 12.2.1.1; the Oracle Tuxedo System and Applications Monitor (TSAM) 11.1.1.2.0, 11.1.1.2.1, 11.1.1.2.1, 12.1.1.1.0, 12.1.3.0.0, and 12.2.2.0.0; the Oracle Communications WebRTC Session Controller component of Oracle Communications Applications (subcomponent: Security (Spring)) 7.0, 7.1 and 7.2; the Oracle Endeca Information Discovery Integrator 3.2; the Converged Commerce component of Oracle Retail Applications 16.0.1; the Oracle Identity Manager 11.1.2.3.0; Oracle Enterprise Manager for MySQL Database 12.1.0.4; Oracle Retail Invoice Matching 12.0, 13.0, 13.1, 13.2, 14.0, and 14.1; Oracle Communications Performance Intelligence Center (PIC) Software Prior to 10.2.1 and the Oracle Knowledge component of Oracle Siebel CRM (subcomponent: AnswerFlow (Spring Framework)) version 8.5.1.0 - 8.5.1.7 and 8.6.0 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.",Oracle,"Documaker,Insurance Policy Administration J2ee,Insurance Calculation Engine,Insurance Rules Palette,Enterprise Manager Ops Center,Primavera P6 Enterprise Project Portfolio Management,Retail Order Broker Cloud Service,Primavera Contract Management,Health Sciences Information Manager,Healthcare Master Person Index,Retail Integration Bus",8.8,HIGH,0.0020600000862032175,false,false,false,false,,false,false,2016-07-21T10:00:00.000Z,0