<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet type="text/xsl" href="http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/1687073.xsl"?>
<?xml-stylesheet type="text/css" href="http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/1686935.css"?>
<cvrf:cvrfdoc xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1">
   <DocumentTitle xml:lang="en">Oracle Critical Patch Update Advisory - April 2012 - DRAFT ORACLE CVRF</DocumentTitle>
   <DocumentType xml:lang="en">Oracle Critical Patch Update Advisory</DocumentType>
   <DocumentPublisher Type="Vendor"/>
   <DocumentTracking>
      <Identification>
         <ID>CPUApr2012</ID>
      </Identification>
      <Status>Draft</Status>
      <Version>1.0</Version>
      <RevisionHistory>
         <Revision>
            <Number>1.0</Number>
            <Date>2012-04-17T13:00:00-07:00</Date>
            <Description>Initial Distribution</Description>
         </Revision>
      </RevisionHistory>
      <InitialReleaseDate>2012-04-17T13:00:00-07:00</InitialReleaseDate>
      <CurrentReleaseDate>2012-04-17T13:00:00-07:00</CurrentReleaseDate>
   </DocumentTracking>
   <DocumentNotes>
      <Note Type="Summary" Ordinal="1" Title="Summary" Audience="All" xml:lang="en">This document contains descriptions of Oracle product security vulnerabilities which have had fixes released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including fix distribution information can be found at the Oracle sites referenced in this document.</Note>
   </DocumentNotes>
   <DocumentDistribution>This document is published at: http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</DocumentDistribution>
   <DocumentReferences>
      <Reference Type="External">
         <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
         <Description>URL to html version of Advisory</Description>
      </Reference>
   </DocumentReferences>
   <Acknowledgments>
      <Acknowledgment>
         <Name>Alexander Kornbrust</Name>
         <Organization>Red Database Security</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Andrea Micalizzi</Name>
         <Organization>TippingPoint's Zero Day Initiative</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Brian Gorenc</Name>
         <Organization>TippingPoint's Zero Day Initiative</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Dave Love</Name>
         <Organization>Dave Love</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>David Litchfield</Name>
         <Organization>V3rity</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Edward Torkington</Name>
         <Organization>Edward Torkington</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Esteban Martinez Fayo</Name>
         <Organization>Application Security, Inc.</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Frank Stuart</Name>
         <Organization>Frank Stuart</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>G &amp; W Laboratories</Name>
         <Organization>TippingPoint's Zero Day Initiative</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Joxean Koret</Name>
         <Organization>iSIGHT Partners Global Vulnerability Partnership</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Nathan Catlow</Name>
         <Organization>Recx</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Peter Maklary</Name>
         <Organization>LYNX Ltd.</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Pierre Ernst</Name>
         <Organization>IBM Canada</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Roberto Suggi Liverani</Name>
         <Organization>Security-Assessment.com</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Shrikant Antre</Name>
         <Organization>Network Intelligence</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Sow Ching Shiong</Name>
         <Organization>Secunia Research</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Stephen Kost</Name>
         <Organization>Integrigy</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Vishal K</Name>
         <Organization>Vishal K</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>William Hay</Name>
         <Organization>William Hay</Organization>
      </Acknowledgment>
   </Acknowledgments>
   <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
      <Branch Type="Vendor" Name="Oracle">
         <Branch Type="Product Family" Name="Oracle Database Server">
            <Branch Type="Product Name" Name="Oracle Database">
               <Branch Type="Product Version" Name="10.2.0.3">
                  <FullProductName ProductID="P-5V-10.2.0.3">Oracle Database Version 10.2.0.3</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="10.2.0.4">
                  <FullProductName ProductID="P-5V-10.2.0.4">Oracle Database Version 10.2.0.4</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="10.2.0.5">
                  <FullProductName ProductID="P-5V-10.2.0.5">Oracle Database Version 10.2.0.5</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.1.0.7">
                  <FullProductName ProductID="P-5V-11.1.0.7">Oracle Database Version 11.1.0.7</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.2.0.2">
                  <FullProductName ProductID="P-5V-11.2.0.2">Oracle Database Version 11.2.0.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.2.0.3">
                  <FullProductName ProductID="P-5V-11.2.0.3">Oracle Database Version 11.2.0.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle Spatial">
               <Branch Type="Product Version" Name="10.2.0.3">
                  <FullProductName ProductID="P-619V-10.2.0.3">Oracle Spatial Version 10.2.0.3</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="10.2.0.4">
                  <FullProductName ProductID="P-619V-10.2.0.4">Oracle Spatial Version 10.2.0.4</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="10.2.0.5">
                  <FullProductName ProductID="P-619V-10.2.0.5">Oracle Spatial Version 10.2.0.5</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.1.0.7">
                  <FullProductName ProductID="P-619V-11.1.0.7">Oracle Spatial Version 11.1.0.7</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.2.0.2">
                  <FullProductName ProductID="P-619V-11.2.0.2">Oracle Spatial Version 11.2.0.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.2.0.3">
                  <FullProductName ProductID="P-619V-11.2.0.3">Oracle Spatial Version 11.2.0.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Application Express">
               <Branch Type="Product Version" Name="4.0">
                  <FullProductName ProductID="P-1348V-4.0">Application Express Version 4.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="4.1">
                  <FullProductName ProductID="P-1348V-4.1">Application Express Version 4.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle E-Business Suite">
            <Branch Type="Product Name" Name="Oracle iStore">
               <Branch Type="Product Version" Name="11.5.10.2">
                  <FullProductName ProductID="P-384V-11.5.10.2">Oracle iStore Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.0.4">
                  <FullProductName ProductID="P-384V-12.0.4">Oracle iStore Version 12.0.4</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.0.6">
                  <FullProductName ProductID="P-384V-12.0.6">Oracle iStore Version 12.0.6</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.1.1">
                  <FullProductName ProductID="P-384V-12.1.1">Oracle iStore Version 12.1.1</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.1.2">
                  <FullProductName ProductID="P-384V-12.1.2">Oracle iStore Version 12.1.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.1.3">
                  <FullProductName ProductID="P-384V-12.1.3">Oracle iStore Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle Application Object Library">
               <Branch Type="Product Version" Name="12.0.6">
                  <FullProductName ProductID="P-510V-12.0.6">Oracle Application Object Library Version 12.0.6</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.1.3">
                  <FullProductName ProductID="P-510V-12.1.3">Oracle Application Object Library Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle Applications Framework">
               <Branch Type="Product Version" Name="12.1.3">
                  <FullProductName ProductID="P-1472V-12.1.3">Oracle Applications Framework Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle Applications Technology Stack">
               <Branch Type="Product Version" Name="12.0.6">
                  <FullProductName ProductID="P-1745V-12.0.6">Oracle Applications Technology Stack Version 12.0.6</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.1.3">
                  <FullProductName ProductID="P-1745V-12.1.3">Oracle Applications Technology Stack Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle Enterprise Manager Grid Control">
            <Branch Type="Product Name" Name="Enterprise Manager for Oracle Database">
               <Branch Type="Product Version" Name="10.2.0.5">
                  <FullProductName ProductID="P-1366V-10.2.0.5">Enterprise Manager for Oracle Database Version 10.2.0.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Enterprise Manager Base Platform">
               <Branch Type="Product Version" Name="-">
                  <FullProductName ProductID="P-1370V--">Enterprise Manager Base Platform Version -</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="10.2.0.5">
                  <FullProductName ProductID="P-1370V-10.2.0.5">Enterprise Manager Base Platform Version 10.2.0.5</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.1.0.1">
                  <FullProductName ProductID="P-1370V-11.1.0.1">Enterprise Manager Base Platform Version 11.1.0.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle Financial Services Software">
            <Branch Type="Product Name" Name="Oracle FLEXCUBE Universal Banking">
               <Branch Type="Product Version" Name="10.0.0 - 10.5.0">
                  <FullProductName ProductID="P-9052V-10.0.0 - 10.5.0">Oracle FLEXCUBE Universal Banking Version 10.0.0 - 10.5.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.0.0 - 11.2.0">
                  <FullProductName ProductID="P-9052V-11.0.0 - 11.2.0">Oracle FLEXCUBE Universal Banking Version 11.0.0 - 11.2.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.0.0 - 11.4.0">
                  <FullProductName ProductID="P-9052V-11.0.0 - 11.4.0">Oracle FLEXCUBE Universal Banking Version 11.0.0 - 11.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle FLEXCUBE Direct Banking">
               <Branch Type="Product Version" Name="5.0.2">
                  <FullProductName ProductID="P-9111V-5.0.2">Oracle FLEXCUBE Direct Banking Version 5.0.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="5.3.0 - 5.3.4">
                  <FullProductName ProductID="P-9111V-5.3.0 - 5.3.4">Oracle FLEXCUBE Direct Banking Version 5.3.0 - 5.3.4</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="6.0.1">
                  <FullProductName ProductID="P-9111V-6.0.1">Oracle FLEXCUBE Direct Banking Version 6.0.1</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="6.2.0">
                  <FullProductName ProductID="P-9111V-6.2.0">Oracle FLEXCUBE Direct Banking Version 6.2.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle Fusion Middleware">
            <Branch Type="Product Name" Name="Oracle JDeveloper">
               <Branch Type="Product Version" Name="10.1.3.5">
                  <FullProductName ProductID="P-807V-10.1.3.5">Oracle JDeveloper Version 10.1.3.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="BI Publisher (formerly XML Publisher)">
               <Branch Type="Product Version" Name="10.1.3.4.1">
                  <FullProductName ProductID="P-1479V-10.1.3.4.1">BI Publisher (formerly XML Publisher) Version 10.1.3.4.1</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="10.1.3.4.2">
                  <FullProductName ProductID="P-1479V-10.1.3.4.2">BI Publisher (formerly XML Publisher) Version 10.1.3.4.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Identity Manager">
               <Branch Type="Product Version" Name="11.1.1.3">
                  <FullProductName ProductID="P-1980V-11.1.1.3">Identity Manager Version 11.1.1.3</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.1.1.5">
                  <FullProductName ProductID="P-1980V-11.1.1.5">Identity Manager Version 11.1.1.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Identity Manager Connector">
               <Branch Type="Product Version" Name="9.1.0.4">
                  <FullProductName ProductID="P-1999V-9.1.0.4">Identity Manager Connector Version 9.1.0.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle Outside In Technology">
               <Branch Type="Product Version" Name="8.3.5">
                  <FullProductName ProductID="P-2276V-8.3.5">Oracle Outside In Technology Version 8.3.5</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="8.3.7">
                  <FullProductName ProductID="P-2276V-8.3.7">Oracle Outside In Technology Version 8.3.7</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle JRockit">
               <Branch Type="Product Version" Name="27.7.1 and before: JKD/JRE 5 and 6">
                  <FullProductName ProductID="P-5260V-27.7.1 and before: JKD/JRE 5 and 6">Oracle JRockit Version 27.7.1 and before: JKD/JRE 5 and 6</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="28.2.2 and before: JDK/JRE 5 and 6">
                  <FullProductName ProductID="P-5260V-28.2.2 and before: JDK/JRE 5 and 6">Oracle JRockit Version 28.2.2 and before: JDK/JRE 5 and 6</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle WebCenter Forms Recognition">
               <Branch Type="Product Version" Name="10.1.3.5">
                  <FullProductName ProductID="P-5746V-10.1.3.5">Oracle WebCenter Forms Recognition Version 10.1.3.5</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle Industry Applications">
            <Branch Type="Product Name" Name="Siebel Life Sciences">
               <Branch Type="Product Version" Name="7.7">
                  <FullProductName ProductID="P-9173V-7.7">Siebel Life Sciences Version 7.7</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="7.8">
                  <FullProductName ProductID="P-9173V-7.8">Siebel Life Sciences Version 7.8</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="8.0.0.x">
                  <FullProductName ProductID="P-9173V-8.0.0.x">Siebel Life Sciences Version 8.0.0.x</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="8.1.1.x">
                  <FullProductName ProductID="P-9173V-8.1.1.x">Siebel Life Sciences Version 8.1.1.x</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="8.2.2.x">
                  <FullProductName ProductID="P-9173V-8.2.2.x">Siebel Life Sciences Version 8.2.2.x</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle MySQL">
            <Branch Type="Product Name" Name="MySQL Server">
               <Branch Type="Product Version" Name="5.1.60 and earlier">
                  <FullProductName ProductID="P-8478V-5.1.60 and earlier">MySQL Server Version 5.1.60 and earlier</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="5.1.61 and earlier">
                  <FullProductName ProductID="P-8478V-5.1.61 and earlier">MySQL Server Version 5.1.61 and earlier</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="5.5.19 and earlier">
                  <FullProductName ProductID="P-8478V-5.5.19 and earlier">MySQL Server Version 5.5.19 and earlier</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="5.5.21 and earlier">
                  <FullProductName ProductID="P-8478V-5.5.21 and earlier">MySQL Server Version 5.5.21 and earlier</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle PeopleSoft Products">
            <Branch Type="Product Name" Name="PeopleSoft Enterprise CRM Sales">
               <Branch Type="Product Version" Name="9.1">
                  <FullProductName ProductID="P-4895V-9.1">PeopleSoft Enterprise CRM Sales Version 9.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="PeopleSoft Enterprise FIN Receivables">
               <Branch Type="Product Version" Name="9.0">
                  <FullProductName ProductID="P-5021V-9.0">PeopleSoft Enterprise FIN Receivables Version 9.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="9.1">
                  <FullProductName ProductID="P-5021V-9.1">PeopleSoft Enterprise FIN Receivables Version 9.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="PeopleSoft Enterprise HRMS Candidate Gateway">
               <Branch Type="Product Version" Name="9.1">
                  <FullProductName ProductID="P-5043V-9.1">PeopleSoft Enterprise HRMS Candidate Gateway Version 9.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="PeopleSoft Enterprise HRMS eCompensation">
               <Branch Type="Product Version" Name="8.9 through Bundle #26">
                  <FullProductName ProductID="P-5046V-8.9 through Bundle #26">PeopleSoft Enterprise HRMS eCompensation Version 8.9 through Bundle #26</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="PeopleSoft Enterprise HRMS eCompensation Manager Desktop">
               <Branch Type="Product Version" Name="9.0">
                  <FullProductName ProductID="P-5047V-9.0">PeopleSoft Enterprise HRMS eCompensation Manager Desktop Version 9.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="PeopleSoft Enterprise HRMS Human Resources">
               <Branch Type="Product Version" Name="9.1 Bundle #9">
                  <FullProductName ProductID="P-5071V-9.1 Bundle #9">PeopleSoft Enterprise HRMS Human Resources Version 9.1 Bundle #9</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="PeopleSoft Enterprise PT PeopleTools">
               <Branch Type="Product Version" Name="8.50">
                  <FullProductName ProductID="P-5085V-8.50">PeopleSoft Enterprise PT PeopleTools Version 8.50</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="8.51">
                  <FullProductName ProductID="P-5085V-8.51">PeopleSoft Enterprise PT PeopleTools Version 8.51</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="8.52">
                  <FullProductName ProductID="P-5085V-8.52">PeopleSoft Enterprise PT PeopleTools Version 8.52</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="PeopleSoft Enterprise PRTL Interaction Hub">
               <Branch Type="Product Version" Name="9.1">
                  <FullProductName ProductID="P-5090V-9.1">PeopleSoft Enterprise PRTL Interaction Hub Version 9.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="PeopleSoft Enterprise SCM Billing">
               <Branch Type="Product Version" Name="9.0">
                  <FullProductName ProductID="P-5109V-9.0">PeopleSoft Enterprise SCM Billing Version 9.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="9.1">
                  <FullProductName ProductID="P-5109V-9.1">PeopleSoft Enterprise SCM Billing Version 9.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="PeopleSoft Enterprise SCM eProcurement">
               <Branch Type="Product Version" Name="9.0">
                  <FullProductName ProductID="P-5118V-9.0">PeopleSoft Enterprise SCM eProcurement Version 9.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="9.1">
                  <FullProductName ProductID="P-5118V-9.1">PeopleSoft Enterprise SCM eProcurement Version 9.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle Primavera Products Suite">
            <Branch Type="Product Name" Name="Primavera P6 Enterprise Project Portfolio Management">
               <Branch Type="Product Version" Name="6.2.1">
                  <FullProductName ProductID="P-5579V-6.2.1">Primavera P6 Enterprise Project Portfolio Management Version 6.2.1</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="8.0">
                  <FullProductName ProductID="P-5579V-8.0">Primavera P6 Enterprise Project Portfolio Management Version 8.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="8.1">
                  <FullProductName ProductID="P-5579V-8.1">Primavera P6 Enterprise Project Portfolio Management Version 8.1</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="8.2">
                  <FullProductName ProductID="P-5579V-8.2">Primavera P6 Enterprise Project Portfolio Management Version 8.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle Sun Products Suite">
            <Branch Type="Product Name" Name="Oracle GlassFish Server">
               <Branch Type="Product Version" Name="GlassFish Enterprise Server 3.1.1">
                  <FullProductName ProductID="P-8493V-GlassFish Enterprise Server 3.1.1">Oracle GlassFish Server Version GlassFish Enterprise Server 3.1.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle iPlanet Web Server">
               <Branch Type="Product Version" Name="7.0">
                  <FullProductName ProductID="P-8543V-7.0">Oracle iPlanet Web Server Version 7.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Solaris Products">
               <Branch Type="Product Version" Name="10">
                  <FullProductName ProductID="P-8752V-10">Solaris Products Version 10</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11">
                  <FullProductName ProductID="P-8752V-11">Solaris Products Version 11</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="6.1">
                  <FullProductName ProductID="P-8752V-6.1">Solaris Products Version 6.1</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="6.2">
                  <FullProductName ProductID="P-8752V-6.2">Solaris Products Version 6.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="8">
                  <FullProductName ProductID="P-8752V-8">Solaris Products Version 8</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="9">
                  <FullProductName ProductID="P-8752V-9">Solaris Products Version 9</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="XCP 1110">
                  <FullProductName ProductID="P-8752V-XCP 1110">Solaris Products Version XCP 1110</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="XCP 1110 and earlier">
                  <FullProductName ProductID="P-8752V-XCP 1110 and earlier">Solaris Products Version XCP 1110 and earlier</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle Supply Chain Products Suite">
            <Branch Type="Product Name" Name="Oracle Agile Product Data Management for Process">
               <Branch Type="Product Version" Name="6.0.0">
                  <FullProductName ProductID="P-4445V-6.0.0">Oracle Agile Product Data Management for Process Version 6.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle Agile Product Supplier Collaboration for Process">
               <Branch Type="Product Version" Name="6.0.0">
                  <FullProductName ProductID="P-4447V-6.0.0">Oracle Agile Product Supplier Collaboration for Process Version 6.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle Agile New Product Development and Introduction for Process">
               <Branch Type="Product Version" Name="6.0.0">
                  <FullProductName ProductID="P-4448V-6.0.0">Oracle Agile New Product Development and Introduction for Process Version 6.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle AutoVue Office">
               <Branch Type="Product Version" Name="20.0.2">
                  <FullProductName ProductID="P-4449V-20.0.2">Oracle AutoVue Office Version 20.0.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
      </Branch>
   </ProductTree>
   <Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0208</Title>
      <Notes>
         <Note Type="Details" Ordinal="1" Title="Details" Audience="All">Vulnerability in the Oracle Grid Engine component of Oracle Sun Products Suite (subcomponent: qrsh).  Supported versions that are affected are 6.1 and  6.2. Easily exploitable vulnerability allows successful authenticated network attacks via RSH.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.  CVSS Base Score 9.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:S/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0208</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-6.1</ProductID>
            <ProductID>P-8752V-6.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>9.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-8752V-6.1</ProductID>
            <ProductID>P-8752V-6.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0509</Title>
      <Notes>
         <Note Type="Details" Ordinal="2" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Software (subcomponent: Core-Base).  Supported versions that are affected are 5.0.2 and  5.3.0 - 5.3.4. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle FLEXCUBE Direct Banking accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0509</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9111V-5.0.2</ProductID>
            <ProductID>P-9111V-5.3.0 - 5.3.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-9111V-5.0.2</ProductID>
            <ProductID>P-9111V-5.3.0 - 5.3.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="3" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0510</Title>
      <Notes>
         <Note Type="Details" Ordinal="3" Title="Details" Audience="All">Vulnerability in the Core RDBMS component of Oracle Database Server.  Supported versions that are affected are 10.2.0.3, 10.2.0.4, 10.2.0.5 and 11.1.0.7. Easily exploitable vulnerability allows successful unauthenticated network attacks via Oracle Net.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Core RDBMS accessible data and ability to cause a partial denial of service (partial DOS) of Core RDBMS.  CVSS Base Score 6.4 (Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0510</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-10.2.0.3</ProductID>
            <ProductID>P-5V-10.2.0.4</ProductID>
            <ProductID>P-5V-10.2.0.5</ProductID>
            <ProductID>P-5V-11.1.0.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-5V-10.2.0.3</ProductID>
            <ProductID>P-5V-10.2.0.4</ProductID>
            <ProductID>P-5V-10.2.0.5</ProductID>
            <ProductID>P-5V-11.1.0.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="4" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0511</Title>
      <Notes>
         <Note Type="Details" Ordinal="4" Title="Details" Audience="All">Vulnerability in the OCI  component of Oracle Database Server.  Supported versions that are affected are 10.2.0.3, 10.2.0.4 and  11.1.0.7. Easily exploitable vulnerability allows successful unauthenticated network attacks via Oracle NET.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some OCI  accessible data as well as  read access to a subset of OCI  accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0511</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-10.2.0.3</ProductID>
            <ProductID>P-5V-10.2.0.4</ProductID>
            <ProductID>P-5V-11.1.0.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-5V-10.2.0.3</ProductID>
            <ProductID>P-5V-10.2.0.4</ProductID>
            <ProductID>P-5V-11.1.0.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="5" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0512</Title>
      <Notes>
         <Note Type="Details" Ordinal="5" Title="Details" Audience="All">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Enterprise Config Management). For supported versions that are affected see note. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Enterprise Manager Base Platform accessible data as well as  read access to all Enterprise Manager Base Platform accessible data.   Note: Fixed in all supported releases and patchsets. CVSS Base Score 5.5 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0512</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V--</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-1370V--</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="6" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0513</Title>
      <Notes>
         <Note Type="Details" Ordinal="6" Title="Details" Audience="All">Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: REST Services).  Supported versions that are affected are 12.0.6 and  12.1.3. Very difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Application Object Library accessible data.  CVSS Base Score 2.6 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:H/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0513</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-510V-12.0.6</ProductID>
            <ProductID>P-510V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.6</BaseScore>
            <Vector>AV:N/AC:H/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-510V-12.0.6</ProductID>
            <ProductID>P-510V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="7" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0514</Title>
      <Notes>
         <Note Type="Details" Ordinal="7" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise CRM component of Oracle PeopleSoft Products (subcomponent: SEC).   The supported version that is affected is 9.1. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of PeopleSoft Enterprise CRM accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0514</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4895V-9.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-4895V-9.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="8" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0515</Title>
      <Notes>
         <Note Type="Details" Ordinal="8" Title="Details" Audience="All">Vulnerability in the Identity Manager Connector component of Oracle Fusion Middleware (subcomponent: Database User).   The supported version that is affected is 9.1.0.4. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Identity Manager Connector accessible data.  CVSS Base Score 4.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0515</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1999V-9.1.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-1999V-9.1.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="9" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0516</Title>
      <Notes>
         <Note Type="Details" Ordinal="9" Title="Details" Audience="All">Vulnerability in the Oracle iPlanet Web Server component of Oracle Sun Products Suite (subcomponent: Administration Console).   The supported version that is affected is 7.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized takeover of Oracle iPlanet Web Server possibly including arbitrary code execution within the Oracle iPlanet Web Server.  CVSS Base Score 6.8 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0516</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8543V-7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-8543V-7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="10" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0517</Title>
      <Notes>
         <Note Type="Details" Ordinal="10" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise HRMS component of Oracle PeopleSoft Products (subcomponent: eCompensation Manager Desktop).   The supported version that is affected is 9.0. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some PeopleSoft Enterprise HRMS accessible data as well as  read access to a subset of PeopleSoft Enterprise HRMS accessible data.  CVSS Base Score 5.5 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0517</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5047V-9.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-5047V-9.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="11" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0519</Title>
      <Notes>
         <Note Type="Details" Ordinal="11" Title="Details" Audience="All">Vulnerability in the Core RDBMS component of Oracle Database Server.  This vulnerability requires Create library, create procedure privileges for a successful attack.   The supported version that is affected is 11.2.0.2. Very difficult to exploit vulnerability allows successful authenticated network attacks via Oracle NET.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: The vulnerability affects Microsoft Windows platforms only. CVSS Base Score 7.1 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:S/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:H/Au:S/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0519</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-11.2.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.1</BaseScore>
            <Vector>AV:N/AC:H/Au:S/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-5V-11.2.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="12" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0520</Title>
      <Notes>
         <Note Type="Details" Ordinal="12" Title="Details" Audience="All">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Security Framework).  Supported versions that are affected are 10.2.0.5 and  11.1.0.1. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Enterprise Manager Base Platform accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0520</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-10.2.0.5</ProductID>
            <ProductID>P-1370V-11.1.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-1370V-10.2.0.5</ProductID>
            <ProductID>P-1370V-11.1.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="13" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0521</Title>
      <Notes>
         <Note Type="Details" Ordinal="13" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise HCM component of Oracle PeopleSoft Products (subcomponent: Human Resources).   The supported version that is affected is 9.1 Bundle #9. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of PeopleSoft Enterprise HCM accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0521</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5071V-9.1 Bundle #9</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-5071V-9.1 Bundle #9</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="14" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0522</Title>
      <Notes>
         <Note Type="Details" Ordinal="14" Title="Details" Audience="All">Vulnerability in the Oracle JDeveloper component of Oracle Fusion Middleware (subcomponent: Java Business Objects).   The supported version that is affected is 10.1.3.5. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle JDeveloper accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0522</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-807V-10.1.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-807V-10.1.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="15" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0523</Title>
      <Notes>
         <Note Type="Details" Ordinal="15" Title="Details" Audience="All">Vulnerability in the Oracle Grid Engine component of Oracle Sun Products Suite (subcomponent: sgepasswd).  Supported versions that are affected are 6.1 and  6.2. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.  CVSS Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:L/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0523</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-6.1</ProductID>
            <ProductID>P-8752V-6.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.2</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-8752V-6.1</ProductID>
            <ProductID>P-8752V-6.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="16" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0524</Title>
      <Notes>
         <Note Type="Details" Ordinal="16" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: File Processing).  Supported versions that are affected are 8.50, 8.51 and  8.52. Easily exploitable vulnerability requiring logon to Operating System plus additional login/authentication to component or subcomponent.  Successful attack of this vulnerability can escalate attacker privileges resulting in unauthorized  update, insert or delete access to some PeopleSoft Enterprise PeopleTools accessible data as well as  read access to a subset of PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 3.2 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:L/AC:L/Au:S/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0524</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.2</BaseScore>
            <Vector>AV:L/AC:L/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="17" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0525</Title>
      <Notes>
         <Note Type="Details" Ordinal="17" Title="Details" Audience="All">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Enterprise Config Management).  Supported versions that are affected are 10.2.0.5 and  11.1.0.1. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to all Enterprise Manager Base Platform accessible data as well as  update, insert or delete access to some Enterprise Manager Base Platform accessible data.  CVSS Base Score 4.9 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:P+/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0525</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-10.2.0.5</ProductID>
            <ProductID>P-1370V-11.1.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.9</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-1370V-10.2.0.5</ProductID>
            <ProductID>P-1370V-11.1.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="18" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0526</Title>
      <Notes>
         <Note Type="Details" Ordinal="18" Title="Details" Audience="All">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Schema Management).   The supported version that is affected is 10.2.0.5. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Enterprise Manager Base Platform accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0526</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1366V-10.2.0.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-1366V-10.2.0.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="19" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0527</Title>
      <Notes>
         <Note Type="Details" Ordinal="19" Title="Details" Audience="All">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Schema Management).   The supported version that is affected is 10.2.0.5. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Enterprise Manager Base Platform accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0527</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1366V-10.2.0.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-1366V-10.2.0.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="20" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0528</Title>
      <Notes>
         <Note Type="Details" Ordinal="20" Title="Details" Audience="All">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Security Framework). For supported versions that are affected see note. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Enterprise Manager Base Platform accessible data as well as  read access to a subset of Enterprise Manager Base Platform accessible data.   Note: Fixed in all supported releases and patchsets. CVSS Base Score 5.8 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0528</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V--</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-1370V--</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="21" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0529</Title>
      <Notes>
         <Note Type="Details" Ordinal="21" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: core).   The supported version that is affected is 8.51. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0529</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.51</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-5085V-8.51</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="22" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0530</Title>
      <Notes>
         <Note Type="Details" Ordinal="22" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise SCM component of Oracle PeopleSoft Products (subcomponent: eProcurement).  Supported versions that are affected are 9.0 and  9.1. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some PeopleSoft Enterprise SCM accessible data.  CVSS Base Score 4.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0530</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5118V-9.0</ProductID>
            <ProductID>P-5118V-9.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-5118V-9.0</ProductID>
            <ProductID>P-5118V-9.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="23" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0531</Title>
      <Notes>
         <Note Type="Details" Ordinal="23" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise Portal component of Oracle PeopleSoft Products (subcomponent: Enterprise Portal).   The supported version that is affected is 9.1. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some PeopleSoft Enterprise Portal accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0531</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5090V-9.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-5090V-9.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="24" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0532</Title>
      <Notes>
         <Note Type="Details" Ordinal="24" Title="Details" Audience="All">Vulnerability in the Identity Manager component of Oracle Fusion Middleware (subcomponent: User Config Management).  Supported versions that are affected are 11.1.1.3 and  11.1.1.5. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Identity Manager accessible data as well as  read access to all Identity Manager accessible data.  CVSS Base Score 5.5 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0532</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1980V-11.1.1.3</ProductID>
            <ProductID>P-1980V-11.1.1.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-1980V-11.1.1.3</ProductID>
            <ProductID>P-1980V-11.1.1.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="25" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0533</Title>
      <Notes>
         <Note Type="Details" Ordinal="25" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise FCSM component of Oracle PeopleSoft Products (subcomponent: Receivables).  Supported versions that are affected are 9.0 and  9.1. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of PeopleSoft Enterprise FCSM accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0533</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5021V-9.0</ProductID>
            <ProductID>P-5021V-9.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-5021V-9.0</ProductID>
            <ProductID>P-5021V-9.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="26" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0534</Title>
      <Notes>
         <Note Type="Details" Ordinal="26" Title="Details" Audience="All">Vulnerability in the RDBMS Core component of Oracle Database Server.  This vulnerability requires Create Session privileges for a successful attack.  Supported versions that are affected are 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2 and  11.2.0.3. Easily exploitable vulnerability allows successful authenticated network attacks via Oracle Net.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some RDBMS Core accessible data.  CVSS Base Score 4.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0534</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-10.2.0.3</ProductID>
            <ProductID>P-5V-10.2.0.4</ProductID>
            <ProductID>P-5V-10.2.0.5</ProductID>
            <ProductID>P-5V-11.1.0.7</ProductID>
            <ProductID>P-5V-11.2.0.2</ProductID>
            <ProductID>P-5V-11.2.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-5V-10.2.0.3</ProductID>
            <ProductID>P-5V-10.2.0.4</ProductID>
            <ProductID>P-5V-10.2.0.5</ProductID>
            <ProductID>P-5V-11.1.0.7</ProductID>
            <ProductID>P-5V-11.2.0.2</ProductID>
            <ProductID>P-5V-11.2.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="27" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0535</Title>
      <Notes>
         <Note Type="Details" Ordinal="27" Title="Details" Audience="All">Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Change Password Page).  Supported versions that are affected are 12.0.6 and  12.1.3. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Application Object Library accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0535</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1745V-12.0.6</ProductID>
            <ProductID>P-1745V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-1745V-12.0.6</ProductID>
            <ProductID>P-1745V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="28" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0536</Title>
      <Notes>
         <Note Type="Details" Ordinal="28" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise HRMS component of Oracle PeopleSoft Products (subcomponent: eCompensation).   The supported version that is affected is 8.9 through Bundle #26. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of PeopleSoft Enterprise HRMS accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0536</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5046V-8.9 through Bundle #26</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-5046V-8.9 through Bundle #26</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="29" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0537</Title>
      <Notes>
         <Note Type="Details" Ordinal="29" Title="Details" Audience="All">Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: HTML pages).   The supported version that is affected is 12.1.3. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Application Object Library accessible data as well as  read access to all Oracle Application Object Library accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0537</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1472V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-1472V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="30" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0538</Title>
      <Notes>
         <Note Type="Details" Ordinal="30" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Search).  Supported versions that are affected are 8.50, 8.51 and  8.52. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all PeopleSoft Enterprise PeopleTools accessible data as well as  read access to all PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 5.5 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0538</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="31" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0539</Title>
      <Notes>
         <Note Type="Details" Ordinal="31" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: bsmconv(1M), bsmunconv(1M)).  Supported versions that are affected are 8, 9 and  10. Very difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.  CVSS Base Score 6.2 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:H/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:L/AC:H/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0539</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-8</ProductID>
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.2</BaseScore>
            <Vector>AV:L/AC:H/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-8752V-8</ProductID>
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="32" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0541</Title>
      <Notes>
         <Note Type="Details" Ordinal="32" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Software (subcomponent: Core-My Services).  Supported versions that are affected are 5.0.2, 5.3.0 - 5.3.4, 6.0.1 and  6.2.0. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle FLEXCUBE Direct Banking accessible data.  CVSS Base Score 3.5 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0541</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9111V-5.0.2</ProductID>
            <ProductID>P-9111V-5.3.0 - 5.3.4</ProductID>
            <ProductID>P-9111V-6.0.1</ProductID>
            <ProductID>P-9111V-6.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-9111V-5.0.2</ProductID>
            <ProductID>P-9111V-5.3.0 - 5.3.4</ProductID>
            <ProductID>P-9111V-6.0.1</ProductID>
            <ProductID>P-9111V-6.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="33" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0542</Title>
      <Notes>
         <Note Type="Details" Ordinal="33" Title="Details" Audience="All">Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: Runtime Catalog).  Supported versions that are affected are 11.5.10.2, 12.0.4, 12.0.6, 12.1.1, 12.1.2 and 12.1.3. Very difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle iStore accessible data.  CVSS Base Score 2.6 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:H/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0542</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-384V-11.5.10.2</ProductID>
            <ProductID>P-384V-12.0.4</ProductID>
            <ProductID>P-384V-12.0.6</ProductID>
            <ProductID>P-384V-12.1.1</ProductID>
            <ProductID>P-384V-12.1.2</ProductID>
            <ProductID>P-384V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.6</BaseScore>
            <Vector>AV:N/AC:H/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-384V-11.5.10.2</ProductID>
            <ProductID>P-384V-12.0.4</ProductID>
            <ProductID>P-384V-12.0.6</ProductID>
            <ProductID>P-384V-12.1.1</ProductID>
            <ProductID>P-384V-12.1.2</ProductID>
            <ProductID>P-384V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="34" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0543</Title>
      <Notes>
         <Note Type="Details" Ordinal="34" Title="Details" Audience="All">Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: Administration).  Supported versions that are affected are 10.1.3.4.1 and  10.1.3.4.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some BI Publisher (formerly XML Publisher) accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0543</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1479V-10.1.3.4.1</ProductID>
            <ProductID>P-1479V-10.1.3.4.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-1479V-10.1.3.4.1</ProductID>
            <ProductID>P-1479V-10.1.3.4.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="35" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0544</Title>
      <Notes>
         <Note Type="Details" Ordinal="35" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Software (subcomponent: Core).  Supported versions that are affected are 10.0.0 - 10.5.0 and  11.0.0 - 11.4.0. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle FLEXCUBE Universal Banking accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0544</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9052V-10.0.0 - 10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-9052V-10.0.0 - 10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="36" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0545</Title>
      <Notes>
         <Note Type="Details" Ordinal="36" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Software (subcomponent: Core).  Supported versions that are affected are 10.0.0 - 10.5.0 and  11.0.0 - 11.2.0. Very difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle FLEXCUBE Universal Banking accessible data as well as  read access to a subset of Oracle FLEXCUBE Universal Banking accessible data.  CVSS Base Score 3.6 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:H/Au:S/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0545</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9052V-10.0.0 - 10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.6</BaseScore>
            <Vector>AV:N/AC:H/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-9052V-10.0.0 - 10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="37" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0546</Title>
      <Notes>
         <Note Type="Details" Ordinal="37" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Software (subcomponent: Core).  Supported versions that are affected are 10.0.0 - 10.5.0 and  11.0.0 - 11.2.0. Very difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle FLEXCUBE Universal Banking accessible data as well as  read access to a subset of Oracle FLEXCUBE Universal Banking accessible data.  CVSS Base Score 3.6 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:H/Au:S/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0546</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9052V-10.0.0 - 10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.6</BaseScore>
            <Vector>AV:N/AC:H/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-9052V-10.0.0 - 10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="38" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0548</Title>
      <Notes>
         <Note Type="Details" Ordinal="38" Title="Details" Audience="All">Vulnerability in the SPARC Enterprise M Series Servers component of Oracle Sun Products Suite (subcomponent: XSCF Control Package (XCP)).  Supported versions that are affected are XCP 1110 and earlier. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of SPARC Enterprise M Series Servers accessible data.  CVSS Base Score 2.1 (Confidentiality impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:L/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0548</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-XCP 1110 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-8752V-XCP 1110 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="39" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0549</Title>
      <Notes>
         <Note Type="Details" Ordinal="39" Title="Details" Audience="All">Vulnerability in the Oracle AutoVue Office component of Oracle Supply Chain Products Suite (subcomponent: Desktop API).   The supported version that is affected is 20.0.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle AutoVue Office accessible data as well as  read access to a subset of Oracle AutoVue Office accessible data and ability to cause a partial denial of service (partial DOS) of Oracle AutoVue Office.  CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0549</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4449V-20.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-4449V-20.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="40" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0550</Title>
      <Notes>
         <Note Type="Details" Ordinal="40" Title="Details" Audience="All">Vulnerability in the GlassFish Enterprise Server component of Oracle Sun Products Suite (subcomponent: Web Container).   The supported version that is affected is GlassFish Enterprise Server 3.1.1. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some GlassFish Enterprise Server accessible data as well as  read access to a subset of GlassFish Enterprise Server accessible data and ability to cause a partial denial of service (partial DOS) of GlassFish Enterprise Server.  CVSS Base Score 6.8 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0550</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8493V-GlassFish Enterprise Server 3.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-8493V-GlassFish Enterprise Server 3.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="41" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0551</Title>
      <Notes>
         <Note Type="Details" Ordinal="41" Title="Details" Audience="All">Vulnerability in the GlassFish Enterprise Server component of Oracle Sun Products Suite (subcomponent: Web Container).   The supported version that is affected is GlassFish Enterprise Server 3.1.1. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some GlassFish Enterprise Server accessible data as well as  read access to a subset of GlassFish Enterprise Server accessible data.  CVSS Base Score 5.8 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0551</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8493V-GlassFish Enterprise Server 3.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-8493V-GlassFish Enterprise Server 3.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="42" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0552</Title>
      <Notes>
         <Note Type="Details" Ordinal="42" Title="Details" Audience="All">Vulnerability in the Oracle Spatial component of Oracle Database Server.  This vulnerability requires Create session, create index, alter index, create table  privileges for a successful attack.  Supported versions that are affected are 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2 and  11.2.0.3. Easily exploitable vulnerability allows successful authenticated network attacks via Oracle NET.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: The CVSS Base Score is 9.0 only for Windows. For Linux, Unix and other platforms, the CVSS Base Score is 6.5, and the impacts for Confidentiality, Integrity and Availability are Partial+. CVSS Base Score 9.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:S/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0552</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-619V-10.2.0.3</ProductID>
            <ProductID>P-619V-10.2.0.4</ProductID>
            <ProductID>P-619V-10.2.0.5</ProductID>
            <ProductID>P-619V-11.1.0.7</ProductID>
            <ProductID>P-619V-11.2.0.2</ProductID>
            <ProductID>P-619V-11.2.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>9.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-619V-10.2.0.3</ProductID>
            <ProductID>P-619V-10.2.0.4</ProductID>
            <ProductID>P-619V-10.2.0.5</ProductID>
            <ProductID>P-619V-11.1.0.7</ProductID>
            <ProductID>P-619V-11.2.0.2</ProductID>
            <ProductID>P-619V-11.2.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="43" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0554</Title>
      <Notes>
         <Note Type="Details" Ordinal="43" Title="Details" Audience="All">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Image Export SDK).  Supported versions that are affected are 8.3.5 and  8.3.7. Easily exploitable vulnerability allows successful unauthenticated network attacks via None.  Successful attack of this vulnerability can result in unauthorized takeover of Oracle Outside In Technology possibly including arbitrary code execution within the Oracle Outside In Technology.   Note: Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. In determining the CVSS score for this vulnerability we have assumed the hosting software exposes this functionality over the network without authentication. If this is not the case, the CVSS score could be much lower. CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0554</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="44" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0555</Title>
      <Notes>
         <Note Type="Details" Ordinal="44" Title="Details" Audience="All">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Image Export SDK).  Supported versions that are affected are 8.3.5 and  8.3.7. Easily exploitable vulnerability allows successful unauthenticated network attacks via None.  Successful attack of this vulnerability can result in unauthorized takeover of Oracle Outside In Technology possibly including arbitrary code execution within the Oracle Outside In Technology.   Note: Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. In determining the CVSS score for this vulnerability we have assumed the hosting software exposes this functionality over the network without authentication. If this is not the case, the CVSS score could be much lower. CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0555</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="45" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0556</Title>
      <Notes>
         <Note Type="Details" Ordinal="45" Title="Details" Audience="All">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Image Export SDK).  Supported versions that are affected are 8.3.5 and  8.3.7. Easily exploitable vulnerability allows successful unauthenticated network attacks via None.  Successful attack of this vulnerability can result in unauthorized takeover of Oracle Outside In Technology possibly including arbitrary code execution within the Oracle Outside In Technology.   Note: Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. In determining the CVSS score for this vulnerability we have assumed the hosting software exposes this functionality over the network without authentication. If this is not the case, the CVSS score could be much lower. CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0556</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="46" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0557</Title>
      <Notes>
         <Note Type="Details" Ordinal="46" Title="Details" Audience="All">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Image Export SDK).  Supported versions that are affected are 8.3.5 and  8.3.7. Easily exploitable vulnerability allows successful unauthenticated network attacks via None.  Successful attack of this vulnerability can result in unauthorized takeover of Oracle Outside In Technology possibly including arbitrary code execution within the Oracle Outside In Technology.   Note: Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. In determining the CVSS score for this vulnerability we have assumed the hosting software exposes this functionality over the network without authentication. If this is not the case, the CVSS score could be much lower. CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0557</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="47" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0558</Title>
      <Notes>
         <Note Type="Details" Ordinal="47" Title="Details" Audience="All">Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web application).  Supported versions that are affected are 6.2.1, 8.0, 8.1 and  8.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Primavera P6 Enterprise Project Portfolio Management accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0558</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5579V-6.2.1</ProductID>
            <ProductID>P-5579V-8.0</ProductID>
            <ProductID>P-5579V-8.1</ProductID>
            <ProductID>P-5579V-8.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-5579V-6.2.1</ProductID>
            <ProductID>P-5579V-8.0</ProductID>
            <ProductID>P-5579V-8.1</ProductID>
            <ProductID>P-5579V-8.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="48" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0559</Title>
      <Notes>
         <Note Type="Details" Ordinal="48" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise SCM component of Oracle PeopleSoft Products (subcomponent: Billing).  Supported versions that are affected are 9.0 and  9.1. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of PeopleSoft Enterprise SCM accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0559</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5109V-9.0</ProductID>
            <ProductID>P-5109V-9.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-5109V-9.0</ProductID>
            <ProductID>P-5109V-9.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="49" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0560</Title>
      <Notes>
         <Note Type="Details" Ordinal="49" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Portal).  Supported versions that are affected are 8.50, 8.51 and  8.52. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0560</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="50" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0561</Title>
      <Notes>
         <Note Type="Details" Ordinal="50" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: PIA Core Technology).  Supported versions that are affected are 8.50, 8.51 and  8.52. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0561</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="51" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0562</Title>
      <Notes>
         <Note Type="Details" Ordinal="51" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise HRMS component of Oracle PeopleSoft Products (subcomponent: Candidate Gateway).   The supported version that is affected is 9.1. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of PeopleSoft Enterprise HRMS accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0562</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5043V-9.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-5043V-9.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="52" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0564</Title>
      <Notes>
         <Note Type="Details" Ordinal="52" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Query).  Supported versions that are affected are 8.50 and  8.51. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized takeover of PeopleSoft Enterprise PeopleTools possibly including arbitrary code execution within the PeopleSoft Enterprise PeopleTools.  CVSS Base Score 6.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0564</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="53" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0565</Title>
      <Notes>
         <Note Type="Details" Ordinal="53" Title="Details" Audience="All">Vulnerability in the Oracle Agile component of Oracle Supply Chain Products Suite (subcomponent: Install).   The supported version that is affected is 6.0.0. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Agile accessible data as well as  read access to all Oracle Agile accessible data.  CVSS Base Score 5.5 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0565</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4448V-6.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-4448V-6.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="54" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0566</Title>
      <Notes>
         <Note Type="Details" Ordinal="54" Title="Details" Audience="All">Vulnerability in the Oracle Agile component of Oracle Supply Chain Products Suite (subcomponent: Supplier Portal).   The supported version that is affected is 6.0.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Agile accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0566</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4447V-6.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-4447V-6.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="55" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0567</Title>
      <Notes>
         <Note Type="Details" Ordinal="55" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Software (subcomponent: Core).  Supported versions that are affected are 10.0.0 - 10.5.0 and  11.0.0 - 11.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle FLEXCUBE Universal Banking accessible data as well as  read access to a subset of Oracle FLEXCUBE Universal Banking accessible data.  CVSS Base Score 5.5 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0567</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9052V-10.0.0 - 10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-9052V-10.0.0 - 10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="56" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0571</Title>
      <Notes>
         <Note Type="Details" Ordinal="56" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Software (subcomponent: Core).  Supported versions that are affected are 10.0.0 - 10.5.0 and  11.0.0 - 11.4.0. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle FLEXCUBE Universal Banking accessible data.  CVSS Base Score 4.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0571</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9052V-10.0.0 - 10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-9052V-10.0.0 - 10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="57" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0573</Title>
      <Notes>
         <Note Type="Details" Ordinal="57" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Software (subcomponent: Core).  Supported versions that are affected are 10.0.0 - 10.5.0 and  11.0.0 - 11.4.0. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle FLEXCUBE Universal Banking accessible data as well as  read access to a subset of Oracle FLEXCUBE Universal Banking accessible data.  CVSS Base Score 4.9 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0573</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9052V-10.0.0 - 10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.9</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-9052V-10.0.0 - 10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="58" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0575</Title>
      <Notes>
         <Note Type="Details" Ordinal="58" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Software (subcomponent: Core).  Supported versions that are affected are 10.0.0 - 10.5.0 and  11.0.0 - 11.2.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle FLEXCUBE Universal Banking accessible data as well as  read access to a subset of Oracle FLEXCUBE Universal Banking accessible data and ability to cause a partial denial of service (partial DOS) of Oracle FLEXCUBE Universal Banking.  CVSS Base Score 6.8 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0575</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9052V-10.0.0 - 10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-9052V-10.0.0 - 10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="59" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0576</Title>
      <Notes>
         <Note Type="Details" Ordinal="59" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Software (subcomponent: Core-Help).  Supported versions that are affected are 6.0.1 and  6.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle FLEXCUBE Direct Banking accessible data.  CVSS Base Score 4.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0576</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9111V-6.0.1</ProductID>
            <ProductID>P-9111V-6.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-9111V-6.0.1</ProductID>
            <ProductID>P-9111V-6.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="60" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0577</Title>
      <Notes>
         <Note Type="Details" Ordinal="60" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Software (subcomponent: Core).  Supported versions that are affected are 10.0.0 - 10.5.0 and  11.0.0 - 11.4.0. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle FLEXCUBE Universal Banking.  CVSS Base Score 3.5 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0577</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9052V-10.0.0 - 10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-9052V-10.0.0 - 10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="61" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0579</Title>
      <Notes>
         <Note Type="Details" Ordinal="61" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Software (subcomponent: Core).  Supported versions that are affected are 10.0.0 - 10.5.0 and  11.0.0 - 11.4.0. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle FLEXCUBE Universal Banking accessible data.  CVSS Base Score 3.5 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0579</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9052V-10.0.0 - 10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-9052V-10.0.0 - 10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="62" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0580</Title>
      <Notes>
         <Note Type="Details" Ordinal="62" Title="Details" Audience="All">Vulnerability in the Oracle Agile PLM for Process component of Oracle Supply Chain Products Suite (subcomponent: Supplier Portal).   The supported version that is affected is 6.0.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Agile PLM for Process accessible data.  CVSS Base Score 5.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0580</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4447V-6.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-4447V-6.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="63" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0581</Title>
      <Notes>
         <Note Type="Details" Ordinal="63" Title="Details" Audience="All">Vulnerability in the Oracle Agile component of Oracle Supply Chain Products Suite (subcomponent: SCRM - Company Profiles).   The supported version that is affected is 6.0.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Agile accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0581</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4445V-6.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-4445V-6.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="64" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0582</Title>
      <Notes>
         <Note Type="Details" Ordinal="64" Title="Details" Audience="All">Vulnerability in the Siebel Clinical component of Oracle Industry Applications (subcomponent: Web UI).  Supported versions that are affected are 7.7, 7.8, 8.0.0.x, 8.1.1.x and  8.2.2.x. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Siebel Clinical accessible data.  CVSS Base Score 4.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0582</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9173V-7.7</ProductID>
            <ProductID>P-9173V-7.8</ProductID>
            <ProductID>P-9173V-8.0.0.x</ProductID>
            <ProductID>P-9173V-8.1.1.x</ProductID>
            <ProductID>P-9173V-8.2.2.x</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-9173V-7.7</ProductID>
            <ProductID>P-9173V-7.8</ProductID>
            <ProductID>P-9173V-8.0.0.x</ProductID>
            <ProductID>P-9173V-8.1.1.x</ProductID>
            <ProductID>P-9173V-8.2.2.x</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="65" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0583</Title>
      <Notes>
         <Note Type="Details" Ordinal="65" Title="Details" Audience="All">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: MyISAM).  Supported versions that are affected are 5.1.60 and earlier and  5.5.19 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0583</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.1.60 and earlier</ProductID>
            <ProductID>P-8478V-5.5.19 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-8478V-5.1.60 and earlier</ProductID>
            <ProductID>P-8478V-5.5.19 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="66" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1674</Title>
      <Notes>
         <Note Type="Details" Ordinal="66" Title="Details" Audience="All">Vulnerability in the Siebel Clinical component of Oracle Industry Applications (subcomponent: Web UI).  Supported versions that are affected are 7.7, 7.8, 8.0.0.x, 8.1.1.x and  8.2.2.x. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Siebel Clinical accessible data.  CVSS Base Score 4.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1674</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9173V-7.7</ProductID>
            <ProductID>P-9173V-7.8</ProductID>
            <ProductID>P-9173V-8.0.0.x</ProductID>
            <ProductID>P-9173V-8.1.1.x</ProductID>
            <ProductID>P-9173V-8.2.2.x</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-9173V-7.7</ProductID>
            <ProductID>P-9173V-7.8</ProductID>
            <ProductID>P-9173V-8.0.0.x</ProductID>
            <ProductID>P-9173V-8.1.1.x</ProductID>
            <ProductID>P-9173V-8.2.2.x</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="67" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1676</Title>
      <Notes>
         <Note Type="Details" Ordinal="67" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Software (subcomponent: Virtual Banking).  Supported versions that are affected are 5.0.2, 5.3.0 - 5.3.4, 6.0.1 and  6.2.0. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle FLEXCUBE Direct Banking accessible data.  CVSS Base Score 3.5 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1676</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9111V-5.0.2</ProductID>
            <ProductID>P-9111V-5.3.0 - 5.3.4</ProductID>
            <ProductID>P-9111V-6.0.1</ProductID>
            <ProductID>P-9111V-6.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-9111V-5.0.2</ProductID>
            <ProductID>P-9111V-5.3.0 - 5.3.4</ProductID>
            <ProductID>P-9111V-6.0.1</ProductID>
            <ProductID>P-9111V-6.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="68" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1679</Title>
      <Notes>
         <Note Type="Details" Ordinal="68" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Software (subcomponent: Core-Base).  Supported versions that are affected are 5.0.2, 5.3.0 - 5.3.4, 6.0.1 and  6.2.0. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle FLEXCUBE Direct Banking accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1679</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9111V-5.0.2</ProductID>
            <ProductID>P-9111V-5.3.0 - 5.3.4</ProductID>
            <ProductID>P-9111V-6.0.1</ProductID>
            <ProductID>P-9111V-6.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-9111V-5.0.2</ProductID>
            <ProductID>P-9111V-5.3.0 - 5.3.4</ProductID>
            <ProductID>P-9111V-6.0.1</ProductID>
            <ProductID>P-9111V-6.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="69" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1681</Title>
      <Notes>
         <Note Type="Details" Ordinal="69" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: Kernel/sockfs
).  Supported versions that are affected are 8, 9, 10 and  11. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 4.9 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1681</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-8</ProductID>
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.9</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-8752V-8</ProductID>
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="70" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1683</Title>
      <Notes>
         <Note Type="Details" Ordinal="70" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: gssd(1M)).  Supported versions that are affected are 8, 9, 10 and  11. Very difficult to exploit vulnerability requiring logon to Operating System plus additional, multiple logins to components.  Successful attack of this vulnerability can escalate attacker privileges resulting in unauthorized Operating System takeover including arbitrary code execution.  CVSS Base Score 5.9 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:H/Au:M/C:C/I:C/A:C).  Oracle Vector: (AV:L/AC:H/Au:M/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1683</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-8</ProductID>
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.9</BaseScore>
            <Vector>AV:L/AC:H/Au:M/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-8752V-8</ProductID>
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="71" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1684</Title>
      <Notes>
         <Note Type="Details" Ordinal="71" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: Password Policy).  Supported versions that are affected are 8, 9, 10 and  11. Easily exploitable vulnerability requiring logon to Operating System plus additional login/authentication to component or subcomponent.  Successful attack of this vulnerability can escalate attacker privileges resulting in unauthorized  update, insert or delete access to some Solaris accessible data as well as  read access to a subset of Solaris accessible data and ability to cause a partial denial of service (partial DOS) of Solaris.  CVSS Base Score 4.3 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:S/C:P/I:P/A:P).  Oracle Vector: (AV:L/AC:L/Au:S/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1684</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-8</ProductID>
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:L/AC:L/Au:S/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-8752V-8</ProductID>
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="72" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1688</Title>
      <Notes>
         <Note Type="Details" Ordinal="72" Title="Details" Audience="All">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server DML).  Supported versions that are affected are 5.1.61 and earlier and  5.5.21 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1688</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.1.61 and earlier</ProductID>
            <ProductID>P-8478V-5.5.21 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-8478V-5.1.61 and earlier</ProductID>
            <ProductID>P-8478V-5.5.21 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="73" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1690</Title>
      <Notes>
         <Note Type="Details" Ordinal="73" Title="Details" Audience="All">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server Optimizer).  Supported versions that are affected are 5.1.61 and earlier and  5.5.21 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1690</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.1.61 and earlier</ProductID>
            <ProductID>P-8478V-5.5.21 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-8478V-5.1.61 and earlier</ProductID>
            <ProductID>P-8478V-5.5.21 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="74" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1691</Title>
      <Notes>
         <Note Type="Details" Ordinal="74" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: Kernel/Privileges).   The supported version that is affected is 11. Difficult to exploit vulnerability requiring logon to Operating System plus additional login/authentication to component or subcomponent.  Successful attack of this vulnerability can escalate attacker privileges resulting in unauthorized Operating System takeover including arbitrary code execution.  CVSS Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:S/C:C/I:C/A:C).  Oracle Vector: (AV:L/AC:M/Au:S/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1691</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.6</BaseScore>
            <Vector>AV:L/AC:M/Au:S/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-8752V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="75" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1692</Title>
      <Notes>
         <Note Type="Details" Ordinal="75" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: SCTP(7P)).   The supported version that is affected is 10. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 4.9 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1692</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.9</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-8752V-10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="76" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1693</Title>
      <Notes>
         <Note Type="Details" Ordinal="76" Title="Details" Audience="All">Vulnerability in the SPARC Enterprise M Series Servers component of Oracle Sun Products Suite (subcomponent: XSCF Control Package (XCP)	).   The supported version that is affected is XCP 1110. Very difficult to exploit vulnerability allows successful unauthenticated network attacks via SSH.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of SPARC Enterprise M Series Servers.  CVSS Base Score 2.6 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:H/Au:N/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1693</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-XCP 1110</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.6</BaseScore>
            <Vector>AV:N/AC:H/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-8752V-XCP 1110</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="77" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1694</Title>
      <Notes>
         <Note Type="Details" Ordinal="77" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: libsasl(3LIB)).   The supported version that is affected is 10. Easily exploitable vulnerability allows successful unauthenticated network attacks via TCP/IP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Solaris accessible data as well as  read access to a subset of Solaris accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1694</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-8752V-10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="78" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1695</Title>
      <Notes>
         <Note Type="Details" Ordinal="78" Title="Details" Audience="All">Vulnerability in the Oracle JRockit component of Oracle Fusion Middleware.  Supported versions that are affected are 28.2.2 and before: JDK/JRE 5 and 6 and  27.7.1 and before: JKD/JRE 5 and 6. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Oracle released a Java SE Critical Patch Update on February 2012 to address multiple vulnerabilities affecting the Java Runtime Environment. Oracle CVE-2012-1695 refers to the advisories that were applicable to JRockit from the Java SE Critical Patch Update. The CVSS score of this vulnerability CVE# reflects the highest among those fixed in JRockit. The complete list of all vulnerabilities addressed in JRockit under CVE-2012-1695 is as follows: CVE-2012-0497, CVE-2012-0498, CVE-2012-0499, CVE-2011-3563, CVE-2012-0501, and CVE-2011-5035. CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1695</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5260V-28.2.2 and before: JDK/JRE 5 and 6</ProductID>
            <ProductID>P-5260V-27.7.1 and before: JKD/JRE 5 and 6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-5260V-28.2.2 and before: JDK/JRE 5 and 6</ProductID>
            <ProductID>P-5260V-27.7.1 and before: JKD/JRE 5 and 6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="79" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1696</Title>
      <Notes>
         <Note Type="Details" Ordinal="79" Title="Details" Audience="All">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server Optimizer).  Supported versions that are affected are 5.5.19 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1696</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.19 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-8478V-5.5.19 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="80" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1697</Title>
      <Notes>
         <Note Type="Details" Ordinal="80" Title="Details" Audience="All">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Partition).  Supported versions that are affected are 5.5.21 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1697</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.21 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-8478V-5.5.21 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="81" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1698</Title>
      <Notes>
         <Note Type="Details" Ordinal="81" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: Kernel/GLD(7D)).   The supported version that is affected is 11. Very difficult to exploit vulnerability allows successful authenticated network attacks via TCP/IP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Solaris accessible data.  CVSS Base Score 2.1 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:H/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1698</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:N/AC:H/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-8752V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="82" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1703</Title>
      <Notes>
         <Note Type="Details" Ordinal="82" Title="Details" Audience="All">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server Optimizer).  Supported versions that are affected are 5.1.61 and earlier and  5.5.21 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 6.8 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:C).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1703</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.1.61 and earlier</ProductID>
            <ProductID>P-8478V-5.5.21 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.8</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-8478V-5.1.61 and earlier</ProductID>
            <ProductID>P-8478V-5.5.21 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="83" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1704</Title>
      <Notes>
         <Note Type="Details" Ordinal="83" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Software (subcomponent: Core-Base).  Supported versions that are affected are 5.0.2, 5.3.0 - 5.3.4, 6.0.1 and  6.2.0. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle FLEXCUBE Direct Banking accessible data.  CVSS Base Score 3.5 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1704</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9111V-5.0.2</ProductID>
            <ProductID>P-9111V-5.3.0 - 5.3.4</ProductID>
            <ProductID>P-9111V-6.0.1</ProductID>
            <ProductID>P-9111V-6.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-9111V-5.0.2</ProductID>
            <ProductID>P-9111V-5.3.0 - 5.3.4</ProductID>
            <ProductID>P-9111V-6.0.1</ProductID>
            <ProductID>P-9111V-6.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="84" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1706</Title>
      <Notes>
         <Note Type="Details" Ordinal="84" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Software (subcomponent: Logging).  Supported versions that are affected are 5.0.2, 5.3.0 - 5.3.4, 6.0.1 and  6.2.0. Easily exploitable vulnerability allows successful network attacks via File, requiring multiple authentications.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle FLEXCUBE Direct Banking accessible data as well as  read access to a subset of Oracle FLEXCUBE Direct Banking accessible data.  CVSS Base Score 4.7 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:M/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:M/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1706</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9111V-5.0.2</ProductID>
            <ProductID>P-9111V-5.3.0 - 5.3.4</ProductID>
            <ProductID>P-9111V-6.0.1</ProductID>
            <ProductID>P-9111V-6.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.7</BaseScore>
            <Vector>AV:N/AC:L/Au:M/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-9111V-5.0.2</ProductID>
            <ProductID>P-9111V-5.3.0 - 5.3.4</ProductID>
            <ProductID>P-9111V-6.0.1</ProductID>
            <ProductID>P-9111V-6.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="85" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1707</Title>
      <Notes>
         <Note Type="Details" Ordinal="85" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Software (subcomponent: Core-Base).  Supported versions that are affected are 5.0.2, 5.3.0 - 5.3.4, 6.0.1 and  6.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle FLEXCUBE Direct Banking accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1707</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9111V-5.0.2</ProductID>
            <ProductID>P-9111V-5.3.0 - 5.3.4</ProductID>
            <ProductID>P-9111V-6.0.1</ProductID>
            <ProductID>P-9111V-6.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-9111V-5.0.2</ProductID>
            <ProductID>P-9111V-5.3.0 - 5.3.4</ProductID>
            <ProductID>P-9111V-6.0.1</ProductID>
            <ProductID>P-9111V-6.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="86" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1708</Title>
      <Notes>
         <Note Type="Details" Ordinal="86" Title="Details" Audience="All">Vulnerability in the Application Express component of Oracle Database Server.  Supported versions that are affected are 4.0 and  4.1. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Application Express accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1708</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1348V-4.0</ProductID>
            <ProductID>P-1348V-4.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-1348V-4.0</ProductID>
            <ProductID>P-1348V-4.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="87" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1709</Title>
      <Notes>
         <Note Type="Details" Ordinal="87" Title="Details" Audience="All">Vulnerability in the Oracle WebCenter Forms Recognition component of Oracle Fusion Middleware (subcomponent: Designer).   The supported version that is affected is 10.1.3.5. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle WebCenter Forms Recognition accessible data as well as  read access to a subset of Oracle WebCenter Forms Recognition accessible data and ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Forms Recognition.  CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1709</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5746V-10.1.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-5746V-10.1.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="88" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1710</Title>
      <Notes>
         <Note Type="Details" Ordinal="88" Title="Details" Audience="All">Vulnerability in the Oracle WebCenter Forms Recognition component of Oracle Fusion Middleware (subcomponent: Designer).   The supported version that is affected is 10.1.3.5. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle WebCenter Forms Recognition accessible data as well as  read access to a subset of Oracle WebCenter Forms Recognition accessible data and ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Forms Recognition.  CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1710</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5746V-10.1.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</URL>
            <ProductID>P-5746V-10.1.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
</cvrf:cvrfdoc>
