Vulnerabilities in Oracle Corporation

7,792 results
Vexday analysis

Com 5.160 CVEs catalogadas e 376 surgidas apenas nos últimos 90 dias, o portfólio de vulnerabilidades da Oracle Corporation reflete a amplitude e complexidade de seu ecossistema de produtos. A taxa de exploração ativa — 26 entradas no CISA KEV, representando 0,5% do total — está em linha com a média geral do catálogo, mas o EPSS máximo observado de 1,0 indica que ao menos uma vulnerabilidade concentra probabilidade praticamente certa de exploração: CVE-2020-14882, uma falha ativa com EPSS de 1,0 que deve ser tratada como prioridade absoluta em qualquer ambiente Oracle. O tipo de falha mais recorrente, CWE-284 (controle de acesso impróprio), associado às 254 vulnerabilidades críticas e 74 com prova de conceito pública, sugere que superfícies de exposição relacionadas a autorização e gerenciamento de permissões merecem atenção redobrada nas avaliações de risco e nos ciclos de patching.

CVE-2022-21244MEDIUMVulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versioEPSS 0.9%CVE-2018-2881—Vulnerability in the MICROS Retail-J component of Oracle Retail Applications (subcomponent: Database). Supported versions that are affected EPSS 0.9%CVE-2023-22026MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.7.42 aEPSS 0.9%CVE-2022-21372LOWVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected arEPSS 0.9%CVE-2024-21238MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that are affected are 8.0EPSS 0.9%CVE-2024-21171MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.37 aEPSS 0.9%CVE-2017-10051—Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). The supported veEPSS 0.9%CVE-2024-21241MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.39 aEPSS 0.9%CVE-2019-2735—Vulnerability in the Oracle Hyperion Workspace component of Oracle Hyperion (subcomponent: UI and Visualization). The supported version thatEPSS 0.9%CVE-2024-21231LOWVulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are affected are 8.0.39 andEPSS 0.9%CVE-2020-2657MEDIUMVulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that arEPSS 0.9%CVE-2017-10399—Vulnerability in the Oracle Hospitality Cruise Fleet Management component of Oracle Hospitality Applications (subcomponent: GangwayActivityWEPSS 0.9%CVE-2023-22102HIGHVulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and EPSS 0.9%CVE-2024-21060MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Data Dictionary). Supported versions that are affected are 8.EPSS 0.9%CVE-2023-22070MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.34 aEPSS 0.9%CVE-2025-21543MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Packaging). Supported versions that are affected are 8.0.40 aEPSS 0.9%CVE-2021-2057MEDIUMVulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: InternaEPSS 0.9%CVE-2020-14544MEDIUMVulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Data, Domain & Function Security). The suppEPSS 0.9%CVE-2017-10423—Vulnerability in the Oracle Retail Back Office component of Oracle Retail Applications (subcomponent: Security). Supported versions that areEPSS 0.9%CVE-2022-21614HIGHVulnerability in the Oracle Enterprise Data Quality product of Oracle Fusion Middleware (component: Dashboard). Supported versions that are EPSS 0.9%