cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2024-21280,https://securityvulnerability.io/vulnerability/CVE-2024-21280,Oracle Service Contracts Vulnerability: Confidentiality and Integrity at Risk,"This vulnerability resides within the Oracle Service Contracts component of the Oracle E-Business Suite, impacting versions 12.2.5 through 12.2.13. It enables low-privileged attackers with network access via HTTP to exploit weaknesses in the system. This could lead to unauthorized creation, deletion, or modification of critical data associated with all Oracle Service Contracts. Successful exploitation permits attackers to gain complete access to sensitive data stored in the affected product, posing significant risks to data confidentiality and integrity.",Oracle,Oracle Service Contracts,8.1,HIGH,0.0004799999878741801,false,,false,false,false,,,false,false,,2024-10-15T19:53:01.851Z,0 CVE-2021-2255,https://securityvulnerability.io/vulnerability/CVE-2021-2255,Vulnerability in Oracle E-Business Suite Service Contracts Component,"A vulnerability exists in the Oracle Service Contracts component of the Oracle E-Business Suite that allows a low-privileged attacker with network access to exploit the system via HTTP. This exploitation can lead to unauthorized creation, deletion, or modification of data within Oracle Service Contracts. Attackers may gain access to sensitive information and potentially compromise the integrity and confidentiality of critical data. Supported versions 12.1.1 to 12.1.3 are affected, highlighting the importance of prompt patching and security measures.",Oracle,Service Contracts,8.1,HIGH,0.0009399999980814755,false,,false,false,false,,,false,false,,2021-04-22T21:53:56.000Z,0 CVE-2019-2622,https://securityvulnerability.io/vulnerability/CVE-2019-2622,Vulnerability in Oracle E-Business Suite Service Contracts Component,"A vulnerability exists in the Oracle E-Business Suite's Service Contracts component that allows an unauthenticated attacker to exploit the system through HTTP. The vulnerability requires interaction from a user other than the attacker, which could lead to unauthorized data manipulation, including updates, inserts, or deletions within Oracle Service Contracts. This issue affects several versions of the product, posing significant risks not only to the service contracts but potentially impacting additional interconnected components.",Oracle,Service Contracts,4.7,MEDIUM,0.0008299999753944576,false,,false,false,false,,,false,false,,2019-04-23T18:16:41.000Z,0 CVE-2016-0635,https://securityvulnerability.io/vulnerability/CVE-2016-0635,,"Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 12.1.4, 12.2.2, and 12.3.2; the Oracle Health Sciences Information Manager component in Oracle Health Sciences Applications 1.2.8.3, 2.0.2.3, and 3.0.1.0; the Oracle Healthcare Master Person Index component in Oracle Health Sciences Applications 2.0.12, 3.0.0, and 4.0.1; the Oracle Documaker component in Oracle Insurance Applications before 12.5; the Oracle Insurance Calculation Engine component in Oracle Insurance Applications 9.7.1, 10.1.2, and 10.2.2; the Oracle Insurance Policy Administration J2EE and Oracle Insurance Rules Palette components in Oracle Insurance Applications 9.6.1, 9.7.1, 10.0.1, 10.1.2, 10.2.0, and 10.2.2; the Oracle Retail Integration Bus component in Oracle Retail Applications 15.0; the Oracle Retail Order Broker component in Oracle Retail Applications 5.1, 5.2, and 15.0; the Primavera Contract Management component in Oracle Primavera Products Suite 14.2; the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.2, 8.3, 8.4, 15.1, 15.2, and 16.1; the Oracle Financial Services Analytical Applications Infrastructure component in Oracle Financial Services Applications 8.0.0, 8.0.1, 8.0.2, and 8.0.3; the Oracle Commerce Guided Search / Oracle Commerce Experience Manager component in Oracle Commerce 3.1.1, 3.1.2, 11.0, 11.1, and 11.2; the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5; the Oracle Communications BRM - Elastic Charging Engine 11.2.0.0.0 and 11.3.0.0.0; the Oracle Enterprise Repository Enterprise Repository 12.1.3.0.0; the Oracle Financial Services Behavior Detection Platform 8.0.1 and 8.0.2; the Oracle Hyperion Essbase 12.2.1.1; the Oracle Tuxedo System and Applications Monitor (TSAM) 11.1.1.2.0, 11.1.1.2.1, 11.1.1.2.1, 12.1.1.1.0, 12.1.3.0.0, and 12.2.2.0.0; the Oracle Communications WebRTC Session Controller component of Oracle Communications Applications (subcomponent: Security (Spring)) 7.0, 7.1 and 7.2; the Oracle Endeca Information Discovery Integrator 3.2; the Converged Commerce component of Oracle Retail Applications 16.0.1; the Oracle Identity Manager 11.1.2.3.0; Oracle Enterprise Manager for MySQL Database 12.1.0.4; Oracle Retail Invoice Matching 12.0, 13.0, 13.1, 13.2, 14.0, and 14.1; Oracle Communications Performance Intelligence Center (PIC) Software Prior to 10.2.1 and the Oracle Knowledge component of Oracle Siebel CRM (subcomponent: AnswerFlow (Spring Framework)) version 8.5.1.0 - 8.5.1.7 and 8.6.0 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.",Oracle,"Documaker,Insurance Policy Administration J2ee,Insurance Calculation Engine,Insurance Rules Palette,Enterprise Manager Ops Center,Primavera P6 Enterprise Project Portfolio Management,Retail Order Broker Cloud Service,Primavera Contract Management,Health Sciences Information Manager,Healthcare Master Person Index,Retail Integration Bus",8.8,HIGH,0.0020600000862032175,false,,false,false,false,,,false,false,,2016-07-21T10:00:00.000Z,0 CVE-2016-0558,https://securityvulnerability.io/vulnerability/CVE-2016-0558,,"Unspecified vulnerability in the Oracle Service Contracts component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Renewals.",Oracle,Service Contracts,,,0.001449999981559813,false,,false,false,false,,,false,false,,2016-01-21T02:00:00.000Z,0