Where
AND
-Infinity
0

Vendor Risk Score

See how oracle compares to other vendors in security performance

View Risk Score →

Software

oracle weblogic server
18
oracle jre
14
oracle jdk
13
oracle solaris
10
oracle fusion middleware
9
oracle linux
8
oracle e-business suite
7
oracle java se
6
oracle mysql enterprise monitor
6
oracle instantis enterprisetrack
5
oracle retail xstore point of service
5
oracle agile plm
4
oracle communications cloud native core automated test suite
4
oracle financial services analytical applications infrastructure
4
oracle hospitality guest access
4
oracle java runtime environment (jre)
4
oracle transportation management
4
oracle access manager
3
oracle business intelligence
3
oracle communications cloud native core binding support function
3
oracle communications cloud native core console
3
oracle communications cloud native core network exposure function
3
oracle communications cloud native core network function cloud native environment
3
oracle communications cloud native core network repository function
3
oracle communications cloud native core network slice selection function
3
oracle communications cloud native core policy
3
oracle communications cloud native core security edge protection proxy
3
oracle communications diameter signaling router
3
oracle communications element manager
3
oracle communications instant messaging server
3
oracle communications interactive session recorder
3
oracle communications policy management
3
oracle communications session report manager
3
oracle communications session route manager
3
oracle communications unified inventory management
3
oracle enterprise manager ops center
3
oracle peoplesoft enterprise peopletools
3
oracle storagetek tape analytics sw tool
3
oracle agile engineering data management
2
oracle agile product lifecycle management
2
oracle agile product lifecycle management (plm)
2
oracle application express
2
oracle application testing suite
2
oracle banking enterprise collections
2
oracle banking platform
2
oracle commerce guided search
2
oracle commerce platform
2
oracle communications analytics
2
oracle communications application session controller
2
oracle communications cloud native core unified data repository
2
Severity
9.8
3 Months
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.

1 / 2
Source: CISA
First published (updated )
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.

1 / 2
Source: CISA
First published (updated )
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager.

1 / 2
Source: CISA
First published (updated )
Severity
7.5
SSRF, Path Traversal, CRLF Injection
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.

1 / 2
Source: CISA
First published (updated )
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks can result in takeover of Oracle Concurrent Processing.

1 / 2
Source: CISA
First published (updated )
Severity
9.9
AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H

A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt services within the impacted systems. This vulnerability exists because credentials are improperly generated when Cisco ISE is being deployed on cloud platforms, resulting in different Cisco ISE deployments sharing the same credentials. These credentials are shared across multiple Cisco ISE deployments as long as the software release and cloud platform are the same. An attacker could exploit this vulnerability by extracting the user credentials from Cisco ISE that is deployed in the cloud and then using them to access Cisco ISE that is deployed in other cloud environments through unsecured ports. A successful exploit could allow the attacker to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt services within the impacted systems. Note: If the Primary Administration node is deployed in the cloud, then Cisco ISE is affected by this vulnerability. If the Primary Administration node is on-premises, then it is not affected.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Oracle Agile Product Lifecycle Management (PLM) contains an incorrect authorization vulnerability in the Process Extension component of the Software Development Kit. Successful exploitation of this vulnerability may result in unauthenticated file disclosure.

1 / 2
Source: CISA
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203