CVEID
|
Product
|
Component
|
Protocol
|
CVSS
|
WithoutAuth
|
AttackVector
|
Versions
|
CVE-2020-11612
|
Oracle Communications Design Studio
|
Inventory Services (Netty)
|
HTTP
|
9.8
|
Yes
|
Network
|
7.4.2
|
CVE-2019-0228
|
Oracle Communications Messaging Server
|
Message Store (Apache PDFBox)
|
HTTP
|
9.8
|
Yes
|
Network
|
8.1.0
|
CVE-2020-11612
|
Oracle Communications Messaging Server
|
Message Store (Netty)
|
HTTP
|
9.8
|
Yes
|
Network
|
8.1.0
|
CVE-2020-28052
|
Oracle Communications Messaging Server
|
Message Store (Bouncy Castle Java Library)
|
HTTPS
|
9.8
|
Yes
|
Network
|
8.0.2
|
CVE-2020-28052
|
Oracle Communications Application Session Controller
|
Security (Bouncy Castle Java Library)
|
HTTPS
|
9.8
|
Yes
|
Network
|
3.9m0p3
|
CVE-2019-0219
|
Instantis EnterpriseTrack
|
Browser (Apache Cordova InAppBrowser)
|
HTTP
|
9.8
|
Yes
|
Network
|
17.1, 17.2, 17.3
|
CVE-2019-17195
|
Enterprise Manager Base Platform
|
Enterprise Manager Install (Nimbus JOSE+JWT)
|
HTTP
|
9.8
|
Yes
|
Network
|
13.4.0.0
|
CVE-2020-11998
|
Oracle FLEXCUBE Private Banking
|
Financial Planning (Apache ActiveMQ)
|
HTTP
|
9.8
|
Yes
|
Network
|
12.0.0, 12.1.0
|
CVE-2020-5413
|
Oracle FLEXCUBE Private Banking
|
Order Management (Spring Integration)
|
HTTP
|
9.8
|
Yes
|
Network
|
12.0.0, 12.1.0
|
CVE-2019-3773
|
Oracle FLEXCUBE Private Banking
|
Order Management (Spring Web Services)
|
HTTP
|
9.8
|
Yes
|
Network
|
12.0.0, 12.1.0
|
CVE-2020-9480
|
Oracle Business Intelligence Enterprise Edition
|
Analytics Server (Apache Spark)
|
HTTP
|
9.8
|
Yes
|
Network
|
5.5.0.0.0
|
CVE-2020-10683
|
Oracle Fusion Middleware
|
Centralized Thirdparty Jars (dom4j)
|
HTTP
|
9.8
|
Yes
|
Network
|
11.1.1.9.0, 12.2.1.3.0, 12.2.1.4.0
|
CVE-2021-2302
|
Oracle Platform Security for Java
|
OPSS
|
HTTP
|
9.8
|
Yes
|
Network
|
11.1.1.9.0, 12.2.1.3.0, 12.2.1.4.0
|
CVE-2020-11612
|
Oracle WebCenter Portal
|
Security Framework (Netty)
|
HTTP
|
9.8
|
Yes
|
Network
|
12.2.1.3.0, 12.2.1.4.0
|
CVE-2021-2136
|
Oracle WebLogic Server
|
Core
|
IIOP
|
9.8
|
Yes
|
Network
|
12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0
|
CVE-2021-2135
|
Oracle WebLogic Server
|
Coherence Container
|
T3, IIOP
|
9.8
|
Yes
|
Network
|
12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0
|
CVE-2018-1285
|
Oracle Hospitality OPERA 5
|
Logging (Apache log4net)
|
HTTP
|
9.8
|
Yes
|
Network
|
5.5, 5.6
|
CVE-2020-17530
|
Oracle Hospitality OPERA 5
|
Login (Apache Struts)
|
HTTP
|
9.8
|
Yes
|
Network
|
5.6
|
CVE-2020-28052
|
JD Edwards EnterpriseOne Tools
|
E1 Dev Platform Tech - Cloud (Bouncy Castle Java Library)
|
HTTPS
|
9.8
|
Yes
|
Network
|
Prior to 9.2.5.3
|
CVE-2020-17530
|
MySQL Enterprise Monitor
|
Monitoring: General (Apache Struts)
|
HTTPS
|
9.8
|
Yes
|
Network
|
8.0.23 and prior
|
CVE-2020-10683
|
Oracle Retail Xstore Point of Service
|
Xenvironment (dom4j)
|
HTTP
|
9.8
|
Yes
|
Network
|
15.0.4, 16.0.6, 17.0.4, 18.0.3
|
CVE-2019-0228
|
Oracle Retail Xstore Point of Service
|
Xstore Office (Apache PDFbox)
|
HTTP
|
9.8
|
Yes
|