Known vulnerabilities in Oracle Utilities Framework
Vendor:
Oracle
Software:
Oracle Utilities Framework
Software CPE:
cpe:2.3:a:oracle:oracle_utilities_framework:*:*:*:*:*:*:*:*
Website:
https://www.oracle.com
Total vulnerabilities:
24
Public exploits:
5
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (24)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU68635 - Deserialization of Untrusted Data CVE-2022-42003 |
CWE-502 | Medium | - | 25.10.2022 | - | ||
| #VU68307 - Improper Control of Generation of Code ('Code Injection') CVE-2022-42889 |
CWE-94 | High | - | 14.10.2022 | - | ||
| #VU61799 - Out-of-bounds write CVE-2020-36518 |
CWE-787 | Medium | - | 01.04.2022 | - | ||
| #VU59813 - Improper input validation CVE-2021-39139 |
CWE-20 | High | - | 19.01.2022 | - | ||
| #VU59098 - Improper Control of Generation of Code ('Code Injection') CVE-2021-44832 |
CWE-94 | Medium | - | 28.12.2021 | - | ||
| #VU55372 - Improper input validation CVE-2021-27568 |
CWE-20 | High | - | 27.07.2021 | - | ||
| #VU55044 - Improper input validation CVE-2021-2351 |
CWE-20 | High | - | 20.07.2021 | - | ||
| #VU54856 - Resource exhaustion CVE-2021-36374 |
CWE-400 | Medium | - | 14.07.2021 | - | ||
| #VU49774 - Improper input validation CVE-2020-14756 |
CWE-20 | High | - | 20.01.2021 | - | ||
| #VU49086 - Comparison using wrong factors CVE-2020-28052 |
CWE-1025 | High | - | 18.12.2020 | - | ||
| #VU48979 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2020-25649 |
CWE-611 | Medium | - | 03.12.2020 | - | ||
| #VU47914 - Improper input validation CVE-2020-14895 |
CWE-20 | Medium | - | 26.10.2020 | - | ||
| #VU28238 - Exposed Dangerous Method or Function CVE-2020-10683 |
CWE-749 | Medium | - | 26.05.2020 | - | ||
| #VU27924 - Incorrect Default Permissions CVE-2020-1945 |
CWE-276 | Low | - | 15.05.2020 | - | ||
| #VU47428 - Permissions, Privileges, and Access Controls CVE-2020-11979 |
CWE-264 | Low | - | 14.05.2020 | - | ||
| #VU27487 - Improper Certificate Validation CVE-2020-9488 |
CWE-295 | Low | - | 04.05.2020 | - | ||
| #VU25048 - Improper input validation CVE-2020-2555 |
CWE-20 | High | - | 07.02.2020 | - | ||
| #VU22875 - Deserialization of Untrusted Data CVE-2019-10173 |
CWE-502 | High | - | 20.11.2019 | - | ||
| #VU30727 - Cross-Site Request Forgery (CSRF) CVE-2019-17495 |
CWE-352 | Medium | - | 11.10.2019 | - | ||
| #VU20844 - Protection Mechanism Failure CVE-2019-10086 |
CWE-693 | Low | - | 04.09.2019 | - |
Showing elements 1 - 20 out of 24