Known vulnerabilities in Oracle Enterprise Data Quality

Vendor: Oracle
Software CPE: cpe:2.3:a:oracle:oracle_enterprise_data_quality:*:*:*:*:*:*:*:*
Total vulnerabilities: 34
Public exploits: 7
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Oracle Enterprise Data Quality Oracle Enterprise Data Quality is affected by 34 known vulnerabilities: 1 critical, 13 high, 12 medium, 8 low Critical High Medium Low

Vulnerabilities (34)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU113607 - Uncontrolled Recursion
CVE-2025-48924
CWE-674 Medium
No
No
- 04.08.2025 SB2025080422
SB2025080423
SB2025080427
and 182 more
#VU112166 - Improper Authentication
CVE-2025-49146
CWE-287 High
No
No
- 04.07.2025 SB2025070405
SB2025070406
SB2025070708
and 14 more
#VU112146 - Server-Side Request Forgery (SSRF)
CVE-2025-27817
CWE-918 High
Available
No
- 03.07.2025 SB2025070339
SB2025070340
SB2025070345
and 42 more
#VU108769 - Resource exhaustion
CVE-2025-27533
CWE-400 Medium
Available
No
- 07.05.2025 SB2025050773
SB2025051670
SB2025062647
and 13 more
#VU97244 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2024-38999
CWE-1321 High
No
No
- 13.09.2024 SB2024091339
SB2024091626
SB20241015165
and 13 more
#VU86983 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-1597
CWE-89 High
No
No
- 04.03.2024 SB2024030405
SB2024030406
SB2024030427
and 47 more
#VU86625 - Resource exhaustion
CVE-2024-26308
CWE-400 Medium
No
No
- 20.02.2024 SB2024022033
SB2024022937
SB2024031520
and 138 more
#VU84537 - Inadequate Encryption Strength
CVE-2023-48795
CWE-326 Low
Available
No
- 19.12.2023 SB2023121903
SB2023121905
SB2023121906
and 343 more
#VU83545 - Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CVE-2022-46337
CWE-90 High
No
No
- 28.11.2023 SB2023112861
SB2024011806
SB2024020107
and 34 more
#VU82690 - Deserialization of Untrusted Data
CVE-2023-46604
CWE-502 Critical
Available
Exploited
- 02.11.2023 SB2023110251
SB2023111311
SB2023112410
and 36 more
#VU81427 - UNIX Symbolic Link (Symlink) Following
CVE-2023-35887
CWE-61 Low
No
No
- 03.10.2023 SB2023100336
SB2023100337
SB2023100453
and 21 more
#VU75409 - Improper input validation
CVE-2023-20863
CWE-20 Medium
No
No
- 21.04.2023 SB2023042131
SB2023042132
SB2023050511
and 88 more
#VU72123 - Deserialization of Untrusted Data
CVE-2023-25194
CWE-502 Low
Available
No
- 11.02.2023 SB2023021101
SB2023030952
SB2023040419
and 40 more
#VU70530 - Deserialization of Untrusted Data
CVE-2022-45047
CWE-502 High
Available
No
- 28.12.2022 SB2022122828
SB2022122920
SB2023011148
and 49 more
#VU69809 - Out-of-bounds write
CVE-2022-42920
CWE-787 High
No
No
- 01.12.2022 SB2022120151
SB2022120154
SB2022120628
and 56 more
#VU68827 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-42890
CWE-94 Low
No
No
- 30.10.2022 SB2022103004
SB2022103009
SB2023030742
and 34 more
#VU66747 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-31197
CWE-89 High
No
No
- 24.08.2022 SB2022082432
SB2022082543
SB2022090901
and 27 more
#VU54853 - Resource exhaustion
CVE-2021-36090
CWE-400 Medium
No
No
- 14.07.2021 SB2021071408
SB2021080809
SB2021100411
and 70 more
#VU50072 - Improper Authentication
CVE-2021-26117
CWE-287 High
No
No
- 27.01.2021 SB2021012801
SB2021072724
SB20230719107
and 2 more
#VU47481 - Improper input validation
CVE-2020-13956
CWE-20 Medium
No
No
- 09.10.2020 SB2020100902
SB2020101604
SB2021042104
and 77 more


Showing elements 1 - 20 out of 34