<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Oracle Database</title>
  <link>https://cvedaily.com/pages/tags/oracle-database.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/oracle-database.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Oracle Database</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:40 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-46835 – Vulnerability in the Net Service component of Oracle Database Server.  Supported...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46835</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46835</guid>
    <pubDate>Thu, 28 May 2026 21:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46835</strong></p>
  <p>Vulnerability in the Net Service component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Net Servi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46835">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46834 – Vulnerability in the Net Service component of Oracle Database Server.  Supported...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46834</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46834</guid>
    <pubDate>Thu, 28 May 2026 21:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46834</strong></p>
  <p>Vulnerability in the Net Service component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Net Servi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46834">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-46833 – Vulnerability in the Net Service component of Oracle Database Server.  Supported...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46833</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46833</guid>
    <pubDate>Thu, 28 May 2026 21:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-46833</strong></p>
  <p>Vulnerability in the Net Service component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service.  While the vulnerability is in Net Service, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerab…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46833">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-23927 – A user able to connect to Agent 2 can inject an Oracle TNS connection string via...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23927</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23927</guid>
    <pubDate>Wed, 06 May 2026 08:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-23927</strong></p>
  <p>A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle database credentials if they are saved in a named session.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23927">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42233 – n8n is an open source workflow automation platform. Prior to versions 1.123.32, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42233</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42233</guid>
    <pubDate>Mon, 04 May 2026 19:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42233</strong></p>
  <p>n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the Oracle Database node's select operation allowed user-controlled input passed into the Limit field via expressions to be interpolated directly into the SQL query without sanitization or parameterization. In workflows where external input is passed into the Limit field (e.g., from a web…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42233">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35229 – Vulnerability in the Java VM component of Oracle Database Server.  Supported ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35229</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35229</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35229</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server.  Supported versions that are affected are 19.3-19.30 and  21.3-21.21. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Java VM.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Java VM accessible d…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35229">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-34312 – Vulnerability in the RDBMS component of Oracle Database Server.  Supported versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34312</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34312</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-34312</strong></p>
  <p>Vulnerability in the RDBMS component of Oracle Database Server.  Supported versions that are affected are 19.3-19.30. Easily exploitable vulnerability allows high privileged attacker having Row Access Method privilege with network access via multiple protocols to compromise RDBMS.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulne…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34312">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-21999 – Vulnerability in the XML Database component of Oracle Database Server.  Supporte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21999</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21999</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-21999</strong></p>
  <p>Vulnerability in the XML Database component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise XML Database.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unau…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21999">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-21975 – Vulnerability in the Java VM component of Oracle Database Server.  Supported ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21975</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21975</guid>
    <pubDate>Tue, 20 Jan 2026 22:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-21975</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server.  Supported versions that are affected are 19.3-19.29 and  21.3-21.20. Easily exploitable vulnerability allows high privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise Java VM.  Successful attacks require human interaction from a person other than the attacker. Successful attacks…</p>
  <p><strong>CVSS:</strong> 4.5 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21975">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21939 – Vulnerability in the SQLcl component of Oracle Database Server.  Supported versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21939</guid>
    <pubDate>Tue, 20 Jan 2026 22:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21939</strong></p>
  <p>Vulnerability in the SQLcl component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where SQLcl executes to compromise SQLcl.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can resul…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10703 – Improper Control of Generation of Code ('Code Injection') vulnerability in Progr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10703</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10703</guid>
    <pubDate>Wed, 19 Nov 2025 16:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10703</strong></p>
  <p>Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion.  The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers, DataDirect Hybrid Data Pipeline JDBC driver and the DataDirect OpenAccess JDBC driver l…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10703">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10702 – Improper Control of Generation of Code ('Code Injection') vulnerability in Progr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10702</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10702</guid>
    <pubDate>Wed, 19 Nov 2025 16:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10702</strong></p>
  <p>Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion.   The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers, DataDirect Hybrid Data Pipeline JDBC driver and the DataDirect OpenAccess JDBC driver…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10702">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-61881 – Vulnerability in the Java VM component of Oracle Database Server.  Supported ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61881</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61881</guid>
    <pubDate>Tue, 21 Oct 2025 20:20:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-61881</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server.  Supported versions that are affected are 19.3-19.28, 21.3-21.19 and  23.4-23.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Java VM.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical dat…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61881">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-61749 – Vulnerability in the Unified Audit component of Oracle Database Server.  Support...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61749</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61749</guid>
    <pubDate>Tue, 21 Oct 2025 20:20:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-61749</strong></p>
  <p>Vulnerability in the Unified Audit component of Oracle Database Server.  Supported versions that are affected are 23.4-23.9. Easily exploitable vulnerability allows high privileged attacker having DBA privilege with network access via Oracle Net to compromise Unified Audit.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Unified Aud…</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61749">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-53051 – Vulnerability in the RDBMS Functional Index component of Oracle Database Server...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53051</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53051</guid>
    <pubDate>Tue, 21 Oct 2025 20:20:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-53051</strong></p>
  <p>Vulnerability in the RDBMS Functional Index component of Oracle Database Server.  Supported versions that are affected are 23.4-23.9. Easily exploitable vulnerability allows high privileged attacker having SYSDBA privilege with network access via Oracle Net to compromise RDBMS Functional Index.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of RDBMS…</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53051">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53047 – Vulnerability in the Portable Clusterware component of Oracle Database Server.  ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53047</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53047</guid>
    <pubDate>Tue, 21 Oct 2025 20:20:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53047</strong></p>
  <p>Vulnerability in the Portable Clusterware component of Oracle Database Server.  Supported versions that are affected are 19.3-19.28, 21.3-21.19 and  23.4-23.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via Bonjour to compromise Portable Clusterware.  While the vulnerability is in Portable Clusterware, attacks may significantly impact additional products…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53047">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-50070 – Vulnerability in the JDBC component of Oracle Database Server.  Supported versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50070</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50070</guid>
    <pubDate>Tue, 15 Jul 2025 20:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-50070</strong></p>
  <p>Vulnerability in the JDBC component of Oracle Database Server.  Supported versions that are affected are 23.4-23.8. Difficult to exploit vulnerability allows low privileged attacker having Authenticated OS User privilege with logon to the infrastructure where JDBC executes to compromise JDBC.  Successful attacks require human interaction from a person other than the attacker and while the vulnera…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50070">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-50069 – Vulnerability in the Java VM component of Oracle Database Server.  Supported ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50069</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50069</guid>
    <pubDate>Tue, 15 Jul 2025 20:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-50069</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server.  Supported versions that are affected are 19.3-19.27 and  21.3-21.18. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM.  While the vulnerability is in Java VM, attacks may significantly impact additional product…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50069">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-50066 – Vulnerability in the Oracle Database Materialized View component of Oracle Datab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50066</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50066</guid>
    <pubDate>Tue, 15 Jul 2025 20:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-50066</strong></p>
  <p>Vulnerability in the Oracle Database Materialized View component of Oracle Database Server.  Supported versions that are affected are 19.3-19.27, 21.3-21.18 and  23.4-23.8. Easily exploitable vulnerability allows high privileged attacker having Execute on DBMS_REDEFINITION privilege with network access via Oracle Net to compromise Oracle Database Materialized View.  Successful attacks of this vul…</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50066">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30751 – Vulnerability in the Oracle Database component of Oracle Database Server.  Suppo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30751</guid>
    <pubDate>Tue, 15 Jul 2025 20:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30751</strong></p>
  <p>Vulnerability in the Oracle Database component of Oracle Database Server.  Supported versions that are affected are 19.27  and  23.4-23.8. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Oracle Database.  Successful attacks of this vulnerability can result in takeover of Oracle Datab…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-30750 – Vulnerability in the Unified Audit component of Oracle Database Server.  Support...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30750</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30750</guid>
    <pubDate>Tue, 15 Jul 2025 20:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-30750</strong></p>
  <p>Vulnerability in the Unified Audit component of Oracle Database Server.  Supported versions that are affected are 19.3-19.27, 21.3-21.18 and  23.4-23.8. Easily exploitable vulnerability allows high privileged attacker having Create User privilege with network access via Oracle Net to compromise Unified Audit.  Successful attacks require human interaction from a person other than the attacker. Suc…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30750">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30736 – Vulnerability in the Java VM component of Oracle Database Server.  Supported ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30736</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30736</guid>
    <pubDate>Tue, 15 Apr 2025 21:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30736</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server.  Supported versions that are affected are 19.3-19.26, 21.3-21.17 and  23.4-23.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java VM.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to crit…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30736">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-30733 – Vulnerability in the RDBMS Listener component of Oracle Database Server.  Suppor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30733</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30733</guid>
    <pubDate>Tue, 15 Apr 2025 21:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-30733</strong></p>
  <p>Vulnerability in the RDBMS Listener component of Oracle Database Server.  Supported versions that are affected are 19.3-19.26, 21.3-21.17 and  23.4-23.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise RDBMS Listener.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vul…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30733">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-30702 – Vulnerability in the Fleet Patching and amp; Provisioning component of Oracle Da...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30702</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30702</guid>
    <pubDate>Tue, 15 Apr 2025 21:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-30702</strong></p>
  <p>Vulnerability in the Fleet Patching and amp; Provisioning component of Oracle Database Server.  Supported versions that are affected are 19.3-19.26. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Fleet Patching and amp; Provisioning.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Fleet P…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30702">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30701 – Vulnerability in the RAS Security component of Oracle Database Server.  Supporte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30701</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30701</guid>
    <pubDate>Tue, 15 Apr 2025 21:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30701</strong></p>
  <p>Vulnerability in the RAS Security component of Oracle Database Server.  Supported versions that are affected are 19.3-19.26, 21.3-21.17 and  23.4-23.7. Easily exploitable vulnerability allows low privileged attacker having User Account privilege with network access via Oracle Net to compromise RAS Security.  Successful attacks require human interaction from a person other than the attacker. Succe…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30701">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-30694 – Vulnerability in the XML Database component of Oracle Database Server.  Supporte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30694</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30694</guid>
    <pubDate>Tue, 15 Apr 2025 21:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-30694</strong></p>
  <p>Vulnerability in the XML Database component of Oracle Database Server.  Supported versions that are affected are 19.3-19.26, 21.3-21.17 and  23.4-23.7. Easily exploitable vulnerability allows low privileged attacker having User Account privilege with network access via HTTP to compromise XML Database.  Successful attacks require human interaction from a person other than the attacker and while th…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30694">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-21553 – Vulnerability in the Java VM component of Oracle Database Server.  Supported ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-21553</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-21553</guid>
    <pubDate>Tue, 21 Jan 2025 21:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-21553</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server.  Supported versions that are affected are 19.3-19.25, 21.3-21.16 and  23.4-23.6. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM.  Successful attacks of this vulnerability can result in  unauthorized update,…</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-21553">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-53908 – An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53908</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53908</guid>
    <pubDate>Fri, 06 Dec 2024 12:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-53908</strong></p>
  <p>An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subject to SQL injection if untrusted data is used as an lhs value. (Applications that use the jsonfield.has_key lookup via __ are unaffected.)</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53908">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-21251 – Vulnerability in the Java VM component of Oracle Database Server.  Supported ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21251</guid>
    <pubDate>Tue, 15 Oct 2024 20:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-21251</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server.  Supported versions that are affected are 19.3-19.24, 21.3-21.15 and  23.4-23.5. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM.  Successful attacks of this vulnerability can result in  unauthorized update,…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-203</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-21242 – Vulnerability in the XML Database component of Oracle Database Server.  Supporte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21242</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21242</guid>
    <pubDate>Tue, 15 Oct 2024 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-21242</strong></p>
  <p>Vulnerability in the XML Database component of Oracle Database Server.  Supported versions that are affected are 19.3-19.24, 21.3-21.15 and  23.4-23.5. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via HTTP to compromise XML Database.  Successful attacks require human interaction from a person other than the attacker. Successfu…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21242">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-21233 – Vulnerability in the Oracle Database Core component of Oracle Database Server.  ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21233</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21233</guid>
    <pubDate>Tue, 15 Oct 2024 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-21233</strong></p>
  <p>Vulnerability in the Oracle Database Core component of Oracle Database Server.  Supported versions that are affected are 19.3-19.24, 21.3-21.15 and  23.4-23.5. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Database Core.  Successful attacks of this vulnerability can result in  unauthorized up…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-203</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21233">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21184 – Vulnerability in the Oracle Database RDBMS Security component of Oracle Database...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21184</guid>
    <pubDate>Tue, 16 Jul 2024 23:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21184</strong></p>
  <p>Vulnerability in the Oracle Database RDBMS Security component of Oracle Database Server.  Supported versions that are affected are 19.3-19.23. Easily exploitable vulnerability allows high privileged attacker having Execute on SYS.XS_DIAG privilege with network access via Oracle Net to compromise Oracle Database RDBMS Security.  Successful attacks of this vulnerability can result in takeover of Or…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-21174 – Vulnerability in the Java VM component of Oracle Database Server.  Supported ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21174</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21174</guid>
    <pubDate>Tue, 16 Jul 2024 23:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-21174</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server.  Supported versions that are affected are 19.3-19.23, 21.3-21.14 and  23.4. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM.  Successful attacks of this vulnerability can result in unauthorized ability to cau…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21174">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-21126 – Vulnerability in the Oracle Database Portable Clusterware component of Oracle Da...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21126</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21126</guid>
    <pubDate>Tue, 16 Jul 2024 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-21126</strong></p>
  <p>Vulnerability in the Oracle Database Portable Clusterware component of Oracle Database Server.  Supported versions that are affected are 19.3-19.23 and  21.3-21.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via DNS to compromise Oracle Database Portable Clusterware.  While the vulnerability is in Oracle Database Portable Clusterware, attacks may signific…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21126">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-21123 – Vulnerability in the Oracle Database Core component of Oracle Database Server.  ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21123</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21123</guid>
    <pubDate>Tue, 16 Jul 2024 23:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-21123</strong></p>
  <p>Vulnerability in the Oracle Database Core component of Oracle Database Server.  Supported versions that are affected are 19.3-19.23. Easily exploitable vulnerability allows high privileged attacker having SYSDBA privilege with logon to the infrastructure where Oracle Database Core executes to compromise Oracle Database Core.  Successful attacks of this vulnerability can result in  unauthorized up…</p>
  <p><strong>CVSS:</strong> 2.3 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21123">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-21093 – Vulnerability in the Java VM component of Oracle Database Server.  Supported ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21093</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21093</guid>
    <pubDate>Tue, 16 Apr 2024 22:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-21093</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server.  Supported versions that are affected are 19.3-19.22 and  21.3-21.13. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM.  Successful attacks of this vulnerability can result in  unauthorized access to critical…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21093">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-21066 – Vulnerability in the RDBMS component of Oracle Database Server.  Supported versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21066</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21066</guid>
    <pubDate>Tue, 16 Apr 2024 22:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-21066</strong></p>
  <p>Vulnerability in the RDBMS component of Oracle Database Server.  Supported versions that are affected are 19.3-19.22 and  21.3-21.13. Easily exploitable vulnerability allows high privileged attacker having Authenticated User privilege with logon to the infrastructure where RDBMS executes to compromise RDBMS.  Successful attacks require human interaction from a person other than the attacker. Succ…</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21066">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-21058 – Vulnerability in the Unified Audit component of Oracle Database Server.  Support...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21058</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21058</guid>
    <pubDate>Tue, 16 Apr 2024 22:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-21058</strong></p>
  <p>Vulnerability in the Unified Audit component of Oracle Database Server.  Supported versions that are affected are 19.3-19.22 and  21.3-21.13. Easily exploitable vulnerability allows high privileged attacker having SYSDBA privilege with network access via Oracle Net to compromise Unified Audit.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21058">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-20995 – Vulnerability in the Oracle Database Sharding component of Oracle Database Serve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20995</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20995</guid>
    <pubDate>Tue, 16 Apr 2024 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-20995</strong></p>
  <p>Vulnerability in the Oracle Database Sharding component of Oracle Database Server.  Supported versions that are affected are 19.3-19.22 and  21.3-21.13. Easily exploitable vulnerability allows high privileged attacker having DBA privilege with network access via Oracle Net to compromise Oracle Database Sharding.  Successful attacks require human interaction from a person other than the attacker.…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20995">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-20903 – Vulnerability in the Java VM component of Oracle Database Server.  Supported ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20903</guid>
    <pubDate>Sat, 17 Feb 2024 02:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-20903</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server.  Supported versions that are affected are 19.3-19.21 and  21.3-21.12. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-22096 – Vulnerability in the Java VM component of Oracle Database Server.  Supported ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22096</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22096</guid>
    <pubDate>Tue, 17 Oct 2023 22:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-22096</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server.  Supported versions that are affected are 19.3-19.20 and  21.3-21.11. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM.  Successful attacks of this vulnerability can result in  unauthorized update, insert or del…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22096">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-22077 – Vulnerability in the Oracle Database Recovery Manager component of Oracle Databa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22077</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22077</guid>
    <pubDate>Tue, 17 Oct 2023 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-22077</strong></p>
  <p>Vulnerability in the Oracle Database Recovery Manager component of Oracle Database Server.  Supported versions that are affected are 19.3-19.20 and  21.3-21.11. Easily exploitable vulnerability allows high privileged attacker having DBA account privilege with network access via Oracle Net to compromise Oracle Database Recovery Manager.  Successful attacks of this vulnerability can result in unaut…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22077">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-22075 – Vulnerability in the Oracle Database Sharding component of Oracle Database Serve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22075</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22075</guid>
    <pubDate>Tue, 17 Oct 2023 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-22075</strong></p>
  <p>Vulnerability in the Oracle Database Sharding component of Oracle Database Server.  Supported versions that are affected are 19.3-19.20 and  21.3-21.11. Easily exploitable vulnerability allows high privileged attacker having Create Session, Create Any View, Select Any Table privilege with network access via Oracle Net to compromise Oracle Database Sharding.  Successful attacks require human inter…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22075">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-22074 – Vulnerability in the Oracle Database Sharding component of Oracle Database Serve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22074</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22074</guid>
    <pubDate>Tue, 17 Oct 2023 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-22074</strong></p>
  <p>Vulnerability in the Oracle Database Sharding component of Oracle Database Server.  Supported versions that are affected are 19.3-19.20 and  21.3-21.11. Easily exploitable vulnerability allows high privileged attacker having Create Session, Select Any Dictionary privilege with network access via Oracle Net to compromise Oracle Database Sharding.  Successful attacks require human interaction from…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22074">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-22073 – Vulnerability in the Oracle Notification Server component of Oracle Database Ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22073</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22073</guid>
    <pubDate>Tue, 17 Oct 2023 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-22073</strong></p>
  <p>Vulnerability in the Oracle Notification Server component of Oracle Database Server.  Supported versions that are affected are 19.3-19.20 and  21.3-21.11. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Notification Server executes to compromise Oracle Notification Server.  Successful atta…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22073">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-22071 – Vulnerability in the PL/SQL component of Oracle Database Server.  Supported vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22071</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22071</guid>
    <pubDate>Tue, 17 Oct 2023 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-22071</strong></p>
  <p>Vulnerability in the PL/SQL component of Oracle Database Server.  Supported versions that are affected are 19.3-19.20 and  21.3-21.11. Easily exploitable vulnerability allows high privileged attacker having Create Session, Execute on sys.utl_http privilege with network access via Oracle Net to compromise PL/SQL.  Successful attacks require human interaction from a person other than the attacker a…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22071">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-22052 – Vulnerability in the Java VM component of Oracle Database Server.  Supported ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22052</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22052</guid>
    <pubDate>Tue, 18 Jul 2023 21:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-22052</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server.  Supported versions that are affected are 19.3-19.19 and  21.3-21.10. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise Java VM.  Successful attacks of this vulnerability can result in  unauthorized update, ins…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22052">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-22034 – Vulnerability in the Unified Audit component of Oracle Database Server.  Support...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22034</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22034</guid>
    <pubDate>Tue, 18 Jul 2023 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-22034</strong></p>
  <p>Vulnerability in the Unified Audit component of Oracle Database Server.  Supported versions that are affected are 19.3-19.19 and  21.3-21.10. Easily exploitable vulnerability allows high privileged attacker having SYSDBA privilege with network access via Oracle Net to compromise Unified Audit.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22034">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-21949 – Vulnerability in the Advanced Networking Option component of Oracle Database Ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-21949</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-21949</guid>
    <pubDate>Tue, 18 Jul 2023 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-21949</strong></p>
  <p>Vulnerability in the Advanced Networking Option component of Oracle Database Server.  Supported versions that are affected are 19.3-19.19 and  21.3-21.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete acces…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-21949">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-21934 – Vulnerability in the Java VM component of Oracle Database Server.  Supported ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-21934</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-21934</guid>
    <pubDate>Tue, 18 Apr 2023 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-21934</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server.  Supported versions that are affected are 19c and  21c. Difficult to exploit vulnerability allows low privileged attacker having User Account privilege with network access via TLS to compromise Java VM.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data o…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-21934">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-21918 – Vulnerability in the Oracle Database Recovery Manager component of Oracle Databa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-21918</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-21918</guid>
    <pubDate>Tue, 18 Apr 2023 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-21918</strong></p>
  <p>Vulnerability in the Oracle Database Recovery Manager component of Oracle Database Server.  Supported versions that are affected are 19c and  21c. Easily exploitable vulnerability allows high privileged attacker having Local SYSDBA privilege with network access via Oracle Net to compromise Oracle Database Recovery Manager.  While the vulnerability is in Oracle Database Recovery Manager, attacks m…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-21918">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-21893 – Vulnerability in the Oracle Data Provider for .NET component of Oracle Database ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-21893</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-21893</guid>
    <pubDate>Wed, 18 Jan 2023 00:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-21893</strong></p>
  <p>Vulnerability in the Oracle Data Provider for .NET component of Oracle Database Server.  Supported versions that are affected are 19c and  21c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCPS to compromise Oracle Data Provider for .NET.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vu…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-21893">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-21829 – Vulnerability in the Oracle Database RDBMS Security component of Oracle Database...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-21829</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-21829</guid>
    <pubDate>Wed, 18 Jan 2023 00:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-21829</strong></p>
  <p>Vulnerability in the Oracle Database RDBMS Security component of Oracle Database Server.  Supported versions that are affected are 19c and  21c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Database RDBMS Security.  Successful attacks require human interaction from a person other than the at…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-21829">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-21827 – Vulnerability in the Oracle Database Data Redaction component of Oracle Database...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-21827</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-21827</guid>
    <pubDate>Wed, 18 Jan 2023 00:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-21827</strong></p>
  <p>Vulnerability in the Oracle Database Data Redaction component of Oracle Database Server.  Supported versions that are affected are 19c and  21c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Database Data Redaction.  Successful attacks of this vulnerability can result in  unauthorized read ac…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-21827">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-39429 – Vulnerability in the Java VM component of Oracle Database Server.  Supported ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39429</guid>
    <pubDate>Wed, 18 Jan 2023 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-39429</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server.  Supported versions that are affected are 19c and  21c. Easily exploitable vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to compromise Java VM.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partia…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-39419 – Vulnerability in the Java VM component of Oracle Database Server. Supported vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39419</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39419</guid>
    <pubDate>Tue, 18 Oct 2022 21:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-39419</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java VM accessible data. CVS…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39419">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-21606 – Vulnerability in the Oracle Services for Microsoft Transaction Server component ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21606</guid>
    <pubDate>Tue, 18 Oct 2022 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-21606</strong></p>
  <p>Vulnerability in the Oracle Services for Microsoft Transaction Server component of Oracle Database Server. The supported version that is affected is 19c. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Services for Microsoft Transaction Server. Successful attacks require human interaction from a person other than the attacker and…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-21603 – Vulnerability in the Oracle Database - Sharding component of Oracle Database Ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21603</guid>
    <pubDate>Tue, 18 Oct 2022 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-21603</strong></p>
  <p>Vulnerability in the Oracle Database - Sharding component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Easily exploitable vulnerability allows high privileged attacker having Local Logon privilege with network access via Local Logon to compromise Oracle Database - Sharding. Successful attacks of this vulnerability can result in takeover of Oracle Database - Sha…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-21596 – Vulnerability in the Oracle Database - Advanced Queuing component of Oracle Data...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21596</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21596</guid>
    <pubDate>Tue, 18 Oct 2022 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-21596</strong></p>
  <p>Vulnerability in the Oracle Database - Advanced Queuing component of Oracle Database Server. The supported version that is affected is 19c. Easily exploitable vulnerability allows high privileged attacker having DBA user privilege with network access via Oracle Net to compromise Oracle Database - Advanced Queuing. Successful attacks of this vulnerability can result in takeover of Oracle Database…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21596">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-21565 – Vulnerability in the Java VM component of Oracle Database Server. Supported vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21565</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21565</guid>
    <pubDate>Tue, 19 Jul 2022 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-21565</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21565">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-21511 – Vulnerability in the Oracle Database - Enterprise Edition Recovery component of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21511</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21511</guid>
    <pubDate>Tue, 19 Jul 2022 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-21511</strong></p>
  <p>Vulnerability in the Oracle Database - Enterprise Edition Recovery component of Oracle Database Server. For supported versions that are affected see note. Easily exploitable vulnerability allows high privileged attacker having EXECUTE ON DBMS_IR.EXECUTESQLSCRIPT privilege with network access via Oracle Net to compromise Oracle Database - Enterprise Edition Recovery. Successful attacks of this vul…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21511">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-21510 – Vulnerability in the Oracle Database - Enterprise Edition Sharding component of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21510</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21510</guid>
    <pubDate>Tue, 19 Jul 2022 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-21510</strong></p>
  <p>Vulnerability in the Oracle Database - Enterprise Edition Sharding component of Oracle Database Server. For supported versions that are affected see note. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where Oracle Database - Enterprise Edition Sharding executes to compromise Oracle Database - Enterprise Edition Shardi…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21510">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2022-21432 – Vulnerability in the Oracle Database - Enterprise Edition RDBMS Security compone...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21432</guid>
    <pubDate>Tue, 19 Jul 2022 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2022-21432</strong></p>
  <p>Vulnerability in the Oracle Database - Enterprise Edition RDBMS Security component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 19c and 21c. Easily exploitable vulnerability allows high privileged attacker having DBA role privilege with network access via Oracle Net to compromise Oracle Database - Enterprise Edition RDBMS Security. Successful attacks of this vulne…</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-21498 – Vulnerability in the Java VM component of Oracle Database Server. Supported vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21498</guid>
    <pubDate>Tue, 19 Apr 2022 21:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-21498</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Procedure privilege with network access via multiple protocols to compromise Java VM. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification ac…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-21411 – Vulnerability in the RDBMS Gateway / Generic ODBC Connectivity component of Orac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21411</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21411</guid>
    <pubDate>Tue, 19 Apr 2022 21:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-21411</strong></p>
  <p>Vulnerability in the RDBMS Gateway / Generic ODBC Connectivity component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise RDBMS Gateway / Generic ODBC Connectivity. Successful attacks of this vulnerability can re…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21411">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-21410 – Vulnerability in the Oracle Database - Enterprise Edition Sharding component of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21410</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21410</guid>
    <pubDate>Tue, 19 Apr 2022 21:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-21410</strong></p>
  <p>Vulnerability in the Oracle Database - Enterprise Edition Sharding component of Oracle Database Server. The supported version that is affected is 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Procedure privilege with network access via Oracle Net to compromise Oracle Database - Enterprise Edition Sharding. Successful attacks of this vulnerability can resu…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21410">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-21393 – Vulnerability in the Java VM component of Oracle Database Server. Supported vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21393</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21393</guid>
    <pubDate>Wed, 19 Jan 2022 12:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-21393</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial o…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21393">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2022-21247 – Vulnerability in the Core RDBMS component of Oracle Database Server. Supported v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21247</guid>
    <pubDate>Wed, 19 Jan 2022 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2022-21247</strong></p>
  <p>Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Session, Execute Catalog Role privilege with network access via Oracle Net to compromise Core RDBMS. Successful attacks of this vulnerability can result in unauthorized read access to a subset…</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-42064 – If configured to use an Oracle database and if a query is created using the flex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-42064</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-42064</guid>
    <pubDate>Tue, 14 Dec 2021 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-42064</strong></p>
  <p>If configured to use an Oracle database and if a query is created using the flexible search java api with a parameterized "in" clause, SAP Commerce - versions 1905, 2005, 2105, 2011, allows attacker to execute crafted database queries, exposing backend database. The vulnerability is present if the parameterized "in" clause accepts more than 1000 values.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-42064">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-35619 – Vulnerability in the Java VM component of Oracle Database Server. Supported vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35619</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35619</guid>
    <pubDate>Wed, 20 Oct 2021 11:17:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-35619</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 19c and 21c. Difficult to exploit vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks require human interaction from a person other than the attacker. Successful attack…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35619">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-35599 – Vulnerability in the Zero Downtime DB Migration to Cloud component of Oracle Dat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35599</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35599</guid>
    <pubDate>Wed, 20 Oct 2021 11:17:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-35599</strong></p>
  <p>Vulnerability in the Zero Downtime DB Migration to Cloud component of Oracle Database Server. The supported version that is affected is 21c. Easily exploitable vulnerability allows high privileged attacker having Local Logon privilege with logon to the infrastructure where Zero Downtime DB Migration to Cloud executes to compromise Zero Downtime DB Migration to Cloud. While the vulnerability is in…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35599">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2021-35576 – Vulnerability in the Oracle Database Enterprise Edition Unified Audit component ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35576</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35576</guid>
    <pubDate>Wed, 20 Oct 2021 11:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2021-35576</strong></p>
  <p>Vulnerability in the Oracle Database Enterprise Edition Unified Audit component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having Local Logon privilege with network access via Oracle Net to compromise Oracle Database Enterprise Edition Unified Audit. Successful attacks of this vul…</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35576">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-35558 – Vulnerability in the Core RDBMS component of Oracle Database Server. Supported v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35558</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35558</guid>
    <pubDate>Wed, 20 Oct 2021 11:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-35558</strong></p>
  <p>Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Table privilege with network access via Oracle Net to compromise Core RDBMS. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35558">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-35557 – Vulnerability in the Core RDBMS component of Oracle Database Server. Supported v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35557</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35557</guid>
    <pubDate>Wed, 20 Oct 2021 11:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-35557</strong></p>
  <p>Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Table privilege with network access via Oracle Net to compromise Core RDBMS. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35557">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-35551 – Vulnerability in the RDBMS Security component of Oracle Database Server. Support...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35551</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35551</guid>
    <pubDate>Wed, 20 Oct 2021 11:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-35551</strong></p>
  <p>Vulnerability in the RDBMS Security component of Oracle Database Server. Supported versions that are affected are 12.2.0.1, 19c and 21c. Easily exploitable vulnerability allows high privileged attacker having DBA privilege with network access via Oracle Net to compromise RDBMS Security. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repea…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35551">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-2332 – Vulnerability in the Oracle LogMiner component of Oracle Database Server. Suppor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2332</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2332</guid>
    <pubDate>Wed, 20 Oct 2021 11:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-2332</strong></p>
  <p>Vulnerability in the Oracle LogMiner component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having DBA privilege with network access via Oracle Net to compromise Oracle LogMiner. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification a…</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2332">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-2438 – Vulnerability in the Java VM component of Oracle Database Server. Supported vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2438</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2438</guid>
    <pubDate>Wed, 21 Jul 2021 15:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-2438</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of ser…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2438">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-2351 – Vulnerability in the Advanced Networking Option component of Oracle Database Ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2351</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2351</guid>
    <pubDate>Wed, 21 Jul 2021 15:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-2351</strong></p>
  <p>Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a person other than the attacker and while the vuln…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2351">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-2337 – Vulnerability in the Oracle XML DB component of Oracle Database Server. Supporte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2337</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2337</guid>
    <pubDate>Wed, 21 Jul 2021 15:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-2337</strong></p>
  <p>Vulnerability in the Oracle XML DB component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Procedure, Create Public Synonym privilege with network access via Oracle Net to compromise Oracle XML DB. Successful attacks of this vulnerability can result in takeover of O…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2337">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2021-2336 – Vulnerability in the Oracle Database - Enterprise Edition Data Redaction compone...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2336</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2336</guid>
    <pubDate>Wed, 21 Jul 2021 15:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2021-2336</strong></p>
  <p>Vulnerability in the Oracle Database - Enterprise Edition Data Redaction component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Database - Enterprise Edition Data Redaction. Successful attacks req…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2336">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2021-2335 – Vulnerability in the Oracle Database - Enterprise Edition Data Redaction compone...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2335</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2335</guid>
    <pubDate>Wed, 21 Jul 2021 15:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2021-2335</strong></p>
  <p>Vulnerability in the Oracle Database - Enterprise Edition Data Redaction component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Database - Enterprise Edition Data Redaction. Successful attacks req…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2335">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2021-2334 – Vulnerability in the Oracle Database - Enterprise Edition Data Redaction compone...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2334</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2334</guid>
    <pubDate>Wed, 21 Jul 2021 15:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2021-2334</strong></p>
  <p>Vulnerability in the Oracle Database - Enterprise Edition Data Redaction component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Database - Enterprise Edition Data Redaction. Successful attacks req…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2334">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-2460 – Vulnerability in the Oracle Application Express Data Reporter component of Oracl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2460</guid>
    <pubDate>Wed, 21 Jul 2021 00:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-2460</strong></p>
  <p>Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server. The supported version that is affected is Prior to 21.1.0.00.04. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Data Reporter. Successful attacks require human interaction from…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-2333 – Vulnerability in the Oracle XML DB component of Oracle Database Server. Supporte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2333</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2333</guid>
    <pubDate>Wed, 21 Jul 2021 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-2333</strong></p>
  <p>Vulnerability in the Oracle XML DB component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having Alter User privilege with network access via Oracle Net to compromise Oracle XML DB. Successful attacks of this vulnerability can result in unauthorized access to critical data or comple…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2333">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-2330 – Vulnerability in the Core RDBMS component of Oracle Database Server. The support...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2330</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2330</guid>
    <pubDate>Wed, 21 Jul 2021 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-2330</strong></p>
  <p>Vulnerability in the Core RDBMS component of Oracle Database Server. The supported version that is affected is 19c. Easily exploitable vulnerability allows low privileged attacker having Create Table privilege with network access via Oracle Net to compromise Core RDBMS. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) o…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2330">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-2329 – Vulnerability in the Oracle XML DB component of Oracle Database Server. Supporte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2329</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2329</guid>
    <pubDate>Wed, 21 Jul 2021 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-2329</strong></p>
  <p>Vulnerability in the Oracle XML DB component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Procedure, Create Public Synonym privilege with network access via Oracle Net to compromise Oracle XML DB. Successful attacks of this vulnerability can result in takeover of O…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2329">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-2328 – Vulnerability in the Oracle Text component of Oracle Database Server. Supported ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2328</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2328</guid>
    <pubDate>Wed, 21 Jul 2021 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-2328</strong></p>
  <p>Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Procedure, Alter Any Table privilege with network access via Oracle Net to compromise Oracle Text. Successful attacks of this vulnerability can result in takeover of Oracle Text…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2328">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2021-2326 – Vulnerability in the Database Vault component of Oracle Database Server. Support...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2326</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2326</guid>
    <pubDate>Wed, 21 Jul 2021 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2021-2326</strong></p>
  <p>Vulnerability in the Database Vault component of Oracle Database Server. Supported versions that are affected are 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having DBA privilege with network access via Oracle Net to compromise Database Vault. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Database Vault access…</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2326">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2021-2245 – Vulnerability in the Oracle Database - Enterprise Edition Unified Audit componen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2245</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2245</guid>
    <pubDate>Thu, 22 Apr 2021 22:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2021-2245</strong></p>
  <p>Vulnerability in the Oracle Database - Enterprise Edition Unified Audit component of Oracle Database Server. Supported versions that are affected are 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Audit Policy privilege with network access via Oracle Net to compromise Oracle Database - Enterprise Edition Unified Audit. Successful attacks of this vulner…</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2245">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-2234 – Vulnerability in the Java VM component of Oracle Database Server. Supported vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2234</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2234</guid>
    <pubDate>Thu, 22 Apr 2021 22:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-2234</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2234">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2021-2207 – Vulnerability in the Oracle Database - Enterprise Edition component of Oracle Da...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2207</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2207</guid>
    <pubDate>Thu, 22 Apr 2021 22:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2021-2207</strong></p>
  <p>Vulnerability in the Oracle Database - Enterprise Edition component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having RMAN executable privilege with logon to the infrastructure where Oracle Database - Enterprise Edition executes to compromise Oracle Database - Enterprise Edit…</p>
  <p><strong>CVSS:</strong> 2.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2207">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2021-2175 – Vulnerability in the Database Vault component of Oracle Database Server. Support...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2175</guid>
    <pubDate>Thu, 22 Apr 2021 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2021-2175</strong></p>
  <p>Vulnerability in the Database Vault component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any View, Select Any View privilege with network access via Oracle Net to compromise Database Vault. Successful attacks of this vulnerability can result in unauthorized read…</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-2173 – Vulnerability in the Recovery component of Oracle Database Server. Supported ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2173</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2173</guid>
    <pubDate>Thu, 22 Apr 2021 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-2173</strong></p>
  <p>Vulnerability in the Recovery component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having DBA Level Account privilege with network access via Oracle Net to compromise Recovery. While the vulnerability is in Recovery, attacks may significantly impact additional products. Succe…</p>
  <p><strong>CVSS:</strong> 4.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2173">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-2117 – Vulnerability in the Oracle Application Express Survey Builder component of Orac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2117</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2117</guid>
    <pubDate>Wed, 20 Jan 2021 15:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-2117</strong></p>
  <p>Vulnerability in the Oracle Application Express Survey Builder component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Survey Builder. Successful attacks require human interaction from a pers…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2117">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-2116 – Vulnerability in the Oracle Application Express Opportunity Tracker component of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2116</guid>
    <pubDate>Wed, 20 Jan 2021 15:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-2116</strong></p>
  <p>Vulnerability in the Oracle Application Express Opportunity Tracker component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Opportunity Tracker. Successful attacks require human interaction f…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-2054 – Vulnerability in the RDBMS Sharding component of Oracle Database Server. Support...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2054</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2054</guid>
    <pubDate>Wed, 20 Jan 2021 15:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-2054</strong></p>
  <p>Vulnerability in the RDBMS Sharding component of Oracle Database Server. Supported versions that are affected are 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Procedure, Create Any View, Create Any Trigger privilege with network access via Oracle Net to compromise RDBMS Sharding. Successful attacks of this vulnerability can result in ta…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2054">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2021-2045 – Vulnerability in the Oracle Text component of Oracle Database Server. Supported ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2045</guid>
    <pubDate>Wed, 20 Jan 2021 15:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2021-2045</strong></p>
  <p>Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Text. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-2035 – Vulnerability in the RDBMS Scheduler component of Oracle Database Server. Suppor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2035</guid>
    <pubDate>Wed, 20 Jan 2021 15:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-2035</strong></p>
  <p>Vulnerability in the RDBMS Scheduler component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows low privileged attacker having Export Full Database privilege with network access via Oracle Net to compromise RDBMS Scheduler. Successful attacks of this vulnerability can result in takeover of RDBMS Scheduler.…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-2018 – Vulnerability in the Advanced Networking Option component of Oracle Database Ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2018</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2018</guid>
    <pubDate>Wed, 20 Jan 2021 15:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-2018</strong></p>
  <p>Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 18c and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2018">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2021-2000 – Vulnerability in the Unified Audit component of Oracle Database Server. Supporte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2000</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2000</guid>
    <pubDate>Wed, 20 Jan 2021 15:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2021-2000</strong></p>
  <p>Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having SYS Account privilege with network access via Oracle Net to compromise Unified Audit. Successful attacks require human interaction from a person other than the attacker. Successful…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2000">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
