<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet type="text/xsl" href="http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/1687073.xsl"?>
<?xml-stylesheet type="text/css" href="http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/1686935.css"?>
<cvrf:cvrfdoc xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1">
   <DocumentTitle xml:lang="en">Oracle Critical Patch Update Advisory - October 2012 - BETA ORACLE CVRF</DocumentTitle>
   <DocumentType xml:lang="en">Oracle Critical Patch Update Advisory</DocumentType>
   <DocumentPublisher Type="Vendor"/>
   <DocumentTracking>
      <Identification>
         <ID>CPUOct2012</ID>
      </Identification>
      <Status>Final</Status>
      <Version>1.0</Version>
      <RevisionHistory>
         <Revision>
            <Number>1.0</Number>
            <Date>2012-10-16T13:00:00-07:00</Date>
            <Description>Initial Distribution</Description>
         </Revision>
      </RevisionHistory>
      <InitialReleaseDate>2012-10-16T13:00:00-07:00</InitialReleaseDate>
      <CurrentReleaseDate>2012-10-16T13:00:00-07:00</CurrentReleaseDate>
   </DocumentTracking>
   <DocumentNotes>
      <Note Type="Summary" Ordinal="1" Title="Summary" Audience="All" xml:lang="en">This document contains descriptions of Oracle product security vulnerabilities which have had fixes released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including fix distribution information can be found at the Oracle sites referenced in this document.</Note>
   </DocumentNotes>
   <DocumentDistribution>This document is published at: http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/1841212.xml</DocumentDistribution>
   <DocumentReferences>
      <Reference Type="External">
         <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
         <Description>URL to html version of Advisory</Description>
      </Reference>
   </DocumentReferences>
   <Acknowledgments>
      <Acknowledgment>
         <Name>Alexandr Polyakov</Name>
         <Organization>Digital Security</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Andy Yang</Name>
         <Organization>Stratsec Research</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Dana Lane Taylor</Name>
         <Organization>University of Pennsylvania, Office of Information Security</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Dominic Sim</Name>
         <Organization>KPMG Management Consulting, Singapore</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Esteban Martinez Fayo</Name>
         <Organization>Application Security, Inc.</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Florian Lukavsky</Name>
         <Organization>SEC Consult</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Francis Provencher</Name>
         <Organization>Secunia Research</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>John Zimmerman</Name>
         <Organization>Cisco</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Juan Manuel Pascual Escriba</Name>
         <Organization>Open Source &amp; Security Services Corp</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Martin Carpenter</Name>
         <Organization>Citco</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Martin Rakhmanov</Name>
         <Organization>Application Security, Inc.</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Microsoft Vulnerability Research</Name>
         <Organization>Microsoft Corp</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Paul Harrington</Name>
         <Organization>NGS Secure</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Pavel Toporkov</Name>
         <Organization>Positive Technologies</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ronnie Sahlberg</Name>
         <Organization>Ronnie Sahlberg</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Sam Thomas</Name>
         <Organization>Pentest Limited</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Sjoerd Resink</Name>
         <Organization>Fox-IT</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Thomas Biege</Name>
         <Organization>SUSE</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Travis Emmert</Name>
         <Organization>Travis Emmert</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Travis Emmert</Name>
         <Organization>Veracode</Organization>
      </Acknowledgment>
   </Acknowledgments>
   <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
      <Branch Type="Vendor" Name="Oracle">
         <Branch Type="Product Family" Name="Oracle Database Server">
            <Branch Type="Product Name" Name="Oracle Database">
               <Branch Type="Product Version" Name="10.2.0.3">
                  <FullProductName ProductID="P-5V-10.2.0.3">Oracle Database Version 10.2.0.3</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="10.2.0.4">
                  <FullProductName ProductID="P-5V-10.2.0.4">Oracle Database Version 10.2.0.4</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="10.2.0.5">
                  <FullProductName ProductID="P-5V-10.2.0.5">Oracle Database Version 10.2.0.5</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.1.0.7">
                  <FullProductName ProductID="P-5V-11.1.0.7">Oracle Database Version 11.1.0.7</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.2.0.2">
                  <FullProductName ProductID="P-5V-11.2.0.2">Oracle Database Version 11.2.0.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.2.0.3">
                  <FullProductName ProductID="P-5V-11.2.0.3">Oracle Database Version 11.2.0.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="PL/SQL">
               <Branch Type="Product Version" Name="10.2.0.3">
                  <FullProductName ProductID="P-11V-10.2.0.3">PL/SQL Version 10.2.0.3</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="10.2.0.4">
                  <FullProductName ProductID="P-11V-10.2.0.4">PL/SQL Version 10.2.0.4</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="10.2.0.5">
                  <FullProductName ProductID="P-11V-10.2.0.5">PL/SQL Version 10.2.0.5</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.1.0.7">
                  <FullProductName ProductID="P-11V-11.1.0.7">PL/SQL Version 11.1.0.7</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.2.0.2">
                  <FullProductName ProductID="P-11V-11.2.0.2">PL/SQL Version 11.2.0.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.2.0.3">
                  <FullProductName ProductID="P-11V-11.2.0.3">PL/SQL Version 11.2.0.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle Net Services">
               <Branch Type="Product Version" Name="10.2.0.4">
                  <FullProductName ProductID="P-115V-10.2.0.4">Oracle Net Services Version 10.2.0.4</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="10.2.0.5">
                  <FullProductName ProductID="P-115V-10.2.0.5">Oracle Net Services Version 10.2.0.5</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.1.0.7">
                  <FullProductName ProductID="P-115V-11.1.0.7">Oracle Net Services Version 11.1.0.7</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.2.0.2">
                  <FullProductName ProductID="P-115V-11.2.0.2">Oracle Net Services Version 11.2.0.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.2.0.3">
                  <FullProductName ProductID="P-115V-11.2.0.3">Oracle Net Services Version 11.2.0.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="JDBC">
               <Branch Type="Product Version" Name="10.2.0.3">
                  <FullProductName ProductID="P-972V-10.2.0.3">JDBC Version 10.2.0.3</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="10.2.0.4">
                  <FullProductName ProductID="P-972V-10.2.0.4">JDBC Version 10.2.0.4</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="10.2.0.5">
                  <FullProductName ProductID="P-972V-10.2.0.5">JDBC Version 10.2.0.5</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.1.0.7">
                  <FullProductName ProductID="P-972V-11.1.0.7">JDBC Version 11.1.0.7</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.2.0.2">
                  <FullProductName ProductID="P-972V-11.2.0.2">JDBC Version 11.2.0.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle E-Business Suite">
            <Branch Type="Product Name" Name="Oracle iStore">
               <Branch Type="Product Version" Name="11.5.10.2">
                  <FullProductName ProductID="P-384V-11.5.10.2">Oracle iStore Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.0.6">
                  <FullProductName ProductID="P-384V-12.0.6">Oracle iStore Version 12.0.6</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.1.1">
                  <FullProductName ProductID="P-384V-12.1.1">Oracle iStore Version 12.1.1</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.1.2">
                  <FullProductName ProductID="P-384V-12.1.2">Oracle iStore Version 12.1.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.1.3">
                  <FullProductName ProductID="P-384V-12.1.3">Oracle iStore Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle Human Resources">
               <Branch Type="Product Version" Name="11.5.10.2">
                  <FullProductName ProductID="P-507V-11.5.10.2">Oracle Human Resources Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.0.6">
                  <FullProductName ProductID="P-507V-12.0.6">Oracle Human Resources Version 12.0.6</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.1.1">
                  <FullProductName ProductID="P-507V-12.1.1">Oracle Human Resources Version 12.1.1</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.1.2">
                  <FullProductName ProductID="P-507V-12.1.2">Oracle Human Resources Version 12.1.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.1.3">
                  <FullProductName ProductID="P-507V-12.1.3">Oracle Human Resources Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle Application Object Library">
               <Branch Type="Product Version" Name="11.5.10.2">
                  <FullProductName ProductID="P-510V-11.5.10.2">Oracle Application Object Library Version 11.5.10.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle Field Service">
               <Branch Type="Product Version" Name="12.1.3">
                  <FullProductName ProductID="P-747V-12.1.3">Oracle Field Service Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle Marketing Encyclopedia System">
               <Branch Type="Product Version" Name="11.5.10.2">
                  <FullProductName ProductID="P-759V-11.5.10.2">Oracle Marketing Encyclopedia System Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.0.6">
                  <FullProductName ProductID="P-759V-12.0.6">Oracle Marketing Encyclopedia System Version 12.0.6</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.1.1">
                  <FullProductName ProductID="P-759V-12.1.1">Oracle Marketing Encyclopedia System Version 12.1.1</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.1.2">
                  <FullProductName ProductID="P-759V-12.1.2">Oracle Marketing Encyclopedia System Version 12.1.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.1.3">
                  <FullProductName ProductID="P-759V-12.1.3">Oracle Marketing Encyclopedia System Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle iRecruitment">
               <Branch Type="Product Version" Name="11.5.10.2">
                  <FullProductName ProductID="P-1193V-11.5.10.2">Oracle iRecruitment Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.0.6">
                  <FullProductName ProductID="P-1193V-12.0.6">Oracle iRecruitment Version 12.0.6</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.1.1">
                  <FullProductName ProductID="P-1193V-12.1.1">Oracle iRecruitment Version 12.1.1</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.1.2">
                  <FullProductName ProductID="P-1193V-12.1.2">Oracle iRecruitment Version 12.1.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.1.3">
                  <FullProductName ProductID="P-1193V-12.1.3">Oracle iRecruitment Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle Applications Framework">
               <Branch Type="Product Version" Name="11.5.10.2">
                  <FullProductName ProductID="P-1472V-11.5.10.2">Oracle Applications Framework Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.0.6">
                  <FullProductName ProductID="P-1472V-12.0.6">Oracle Applications Framework Version 12.0.6</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.1.3">
                  <FullProductName ProductID="P-1472V-12.1.3">Oracle Applications Framework Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle Applications Technology Stack">
               <Branch Type="Product Version" Name="11.5.10.2">
                  <FullProductName ProductID="P-1745V-11.5.10.2">Oracle Applications Technology Stack Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.0.6">
                  <FullProductName ProductID="P-1745V-12.0.6">Oracle Applications Technology Stack Version 12.0.6</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.1.3">
                  <FullProductName ProductID="P-1745V-12.1.3">Oracle Applications Technology Stack Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle Financial Services Software">
            <Branch Type="Product Name" Name="Oracle FLEXCUBE Universal Banking">
               <Branch Type="Product Version" Name="10.0.0">
                  <FullProductName ProductID="P-9052V-10.0.0">Oracle FLEXCUBE Universal Banking Version 10.0.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="10.0.2">
                  <FullProductName ProductID="P-9052V-10.0.2">Oracle FLEXCUBE Universal Banking Version 10.0.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="10.1.0">
                  <FullProductName ProductID="P-9052V-10.1.0">Oracle FLEXCUBE Universal Banking Version 10.1.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="10.2.0">
                  <FullProductName ProductID="P-9052V-10.2.0">Oracle FLEXCUBE Universal Banking Version 10.2.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="10.2.2">
                  <FullProductName ProductID="P-9052V-10.2.2">Oracle FLEXCUBE Universal Banking Version 10.2.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="10.3.0">
                  <FullProductName ProductID="P-9052V-10.3.0">Oracle FLEXCUBE Universal Banking Version 10.3.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="10.5.0">
                  <FullProductName ProductID="P-9052V-10.5.0">Oracle FLEXCUBE Universal Banking Version 10.5.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.0.0 - 11.2.0">
                  <FullProductName ProductID="P-9052V-11.0.0 - 11.2.0">Oracle FLEXCUBE Universal Banking Version 11.0.0 - 11.2.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.0.0 - 11.4.0">
                  <FullProductName ProductID="P-9052V-11.0.0 - 11.4.0">Oracle FLEXCUBE Universal Banking Version 11.0.0 - 11.4.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.0.0">
                  <FullProductName ProductID="P-9052V-12.0.0">Oracle FLEXCUBE Universal Banking Version 12.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle FLEXCUBE Direct Banking">
               <Branch Type="Product Version" Name="12">
                  <FullProductName ProductID="P-9111V-12">Oracle FLEXCUBE Direct Banking Version 12</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="5.0.2">
                  <FullProductName ProductID="P-9111V-5.0.2">Oracle FLEXCUBE Direct Banking Version 5.0.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="5.0.5">
                  <FullProductName ProductID="P-9111V-5.0.5">Oracle FLEXCUBE Direct Banking Version 5.0.5</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="5.1.0">
                  <FullProductName ProductID="P-9111V-5.1.0">Oracle FLEXCUBE Direct Banking Version 5.1.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="5.2.0">
                  <FullProductName ProductID="P-9111V-5.2.0">Oracle FLEXCUBE Direct Banking Version 5.2.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="5.3.0 - 5.3.4">
                  <FullProductName ProductID="P-9111V-5.3.0 - 5.3.4">Oracle FLEXCUBE Direct Banking Version 5.3.0 - 5.3.4</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="6.0.1">
                  <FullProductName ProductID="P-9111V-6.0.1">Oracle FLEXCUBE Direct Banking Version 6.0.1</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="6.2.0">
                  <FullProductName ProductID="P-9111V-6.2.0">Oracle FLEXCUBE Direct Banking Version 6.2.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle Fusion Middleware">
            <Branch Type="Product Name" Name="Oracle Reports Developer">
               <Branch Type="Product Version" Name="11.1.1.4">
                  <FullProductName ProductID="P-159V-11.1.1.4">Oracle Reports Developer Version 11.1.1.4</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.1.1.6">
                  <FullProductName ProductID="P-159V-11.1.1.6">Oracle Reports Developer Version 11.1.1.6</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.1.2.0">
                  <FullProductName ProductID="P-159V-11.1.2.0">Oracle Reports Developer Version 11.1.2.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle Application Server Single Sign-On">
               <Branch Type="Product Version" Name="10.1.4.3.0">
                  <FullProductName ProductID="P-1318V-10.1.4.3.0">Oracle Application Server Single Sign-On Version 10.1.4.3.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="BI Publisher (formerly XML Publisher)">
               <Branch Type="Product Version" Name="10.1.3.4.2">
                  <FullProductName ProductID="P-1479V-10.1.3.4.2">BI Publisher (formerly XML Publisher) Version 10.1.3.4.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="10.3.4.2">
                  <FullProductName ProductID="P-1479V-10.3.4.2">BI Publisher (formerly XML Publisher) Version 10.3.4.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.1.1.5.0">
                  <FullProductName ProductID="P-1479V-11.1.1.5.0">BI Publisher (formerly XML Publisher) Version 11.1.1.5.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.1.1.6.0">
                  <FullProductName ProductID="P-1479V-11.1.1.6.0">BI Publisher (formerly XML Publisher) Version 11.1.1.6.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.1.1.6.2">
                  <FullProductName ProductID="P-1479V-11.1.1.6.2">BI Publisher (formerly XML Publisher) Version 11.1.1.6.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle Business Intelligence Enterprise Edition">
               <Branch Type="Product Version" Name="-">
                  <FullProductName ProductID="P-2025V--">Oracle Business Intelligence Enterprise Edition Version -</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle Imaging and Process Management">
               <Branch Type="Product Version" Name="10.1.3.6.0">
                  <FullProductName ProductID="P-2273V-10.1.3.6.0">Oracle Imaging and Process Management Version 10.1.3.6.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle Outside In Technology">
               <Branch Type="Product Version" Name="8.3.7.0">
                  <FullProductName ProductID="P-2276V-8.3.7.0">Oracle Outside In Technology Version 8.3.7.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle Weblogic Server">
               <Branch Type="Product Version" Name="10.0.2.0">
                  <FullProductName ProductID="P-5242V-10.0.2.0">Oracle Weblogic Server Version 10.0.2.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="10.3.5.0">
                  <FullProductName ProductID="P-5242V-10.3.5.0">Oracle Weblogic Server Version 10.3.5.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="10.3.6.0">
                  <FullProductName ProductID="P-5242V-10.3.6.0">Oracle Weblogic Server Version 10.3.6.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.1.1.0">
                  <FullProductName ProductID="P-5242V-12.1.1.0">Oracle Weblogic Server Version 12.1.1.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="9.2.4.0">
                  <FullProductName ProductID="P-5242V-9.2.4.0">Oracle Weblogic Server Version 9.2.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle JRockit">
               <Branch Type="Product Version" Name="27.7.3 and before: JKD/JRE 5">
                  <FullProductName ProductID="P-5260V-27.7.3 and before: JKD/JRE 5">Oracle JRockit Version 27.7.3 and before: JKD/JRE 5</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="28.2.4 and before: JDK/JRE 5 and 6">
                  <FullProductName ProductID="P-5260V-28.2.4 and before: JDK/JRE 5 and 6">Oracle JRockit Version 28.2.4 and before: JDK/JRE 5 and 6</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle Event Processing">
               <Branch Type="Product Version" Name="11.1.1.4.0">
                  <FullProductName ProductID="P-5370V-11.1.1.4.0">Oracle Event Processing Version 11.1.1.4.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.1.1.6.0">
                  <FullProductName ProductID="P-5370V-11.1.1.6.0">Oracle Event Processing Version 11.1.1.6.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="2.0">
                  <FullProductName ProductID="P-5370V-2.0">Oracle Event Processing Version 2.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle WebCenter Sites">
               <Branch Type="Product Version" Name="11.1.1.6.0">
                  <FullProductName ProductID="P-9617V-11.1.1.6.0">Oracle WebCenter Sites Version 11.1.1.6.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="6.1">
                  <FullProductName ProductID="P-9617V-6.1">Oracle WebCenter Sites Version 6.1</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="6.2">
                  <FullProductName ProductID="P-9617V-6.2">Oracle WebCenter Sites Version 6.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="6.3.x">
                  <FullProductName ProductID="P-9617V-6.3.x">Oracle WebCenter Sites Version 6.3.x</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="7">
                  <FullProductName ProductID="P-9617V-7">Oracle WebCenter Sites Version 7</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="7.0.1">
                  <FullProductName ProductID="P-9617V-7.0.1">Oracle WebCenter Sites Version 7.0.1</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="7.0.2">
                  <FullProductName ProductID="P-9617V-7.0.2">Oracle WebCenter Sites Version 7.0.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="7.0.3">
                  <FullProductName ProductID="P-9617V-7.0.3">Oracle WebCenter Sites Version 7.0.3</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="7.5">
                  <FullProductName ProductID="P-9617V-7.5">Oracle WebCenter Sites Version 7.5</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="7.6.1">
                  <FullProductName ProductID="P-9617V-7.6.1">Oracle WebCenter Sites Version 7.6.1</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="7.6.2">
                  <FullProductName ProductID="P-9617V-7.6.2">Oracle WebCenter Sites Version 7.6.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle Industry Applications">
            <Branch Type="Product Name" Name="Oracle Clinical RDC Option">
               <Branch Type="Product Version" Name="4.6.0">
                  <FullProductName ProductID="P-1041V-4.6.0">Oracle Clinical RDC Option Version 4.6.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="4.6.2">
                  <FullProductName ProductID="P-1041V-4.6.2">Oracle Clinical RDC Option Version 4.6.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Health Sciences Product">
               <Branch Type="Product Version" Name="1.3">
                  <FullProductName ProductID="P-9132V-1.3">Health Sciences Product Version 1.3</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="1.4">
                  <FullProductName ProductID="P-9132V-1.4">Health Sciences Product Version 1.4</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="1.4.2">
                  <FullProductName ProductID="P-9132V-1.4.2">Health Sciences Product Version 1.4.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle MySQL">
            <Branch Type="Product Name" Name="MySQL Server">
               <Branch Type="Product Version" Name="5.1.63 and earlier">
                  <FullProductName ProductID="P-8478V-5.1.63 and earlier">MySQL Server Version 5.1.63 and earlier</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="5.1.64 and earlier">
                  <FullProductName ProductID="P-8478V-5.1.64 and earlier">MySQL Server Version 5.1.64 and earlier</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="5.1.65 and earlier">
                  <FullProductName ProductID="P-8478V-5.1.65 and earlier">MySQL Server Version 5.1.65 and earlier</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="5.5.25 and earlier">
                  <FullProductName ProductID="P-8478V-5.5.25 and earlier">MySQL Server Version 5.5.25 and earlier</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="5.5.26 and earlier">
                  <FullProductName ProductID="P-8478V-5.5.26 and earlier">MySQL Server Version 5.5.26 and earlier</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="5.5.27 and earlier">
                  <FullProductName ProductID="P-8478V-5.5.27 and earlier">MySQL Server Version 5.5.27 and earlier</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle PeopleSoft Products">
            <Branch Type="Product Name" Name="PeopleSoft Enterprise PT PeopleTools">
               <Branch Type="Product Version" Name="8.50">
                  <FullProductName ProductID="P-5085V-8.50">PeopleSoft Enterprise PT PeopleTools Version 8.50</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="8.51">
                  <FullProductName ProductID="P-5085V-8.51">PeopleSoft Enterprise PT PeopleTools Version 8.51</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="8.52">
                  <FullProductName ProductID="P-5085V-8.52">PeopleSoft Enterprise PT PeopleTools Version 8.52</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="PeopleSoft Enterprise CS Student Records">
               <Branch Type="Product Version" Name="9.0">
                  <FullProductName ProductID="P-5182V-9.0">PeopleSoft Enterprise CS Student Records Version 9.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle Siebel CRM">
            <Branch Type="Product Name" Name="Siebel Documentation">
               <Branch Type="Product Version" Name="8.1.1">
                  <FullProductName ProductID="P-8962V-8.1.1">Siebel Documentation Version 8.1.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Siebel UI Framework">
               <Branch Type="Product Version" Name="8.1.1">
                  <FullProductName ProductID="P-9011V-8.1.1">Siebel UI Framework Version 8.1.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle Sun Products Suite">
            <Branch Type="Product Name" Name="Oracle GlassFish Server">
               <Branch Type="Product Version" Name="Oracle GlassFish Server 3.0.1">
                  <FullProductName ProductID="P-8493V-Oracle GlassFish Server 3.0.1">Oracle GlassFish Server Version Oracle GlassFish Server 3.0.1</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="Oracle GlassFish Server 3.1.2">
                  <FullProductName ProductID="P-8493V-Oracle GlassFish Server 3.1.2">Oracle GlassFish Server Version Oracle GlassFish Server 3.1.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="Sun GlassFish Enterprise Server 2.1.1">
                  <FullProductName ProductID="P-8493V-Sun GlassFish Enterprise Server 2.1.1">Oracle GlassFish Server Version Sun GlassFish Enterprise Server 2.1.1</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="Sun Java System Application Server 8.1">
                  <FullProductName ProductID="P-8493V-Sun Java System Application Server 8.1">Oracle GlassFish Server Version Sun Java System Application Server 8.1</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="Sun Java System Application Server 8.2">
                  <FullProductName ProductID="P-8493V-Sun Java System Application Server 8.2">Oracle GlassFish Server Version Sun Java System Application Server 8.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Solaris Products">
               <Branch Type="Product Version" Name="10">
                  <FullProductName ProductID="P-8752V-10">Solaris Products Version 10</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11">
                  <FullProductName ProductID="P-8752V-11">Solaris Products Version 11</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="8">
                  <FullProductName ProductID="P-8752V-8">Solaris Products Version 8</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="9">
                  <FullProductName ProductID="P-8752V-9">Solaris Products Version 9</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="SysFW 8.2.0.a for SPARC T3">
                  <FullProductName ProductID="P-8752V-SysFW 8.2.0.a for SPARC T3">Solaris Products Version SysFW 8.2.0.a for SPARC T3</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="T4 based servers; see 1475188.1 for other servers">
                  <FullProductName ProductID="P-8752V-T4 based servers; see 1475188.1 for other servers">Solaris Products Version T4 based servers; see 1475188.1 for other servers</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle Supply Chain Products Suite">
            <Branch Type="Product Name" Name="Oracle Agile Product Data Management for Process">
               <Branch Type="Product Version" Name="5.2.2">
                  <FullProductName ProductID="P-4445V-5.2.2">Oracle Agile Product Data Management for Process Version 5.2.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="6.0.0.6.3">
                  <FullProductName ProductID="P-4445V-6.0.0.6.3">Oracle Agile Product Data Management for Process Version 6.0.0.6.3</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="6.1.0.0">
                  <FullProductName ProductID="P-4445V-6.1.0.0">Oracle Agile Product Data Management for Process Version 6.1.0.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="6.1.0.1.14">
                  <FullProductName ProductID="P-4445V-6.1.0.1.14">Oracle Agile Product Data Management for Process Version 6.1.0.1.14</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle Agile Product Supplier Collaboration for Process">
               <Branch Type="Product Version" Name="5.2.2">
                  <FullProductName ProductID="P-4447V-5.2.2">Oracle Agile Product Supplier Collaboration for Process Version 5.2.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="6.1.0.0">
                  <FullProductName ProductID="P-4447V-6.1.0.0">Oracle Agile Product Supplier Collaboration for Process Version 6.1.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle Agile PLM Framework">
               <Branch Type="Product Version" Name="9.3.1.0">
                  <FullProductName ProductID="P-4461V-9.3.1.0">Oracle Agile PLM Framework Version 9.3.1.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="9.3.1.1">
                  <FullProductName ProductID="P-4461V-9.3.1.1">Oracle Agile PLM Framework Version 9.3.1.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle Virtualization">
            <Branch Type="Product Name" Name="Oracle VM VirtualBox">
               <Branch Type="Product Version" Name="3.2">
                  <FullProductName ProductID="P-8370V-3.2">Oracle VM VirtualBox Version 3.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="4.0">
                  <FullProductName ProductID="P-8370V-4.0">Oracle VM VirtualBox Version 4.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="4.1">
                  <FullProductName ProductID="P-8370V-4.1">Oracle VM VirtualBox Version 4.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle Secure Global Desktop">
               <Branch Type="Product Version" Name="4.6">
                  <FullProductName ProductID="P-8539V-4.6">Oracle Secure Global Desktop Version 4.6</FullProductName>
               </Branch>
            </Branch>
         </Branch>
      </Branch>
   </ProductTree>
   <Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2011-1411</Title>
      <Notes>
         <Note Type="Details" Ordinal="1" Title="Details" Audience="All">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WebLogic Security).  Supported versions that are affected are 9.2.4.0, 10.0.2.0, 10.3.5.0, 10.3.6.0 and  12.1.1.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle WebLogic Server accessible data as well as  read access to a subset of Oracle WebLogic Server accessible data.  CVSS Base Score 5.8 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2011-1411</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-9.2.4.0</ProductID>
            <ProductID>P-5242V-10.0.2.0</ProductID>
            <ProductID>P-5242V-10.3.5.0</ProductID>
            <ProductID>P-5242V-10.3.6.0</ProductID>
            <ProductID>P-5242V-12.1.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-5242V-9.2.4.0</ProductID>
            <ProductID>P-5242V-10.0.2.0</ProductID>
            <ProductID>P-5242V-10.3.5.0</ProductID>
            <ProductID>P-5242V-10.3.6.0</ProductID>
            <ProductID>P-5242V-12.1.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2011-1411</Title>
      <Notes>
         <Note Type="Details" Ordinal="2" Title="Details" Audience="All">Vulnerability in the Oracle Event Processing component of Oracle Fusion Middleware (subcomponent: Complex Event Processing System).  Supported versions that are affected are 2.0, 11.1.1.4.0 and  11.1.1.6.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Event Processing accessible data as well as  read access to a subset of Oracle Event Processing accessible data.  CVSS Base Score 5.8 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2011-1411</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5370V-2.0</ProductID>
            <ProductID>P-5370V-11.1.1.4.0</ProductID>
            <ProductID>P-5370V-11.1.1.6.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-5370V-2.0</ProductID>
            <ProductID>P-5370V-11.1.1.4.0</ProductID>
            <ProductID>P-5370V-11.1.1.6.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="3" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0071</Title>
      <Notes>
         <Note Type="Details" Ordinal="3" Title="Details" Audience="All">Vulnerability in the Oracle Imaging and Process Management component of Oracle Fusion Middleware (subcomponent: Web).   The supported version that is affected is 10.1.3.6.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Imaging and Process Management accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0071</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2273V-10.1.3.6.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-2273V-10.1.3.6.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="4" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0086</Title>
      <Notes>
         <Note Type="Details" Ordinal="4" Title="Details" Audience="All">Vulnerability in the Oracle Imaging and Process Management component of Oracle Fusion Middleware (subcomponent: Web).   The supported version that is affected is 10.1.3.6.0. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Imaging and Process Management accessible data.  CVSS Base Score 3.5 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0086</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2273V-10.1.3.6.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-2273V-10.1.3.6.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="5" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0090</Title>
      <Notes>
         <Note Type="Details" Ordinal="5" Title="Details" Audience="All">Vulnerability in the Oracle Imaging and Process Management component of Oracle Fusion Middleware (subcomponent: Web).   The supported version that is affected is 10.1.3.6.0. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Imaging and Process Management accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0090</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2273V-10.1.3.6.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-2273V-10.1.3.6.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="6" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0092</Title>
      <Notes>
         <Note Type="Details" Ordinal="6" Title="Details" Audience="All">Vulnerability in the Oracle Imaging and Process Management component of Oracle Fusion Middleware (subcomponent: Web).   The supported version that is affected is 10.1.3.6.0. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Imaging and Process Management accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0092</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2273V-10.1.3.6.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-2273V-10.1.3.6.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="7" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0093</Title>
      <Notes>
         <Note Type="Details" Ordinal="7" Title="Details" Audience="All">Vulnerability in the Oracle Imaging and Process Management component of Oracle Fusion Middleware (subcomponent: Web).   The supported version that is affected is 10.1.3.6.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Imaging and Process Management accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0093</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2273V-10.1.3.6.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-2273V-10.1.3.6.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="8" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0095</Title>
      <Notes>
         <Note Type="Details" Ordinal="8" Title="Details" Audience="All">Vulnerability in the Oracle Imaging and Process Management component of Oracle Fusion Middleware (subcomponent: Web).   The supported version that is affected is 10.1.3.6.0. Very difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Imaging and Process Management accessible data.  CVSS Base Score 2.1 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:H/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0095</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2273V-10.1.3.6.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:N/AC:H/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-2273V-10.1.3.6.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="9" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0106</Title>
      <Notes>
         <Note Type="Details" Ordinal="9" Title="Details" Audience="All">Vulnerability in the Oracle Imaging and Process Management component of Oracle Fusion Middleware (subcomponent: Web).   The supported version that is affected is 10.1.3.6.0. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Imaging and Process Management accessible data as well as  read access to all Oracle Imaging and Process Management accessible data.  CVSS Base Score 4.9 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0106</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2273V-10.1.3.6.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.9</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-2273V-10.1.3.6.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="10" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0107</Title>
      <Notes>
         <Note Type="Details" Ordinal="10" Title="Details" Audience="All">Vulnerability in the Oracle Imaging and Process Management component of Oracle Fusion Middleware (subcomponent: Web).   The supported version that is affected is 10.1.3.6.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Imaging and Process Management.  CVSS Base Score 4.3 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0107</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2273V-10.1.3.6.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-2273V-10.1.3.6.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="11" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0108</Title>
      <Notes>
         <Note Type="Details" Ordinal="11" Title="Details" Audience="All">Vulnerability in the Oracle Imaging and Process Management component of Oracle Fusion Middleware (subcomponent: Web).   The supported version that is affected is 10.1.3.6.0. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Imaging and Process Management accessible data.  CVSS Base Score 3.5 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0108</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2273V-10.1.3.6.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-2273V-10.1.3.6.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="12" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0217</Title>
      <Notes>
         <Note Type="Details" Ordinal="12" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: Kernel).  Supported versions that are affected are 10 and 11. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: CVE-2012-0217 only affects Solaris instances running on platforms other than SPARC. CVSS Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:L/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0217</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.2</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="13" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0518</Title>
      <Notes>
         <Note Type="Details" Ordinal="13" Title="Details" Audience="All">Vulnerability in the Oracle Application Server Single Sign-On component of Oracle Fusion Middleware (subcomponent: Cookies/Tokens, Redirects).   The supported version that is affected is 10.1.4.3.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Application Server Single Sign-On accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0518</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1318V-10.1.4.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-1318V-10.1.4.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="14" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1685</Title>
      <Notes>
         <Note Type="Details" Ordinal="14" Title="Details" Audience="All">Vulnerability in the Secure Global Desktop component of Oracle Virtualization (subcomponent: Core).   The supported version that is affected is 4.6. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Secure Global Desktop accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1685</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8539V-4.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8539V-4.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="15" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1686</Title>
      <Notes>
         <Note Type="Details" Ordinal="15" Title="Details" Audience="All">Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Installation). For supported versions that are affected see note. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Business Intelligence Enterprise Edition accessible data.   Note: Fixed in all supported releases and patchsets. CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1686</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2025V--</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-2025V--</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="16" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1751</Title>
      <Notes>
         <Note Type="Details" Ordinal="16" Title="Details" Audience="All">Vulnerability in the Core RDBMS component of Oracle Database Server.  This vulnerability requires Create session, create flashback archive privileges for a successful attack.  Supported versions that are affected are 11.1.0.7, 11.2.0.2 and  11.2.0.3. Easily exploitable vulnerability allows successful authenticated network attacks via Oracle NET.  Successful attack of this vulnerability can result in unauthorized takeover of Core RDBMS possibly including arbitrary code execution within the Core RDBMS.  CVSS Base Score 6.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1751</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-11.1.0.7</ProductID>
            <ProductID>P-5V-11.2.0.2</ProductID>
            <ProductID>P-5V-11.2.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-5V-11.1.0.7</ProductID>
            <ProductID>P-5V-11.2.0.2</ProductID>
            <ProductID>P-5V-11.2.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="17" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1763</Title>
      <Notes>
         <Note Type="Details" Ordinal="17" Title="Details" Audience="All">Vulnerability in the Oracle Clinical/Remote Data Capture component of Oracle Industry Applications (subcomponent: HTML 
Surround).  Supported versions that are affected are 4.6.0 and  4.6.2. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to all Oracle Clinical/Remote Data Capture accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P+/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1763</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1041V-4.6.0</ProductID>
            <ProductID>P-1041V-4.6.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-1041V-4.6.0</ProductID>
            <ProductID>P-1041V-4.6.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="18" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3132</Title>
      <Notes>
         <Note Type="Details" Ordinal="18" Title="Details" Audience="All">Vulnerability in the Core RDBMS component of Oracle Database Server.  This vulnerability requires Create session, create table privileges for a successful attack.  Supported versions that are affected are 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2 and  11.2.0.3. Easily exploitable vulnerability allows successful authenticated network attacks via Oracle NET.  Successful attack of this vulnerability can result in unauthorized takeover of Core RDBMS possibly including arbitrary code execution within the Core RDBMS.  CVSS Base Score 6.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3132</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-10.2.0.3</ProductID>
            <ProductID>P-5V-10.2.0.4</ProductID>
            <ProductID>P-5V-10.2.0.5</ProductID>
            <ProductID>P-5V-11.1.0.7</ProductID>
            <ProductID>P-5V-11.2.0.2</ProductID>
            <ProductID>P-5V-11.2.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-5V-10.2.0.3</ProductID>
            <ProductID>P-5V-10.2.0.4</ProductID>
            <ProductID>P-5V-10.2.0.5</ProductID>
            <ProductID>P-5V-11.1.0.7</ProductID>
            <ProductID>P-5V-11.2.0.2</ProductID>
            <ProductID>P-5V-11.2.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="19" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3137</Title>
      <Notes>
         <Note Type="Details" Ordinal="19" Title="Details" Audience="All">Vulnerability in the Core RDBMS component of Oracle Database Server.  Supported versions that are affected are 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2 and  11.2.0.3. Easily exploitable vulnerability allows successful unauthenticated network attacks via Oracle NET.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: The CVSS Base Score is 10.0 only for Windows. For Linux, Unix and other platforms, the CVSS Base Score is 7.5, and the impacts for Confidentiality, Integrity and Availability are Partial+.

&lt;p&gt;
&lt;/br&gt;
For information, refer to Patching for CVE-2012-3137, &lt;A HREF="http://support.oracle.com/CSP/main/article?cmd=show&amp;type=NOT&amp;id=1493990.1"&gt;My Oracle Support Note 1493990.1&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
In some configurations, client-side updates for Database, Enterprise Manager Grid Control, WebLogic Server and Fusion Middleware are recommended. For information on what patches need to be applied to your environments, refer to Critical Patch Update October 2012 Patch Availability Document for Oracle Products, &lt;A HREF="http://support.oracle.com/CSP/main/article?cmd=show&amp;type=NOT&amp;id=1477727.1"&gt;My Oracle Support Note 1477727.1&lt;/a&gt;
&lt;/p&gt;. CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3137</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-10.2.0.3</ProductID>
            <ProductID>P-5V-10.2.0.4</ProductID>
            <ProductID>P-5V-10.2.0.5</ProductID>
            <ProductID>P-5V-11.1.0.7</ProductID>
            <ProductID>P-5V-11.2.0.2</ProductID>
            <ProductID>P-5V-11.2.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-5V-10.2.0.3</ProductID>
            <ProductID>P-5V-10.2.0.4</ProductID>
            <ProductID>P-5V-10.2.0.5</ProductID>
            <ProductID>P-5V-11.1.0.7</ProductID>
            <ProductID>P-5V-11.2.0.2</ProductID>
            <ProductID>P-5V-11.2.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="20" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3137</Title>
      <Notes>
         <Note Type="Details" Ordinal="20" Title="Details" Audience="All">Vulnerability in the Core RDBMS component of Oracle Database Server.  Supported versions that are affected are 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7 and  11.2.0.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via Oracle Net.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.  CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3137</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-10.2.0.3</ProductID>
            <ProductID>P-5V-10.2.0.4</ProductID>
            <ProductID>P-5V-10.2.0.5</ProductID>
            <ProductID>P-5V-11.1.0.7</ProductID>
            <ProductID>P-5V-11.2.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-5V-10.2.0.3</ProductID>
            <ProductID>P-5V-10.2.0.4</ProductID>
            <ProductID>P-5V-10.2.0.5</ProductID>
            <ProductID>P-5V-11.1.0.7</ProductID>
            <ProductID>P-5V-11.2.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="21" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3137</Title>
      <Notes>
         <Note Type="Details" Ordinal="21" Title="Details" Audience="All">Vulnerability in the Core RDBMS component of Oracle Database Server.  Supported versions that are affected are 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7 and  11.2.0.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via Oracle NET.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.  CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3137</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-972V-10.2.0.3</ProductID>
            <ProductID>P-972V-10.2.0.4</ProductID>
            <ProductID>P-972V-10.2.0.5</ProductID>
            <ProductID>P-972V-11.1.0.7</ProductID>
            <ProductID>P-972V-11.2.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-972V-10.2.0.3</ProductID>
            <ProductID>P-972V-10.2.0.4</ProductID>
            <ProductID>P-972V-10.2.0.5</ProductID>
            <ProductID>P-972V-11.1.0.7</ProductID>
            <ProductID>P-972V-11.2.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="22" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3138</Title>
      <Notes>
         <Note Type="Details" Ordinal="22" Title="Details" Audience="All">Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: Web interface).  Supported versions that are affected are 11.5.10.2, 12.0.6, 12.1.1, 12.1.2 and  12.1.3. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle iStore accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3138</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-384V-11.5.10.2</ProductID>
            <ProductID>P-384V-12.0.6</ProductID>
            <ProductID>P-384V-12.1.1</ProductID>
            <ProductID>P-384V-12.1.2</ProductID>
            <ProductID>P-384V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-384V-11.5.10.2</ProductID>
            <ProductID>P-384V-12.0.6</ProductID>
            <ProductID>P-384V-12.1.1</ProductID>
            <ProductID>P-384V-12.1.2</ProductID>
            <ProductID>P-384V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="23" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3139</Title>
      <Notes>
         <Note Type="Details" Ordinal="23" Title="Details" Audience="All">Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Signon (local and SSO)).   The supported version that is affected is 11.5.10.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Application Object Library accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3139</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-510V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-510V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="24" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3140</Title>
      <Notes>
         <Note Type="Details" Ordinal="24" Title="Details" Audience="All">Vulnerability in the Oracle Agile PLM For Process component of Oracle Supply Chain Products Suite (subcomponent: Supply Chain Relationship Mgmt).  Supported versions that are affected are 6.0.0.6.3 and  6.1.0.1.14. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Agile PLM For Process accessible data as well as  read access to a subset of Oracle Agile PLM For Process accessible data.  CVSS Base Score 5.5 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3140</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4445V-6.0.0.6.3</ProductID>
            <ProductID>P-4445V-6.1.0.1.14</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-4445V-6.0.0.6.3</ProductID>
            <ProductID>P-4445V-6.1.0.1.14</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="25" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3141</Title>
      <Notes>
         <Note Type="Details" Ordinal="25" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Software (subcomponent: BASE).  Supported versions that are affected are 10.0.0, 10.0.2, 10.1.0, 10.2.0, 10.2.2, 10.3.0, 10.5.0 and  11.0.0 - 11.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle FLEXCUBE Universal Banking accessible data.  CVSS Base Score 4.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3141</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9052V-10.0.0</ProductID>
            <ProductID>P-9052V-10.0.2</ProductID>
            <ProductID>P-9052V-10.1.0</ProductID>
            <ProductID>P-9052V-10.2.0</ProductID>
            <ProductID>P-9052V-10.2.2</ProductID>
            <ProductID>P-9052V-10.3.0</ProductID>
            <ProductID>P-9052V-10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-9052V-10.0.0</ProductID>
            <ProductID>P-9052V-10.0.2</ProductID>
            <ProductID>P-9052V-10.1.0</ProductID>
            <ProductID>P-9052V-10.2.0</ProductID>
            <ProductID>P-9052V-10.2.2</ProductID>
            <ProductID>P-9052V-10.3.0</ProductID>
            <ProductID>P-9052V-10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="26" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3142</Title>
      <Notes>
         <Note Type="Details" Ordinal="26" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Software (subcomponent: BASE).  Supported versions that are affected are 5.0.5, 5.1.0, 5.2.0 and  5.3.0 - 5.3.4. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle FLEXCUBE Direct Banking accessible data.  CVSS Base Score 3.5 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3142</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9111V-5.0.5</ProductID>
            <ProductID>P-9111V-5.1.0</ProductID>
            <ProductID>P-9111V-5.2.0</ProductID>
            <ProductID>P-9111V-5.3.0 - 5.3.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-9111V-5.0.5</ProductID>
            <ProductID>P-9111V-5.1.0</ProductID>
            <ProductID>P-9111V-5.2.0</ProductID>
            <ProductID>P-9111V-5.3.0 - 5.3.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="27" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3144</Title>
      <Notes>
         <Note Type="Details" Ordinal="27" Title="Details" Audience="All">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server).  Supported versions that are affected are 5.5.26 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3144</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.26 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8478V-5.5.26 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="28" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3145</Title>
      <Notes>
         <Note Type="Details" Ordinal="28" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Software (subcomponent: BASE).  Supported versions that are affected are 5.0.2, 5.0.5, 5.1.0, 5.2.0, 5.3.0 - 5.3.4 and  6.2.0. Difficult to exploit vulnerability requiring logon to Operating System plus additional login/authentication to component or subcomponent.  Successful attack of this vulnerability can escalate attacker privileges resulting in unauthorized  read access to a subset of Oracle FLEXCUBE Direct Banking accessible data.  CVSS Base Score 1.5 (Confidentiality impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:L/AC:M/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3145</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9111V-5.0.2</ProductID>
            <ProductID>P-9111V-5.0.5</ProductID>
            <ProductID>P-9111V-5.1.0</ProductID>
            <ProductID>P-9111V-5.2.0</ProductID>
            <ProductID>P-9111V-5.3.0 - 5.3.4</ProductID>
            <ProductID>P-9111V-6.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>1.5</BaseScore>
            <Vector>AV:L/AC:M/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-9111V-5.0.2</ProductID>
            <ProductID>P-9111V-5.0.5</ProductID>
            <ProductID>P-9111V-5.1.0</ProductID>
            <ProductID>P-9111V-5.2.0</ProductID>
            <ProductID>P-9111V-5.3.0 - 5.3.4</ProductID>
            <ProductID>P-9111V-6.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="29" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3146</Title>
      <Notes>
         <Note Type="Details" Ordinal="29" Title="Details" Audience="All">Vulnerability in the Core RDBMS component of Oracle Database Server.  This vulnerability requires Create session, create any directory privileges for a successful attack.  Supported versions that are affected are 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2 and  11.2.0.3. Very difficult to exploit vulnerability allows successful authenticated network attacks via Oracle NET.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Core RDBMS accessible data.  CVSS Base Score 2.1 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:H/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3146</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11V-10.2.0.3</ProductID>
            <ProductID>P-11V-10.2.0.4</ProductID>
            <ProductID>P-11V-10.2.0.5</ProductID>
            <ProductID>P-11V-11.1.0.7</ProductID>
            <ProductID>P-11V-11.2.0.2</ProductID>
            <ProductID>P-11V-11.2.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:N/AC:H/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-11V-10.2.0.3</ProductID>
            <ProductID>P-11V-10.2.0.4</ProductID>
            <ProductID>P-11V-10.2.0.5</ProductID>
            <ProductID>P-11V-11.1.0.7</ProductID>
            <ProductID>P-11V-11.2.0.2</ProductID>
            <ProductID>P-11V-11.2.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="30" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3147</Title>
      <Notes>
         <Note Type="Details" Ordinal="30" Title="Details" Audience="All">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: MySQL Client).  Supported versions that are affected are 5.5.26 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some MySQL Server accessible data and ability to cause a partial denial of service (partial DOS) of MySQL Server.  CVSS Base Score 6.4 (Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3147</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.26 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8478V-5.5.26 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="31" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3148</Title>
      <Notes>
         <Note Type="Details" Ordinal="31" Title="Details" Audience="All">Vulnerability in the Oracle Field Service component of Oracle E-Business Suite (subcomponent: Wireless/WAP upload).   The supported version that is affected is 12.1.3. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Field Service accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3148</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-747V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-747V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="32" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3149</Title>
      <Notes>
         <Note Type="Details" Ordinal="32" Title="Details" Audience="All">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: MySQL Client).  Supported versions that are affected are 5.5.26 and earlier. Difficult to exploit vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of MySQL Server accessible data.  CVSS Base Score 3.5 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3149</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.26 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8478V-5.5.26 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="33" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3150</Title>
      <Notes>
         <Note Type="Details" Ordinal="33" Title="Details" Audience="All">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server Optimizer).  Supported versions that are affected are 5.1.64 and earlier and  5.5.26 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3150</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.1.64 and earlier</ProductID>
            <ProductID>P-8478V-5.5.26 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8478V-5.1.64 and earlier</ProductID>
            <ProductID>P-8478V-5.5.26 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="34" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3151</Title>
      <Notes>
         <Note Type="Details" Ordinal="34" Title="Details" Audience="All">Vulnerability in the Core RDBMS component of Oracle Database Server.  Supported versions that are affected are 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2 and  11.2.0.3. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Core RDBMS accessible data and ability to cause a hang or frequently repeatable crash (complete DOS) of Core RDBMS.   Note: The vulnerability affects Unix and Linux platforms only. CVSS Base Score 3.3 (Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:N/I:P/A:P).  Oracle Vector: (AV:L/AC:M/Au:N/C:N/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3151</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-115V-10.2.0.4</ProductID>
            <ProductID>P-115V-10.2.0.5</ProductID>
            <ProductID>P-115V-11.1.0.7</ProductID>
            <ProductID>P-115V-11.2.0.2</ProductID>
            <ProductID>P-115V-11.2.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.3</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:N/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-115V-10.2.0.4</ProductID>
            <ProductID>P-115V-10.2.0.5</ProductID>
            <ProductID>P-115V-11.1.0.7</ProductID>
            <ProductID>P-115V-11.2.0.2</ProductID>
            <ProductID>P-115V-11.2.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="35" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3152</Title>
      <Notes>
         <Note Type="Details" Ordinal="35" Title="Details" Audience="All">Vulnerability in the Oracle Reports Developer component of Oracle Fusion Middleware (subcomponent: Report Server Component).  Supported versions that are affected are 11.1.1.4, 11.1.1.6 and  11.1.2.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Reports Developer accessible data as well as  read access to all Oracle Reports Developer accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3152</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-159V-11.1.1.4</ProductID>
            <ProductID>P-159V-11.1.1.6</ProductID>
            <ProductID>P-159V-11.1.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-159V-11.1.1.4</ProductID>
            <ProductID>P-159V-11.1.1.6</ProductID>
            <ProductID>P-159V-11.1.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="36" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3153</Title>
      <Notes>
         <Note Type="Details" Ordinal="36" Title="Details" Audience="All">Vulnerability in the Oracle Reports Developer component of Oracle Fusion Middleware (subcomponent: Servlet).  Supported versions that are affected are 11.1.1.4, 11.1.1.6 and  11.1.2.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Reports Developer accessible data as well as  read access to a subset of Oracle Reports Developer accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3153</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-159V-11.1.1.4</ProductID>
            <ProductID>P-159V-11.1.1.6</ProductID>
            <ProductID>P-159V-11.1.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-159V-11.1.1.4</ProductID>
            <ProductID>P-159V-11.1.1.6</ProductID>
            <ProductID>P-159V-11.1.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="37" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3154</Title>
      <Notes>
         <Note Type="Details" Ordinal="37" Title="Details" Audience="All">Vulnerability in the Oracle Agile PLM Framework component of Oracle Supply Chain Products Suite (subcomponent: ATTACH).   The supported version that is affected is 9.3.1.0. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Agile PLM Framework accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3154</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-4461V-9.3.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="38" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3155</Title>
      <Notes>
         <Note Type="Details" Ordinal="38" Title="Details" Audience="All">Vulnerability in the Oracle GlassFish Server, Sun GlassFish Enterprise Server, Sun Java System Application Server component of Oracle Sun Products Suite (subcomponent: CORBA ORB).  Supported versions that are affected are Sun GlassFish Enterprise Server 2.1.1, Oracle GlassFish Server 3.0.1, Oracle GlassFish Server 3.1.2, Sun Java System Application Server 8.1 and  Sun Java System Application Server 8.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via TCP/IP.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GlassFish Server, Sun GlassFish Enterprise Server, Sun Java System Application Server.  CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3155</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8493V-Sun GlassFish Enterprise Server 2.1.1</ProductID>
            <ProductID>P-8493V-Oracle GlassFish Server 3.0.1</ProductID>
            <ProductID>P-8493V-Oracle GlassFish Server 3.1.2</ProductID>
            <ProductID>P-8493V-Sun Java System Application Server 8.1</ProductID>
            <ProductID>P-8493V-Sun Java System Application Server 8.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8493V-Sun GlassFish Enterprise Server 2.1.1</ProductID>
            <ProductID>P-8493V-Oracle GlassFish Server 3.0.1</ProductID>
            <ProductID>P-8493V-Oracle GlassFish Server 3.1.2</ProductID>
            <ProductID>P-8493V-Sun Java System Application Server 8.1</ProductID>
            <ProductID>P-8493V-Sun Java System Application Server 8.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="39" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3156</Title>
      <Notes>
         <Note Type="Details" Ordinal="39" Title="Details" Audience="All">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server).  Supported versions that are affected are 5.5.25 and earlier. Difficult to exploit vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 3.5 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3156</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.25 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8478V-5.5.25 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="40" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3157</Title>
      <Notes>
         <Note Type="Details" Ordinal="40" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Software (subcomponent: BASE).  Supported versions that are affected are 5.0.2, 5.0.5, 5.1.0, 5.2.0, 5.3.0 - 5.3.4, 6.0.1, 6.2.0 and  12. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle FLEXCUBE Direct Banking accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3157</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9111V-5.0.2</ProductID>
            <ProductID>P-9111V-5.0.5</ProductID>
            <ProductID>P-9111V-5.1.0</ProductID>
            <ProductID>P-9111V-5.2.0</ProductID>
            <ProductID>P-9111V-5.3.0 - 5.3.4</ProductID>
            <ProductID>P-9111V-6.0.1</ProductID>
            <ProductID>P-9111V-6.2.0</ProductID>
            <ProductID>P-9111V-12</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-9111V-5.0.2</ProductID>
            <ProductID>P-9111V-5.0.5</ProductID>
            <ProductID>P-9111V-5.1.0</ProductID>
            <ProductID>P-9111V-5.2.0</ProductID>
            <ProductID>P-9111V-5.3.0 - 5.3.4</ProductID>
            <ProductID>P-9111V-6.0.1</ProductID>
            <ProductID>P-9111V-6.2.0</ProductID>
            <ProductID>P-9111V-12</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="41" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3158</Title>
      <Notes>
         <Note Type="Details" Ordinal="41" Title="Details" Audience="All">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Protocol).  Supported versions that are affected are 5.1.64 and earlier and  5.5.26 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized takeover of MySQL Server possibly including arbitrary code execution within the MySQL Server.  CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3158</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.1.64 and earlier</ProductID>
            <ProductID>P-8478V-5.5.26 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8478V-5.1.64 and earlier</ProductID>
            <ProductID>P-8478V-5.5.26 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="42" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3160</Title>
      <Notes>
         <Note Type="Details" Ordinal="42" Title="Details" Audience="All">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server Installation).  Supported versions that are affected are 5.1.65 and earlier and  5.5.27 and earlier. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of MySQL Server accessible data.  CVSS Base Score 2.1 (Confidentiality impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:L/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3160</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.1.65 and earlier</ProductID>
            <ProductID>P-8478V-5.5.27 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8478V-5.1.65 and earlier</ProductID>
            <ProductID>P-8478V-5.5.27 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="43" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3161</Title>
      <Notes>
         <Note Type="Details" Ordinal="43" Title="Details" Audience="All">Vulnerability in the Oracle Agile PLM Framework component of Oracle Supply Chain Products Suite (subcomponent: Web Client (CS)).   The supported version that is affected is 9.3.1.1. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Agile PLM Framework accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3161</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-4461V-9.3.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="44" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3162</Title>
      <Notes>
         <Note Type="Details" Ordinal="44" Title="Details" Audience="All">Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: MDS loading).  Supported versions that are affected are 11.5.10.2, 12.0.6 and 12.1.3. Easily exploitable vulnerability requiring logon to Operating System plus additional login/authentication to component or subcomponent.  Successful attack of this vulnerability can escalate attacker privileges resulting in unauthorized  read access to a subset of Oracle Applications Framework accessible data.  CVSS Base Score 1.7 (Confidentiality impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:L/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3162</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1472V-11.5.10.2</ProductID>
            <ProductID>P-1472V-12.0.6</ProductID>
            <ProductID>P-1472V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>1.7</BaseScore>
            <Vector>AV:L/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-1472V-11.5.10.2</ProductID>
            <ProductID>P-1472V-12.0.6</ProductID>
            <ProductID>P-1472V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="45" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3163</Title>
      <Notes>
         <Note Type="Details" Ordinal="45" Title="Details" Audience="All">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Information Schema).  Supported versions that are affected are 5.1.64 and earlier and  5.5.26 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: The CVSS Base Score is 9.0 only for Windows. For Linux, Unix and other platforms, the CVSS Base Score is 6.5, and the impacts for Confidentiality, Integrity and Availability are Partial+. CVSS Base Score 9.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:S/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3163</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.1.64 and earlier</ProductID>
            <ProductID>P-8478V-5.5.26 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>9.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8478V-5.1.64 and earlier</ProductID>
            <ProductID>P-8478V-5.5.26 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="46" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3164</Title>
      <Notes>
         <Note Type="Details" Ordinal="46" Title="Details" Audience="All">Vulnerability in the Oracle Marketing component of Oracle E-Business Suite (subcomponent: Publish Item).  Supported versions that are affected are 11.5.10.2, 12.0.6, 12.1.1, 12.1.2 and 12.1.3. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Marketing accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3164</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-759V-11.5.10.2</ProductID>
            <ProductID>P-759V-12.0.6</ProductID>
            <ProductID>P-759V-12.1.1</ProductID>
            <ProductID>P-759V-12.1.2</ProductID>
            <ProductID>P-759V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-759V-11.5.10.2</ProductID>
            <ProductID>P-759V-12.0.6</ProductID>
            <ProductID>P-759V-12.1.1</ProductID>
            <ProductID>P-759V-12.1.2</ProductID>
            <ProductID>P-759V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="47" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3165</Title>
      <Notes>
         <Note Type="Details" Ordinal="47" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: mailx(1)).  Supported versions that are affected are 8, 9, 10 and  11. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Solaris accessible data as well as  read access to a subset of Solaris accessible data.  CVSS Base Score 3.6 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:L/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3165</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-8</ProductID>
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.6</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8752V-8</ProductID>
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="48" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3166</Title>
      <Notes>
         <Note Type="Details" Ordinal="48" Title="Details" Audience="All">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB).  Supported versions that are affected are 5.1.63 and earlier and  5.5.25 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3166</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.1.63 and earlier</ProductID>
            <ProductID>P-8478V-5.5.25 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8478V-5.1.63 and earlier</ProductID>
            <ProductID>P-8478V-5.5.25 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="49" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3167</Title>
      <Notes>
         <Note Type="Details" Ordinal="49" Title="Details" Audience="All">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server Full Text Search).  Supported versions that are affected are 5.1.63 and earlier and  5.5.25 and earlier. Difficult to exploit vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 3.5 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3167</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.1.63 and earlier</ProductID>
            <ProductID>P-8478V-5.5.25 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8478V-5.1.63 and earlier</ProductID>
            <ProductID>P-8478V-5.5.25 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="50" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3171</Title>
      <Notes>
         <Note Type="Details" Ordinal="50" Title="Details" Audience="All">Vulnerability in the Oracle Applications Technology Stack component of Oracle E-Business Suite (subcomponent: Autoconfig Templates).  Supported versions that are affected are 11.5.10.2, 12.0.6 and 12.1.3. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Applications Technology Stack accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3171</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1745V-11.5.10.2</ProductID>
            <ProductID>P-1745V-12.0.6</ProductID>
            <ProductID>P-1745V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-1745V-11.5.10.2</ProductID>
            <ProductID>P-1745V-12.0.6</ProductID>
            <ProductID>P-1745V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="51" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3173</Title>
      <Notes>
         <Note Type="Details" Ordinal="51" Title="Details" Audience="All">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB Plugin).  Supported versions that are affected are 5.1.63 and earlier and  5.5.25 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3173</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.1.63 and earlier</ProductID>
            <ProductID>P-8478V-5.5.25 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8478V-5.1.63 and earlier</ProductID>
            <ProductID>P-8478V-5.5.25 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="52" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3175</Title>
      <Notes>
         <Note Type="Details" Ordinal="52" Title="Details" Audience="All">Vulnerability in the Oracle Application Server Single Sign-On component of Oracle Fusion Middleware (subcomponent: Cookies/Tokens, Redirects).   The supported version that is affected is 10.1.4.3.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Application Server Single Sign-On accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3175</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1318V-10.1.4.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-1318V-10.1.4.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="53" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3176</Title>
      <Notes>
         <Note Type="Details" Ordinal="53" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Panel Processor).   The supported version that is affected is 8.52. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3176</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.52</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-5085V-8.52</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="54" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3177</Title>
      <Notes>
         <Note Type="Details" Ordinal="54" Title="Details" Audience="All">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server).  Supported versions that are affected are 5.1.65 and earlier and  5.5.27 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 6.8 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:C).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3177</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.1.65 and earlier</ProductID>
            <ProductID>P-8478V-5.5.27 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.8</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8478V-5.1.65 and earlier</ProductID>
            <ProductID>P-8478V-5.5.27 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="55" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3179</Title>
      <Notes>
         <Note Type="Details" Ordinal="55" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Tree Manager).  Supported versions that are affected are 8.50, 8.51 and  8.52. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3179</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="56" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3180</Title>
      <Notes>
         <Note Type="Details" Ordinal="56" Title="Details" Audience="All">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server Optimizer).  Supported versions that are affected are 5.1.65 and earlier and  5.5.27 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3180</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.1.65 and earlier</ProductID>
            <ProductID>P-8478V-5.5.27 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8478V-5.1.65 and earlier</ProductID>
            <ProductID>P-8478V-5.5.27 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="57" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3181</Title>
      <Notes>
         <Note Type="Details" Ordinal="57" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Security).  Supported versions that are affected are 8.50, 8.51 and  8.52. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3181</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="58" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3182</Title>
      <Notes>
         <Note Type="Details" Ordinal="58" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: PIA Core Technology).   The supported version that is affected is 8.52. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3182</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.52</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-5085V-8.52</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="59" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3183</Title>
      <Notes>
         <Note Type="Details" Ordinal="59" Title="Details" Audience="All">Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI).  Supported versions that are affected are 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2 and 11.1.1.6.0. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle WebCenter Sites accessible data as well as  read access to a subset of Oracle WebCenter Sites accessible data.  CVSS Base Score 4.9 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3183</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9617V-6.1</ProductID>
            <ProductID>P-9617V-6.2</ProductID>
            <ProductID>P-9617V-6.3.x</ProductID>
            <ProductID>P-9617V-7</ProductID>
            <ProductID>P-9617V-7.0.1</ProductID>
            <ProductID>P-9617V-7.0.2</ProductID>
            <ProductID>P-9617V-7.0.3</ProductID>
            <ProductID>P-9617V-7.5</ProductID>
            <ProductID>P-9617V-7.6.1</ProductID>
            <ProductID>P-9617V-7.6.2</ProductID>
            <ProductID>P-9617V-11.1.1.6.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.9</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-9617V-6.1</ProductID>
            <ProductID>P-9617V-6.2</ProductID>
            <ProductID>P-9617V-6.3.x</ProductID>
            <ProductID>P-9617V-7</ProductID>
            <ProductID>P-9617V-7.0.1</ProductID>
            <ProductID>P-9617V-7.0.2</ProductID>
            <ProductID>P-9617V-7.0.3</ProductID>
            <ProductID>P-9617V-7.5</ProductID>
            <ProductID>P-9617V-7.6.1</ProductID>
            <ProductID>P-9617V-7.6.2</ProductID>
            <ProductID>P-9617V-11.1.1.6.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="60" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3184</Title>
      <Notes>
         <Note Type="Details" Ordinal="60" Title="Details" Audience="All">Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI).  Supported versions that are affected are 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2 and 11.1.1.6.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle WebCenter Sites accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3184</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9617V-6.1</ProductID>
            <ProductID>P-9617V-6.2</ProductID>
            <ProductID>P-9617V-6.3.x</ProductID>
            <ProductID>P-9617V-7</ProductID>
            <ProductID>P-9617V-7.0.1</ProductID>
            <ProductID>P-9617V-7.0.2</ProductID>
            <ProductID>P-9617V-7.0.3</ProductID>
            <ProductID>P-9617V-7.5</ProductID>
            <ProductID>P-9617V-7.6.1</ProductID>
            <ProductID>P-9617V-7.6.2</ProductID>
            <ProductID>P-9617V-11.1.1.6.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-9617V-6.1</ProductID>
            <ProductID>P-9617V-6.2</ProductID>
            <ProductID>P-9617V-6.3.x</ProductID>
            <ProductID>P-9617V-7</ProductID>
            <ProductID>P-9617V-7.0.1</ProductID>
            <ProductID>P-9617V-7.0.2</ProductID>
            <ProductID>P-9617V-7.0.3</ProductID>
            <ProductID>P-9617V-7.5</ProductID>
            <ProductID>P-9617V-7.6.1</ProductID>
            <ProductID>P-9617V-7.6.2</ProductID>
            <ProductID>P-9617V-11.1.1.6.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="61" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3185</Title>
      <Notes>
         <Note Type="Details" Ordinal="61" Title="Details" Audience="All">Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI).  Supported versions that are affected are 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2 and 11.1.1.6.0. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle WebCenter Sites accessible data as well as  read access to a subset of Oracle WebCenter Sites accessible data.  CVSS Base Score 4.9 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3185</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9617V-6.1</ProductID>
            <ProductID>P-9617V-6.2</ProductID>
            <ProductID>P-9617V-6.3.x</ProductID>
            <ProductID>P-9617V-7</ProductID>
            <ProductID>P-9617V-7.0.1</ProductID>
            <ProductID>P-9617V-7.0.2</ProductID>
            <ProductID>P-9617V-7.0.3</ProductID>
            <ProductID>P-9617V-7.5</ProductID>
            <ProductID>P-9617V-7.6.1</ProductID>
            <ProductID>P-9617V-7.6.2</ProductID>
            <ProductID>P-9617V-11.1.1.6.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.9</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-9617V-6.1</ProductID>
            <ProductID>P-9617V-6.2</ProductID>
            <ProductID>P-9617V-6.3.x</ProductID>
            <ProductID>P-9617V-7</ProductID>
            <ProductID>P-9617V-7.0.1</ProductID>
            <ProductID>P-9617V-7.0.2</ProductID>
            <ProductID>P-9617V-7.0.3</ProductID>
            <ProductID>P-9617V-7.5</ProductID>
            <ProductID>P-9617V-7.6.1</ProductID>
            <ProductID>P-9617V-7.6.2</ProductID>
            <ProductID>P-9617V-11.1.1.6.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="62" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3186</Title>
      <Notes>
         <Note Type="Details" Ordinal="62" Title="Details" Audience="All">Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI).  Supported versions that are affected are 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2 and 11.1.1.6.0. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle WebCenter Sites accessible data as well as  read access to a subset of Oracle WebCenter Sites accessible data.  CVSS Base Score 4.9 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3186</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9617V-6.1</ProductID>
            <ProductID>P-9617V-6.2</ProductID>
            <ProductID>P-9617V-6.3.x</ProductID>
            <ProductID>P-9617V-7</ProductID>
            <ProductID>P-9617V-7.0.1</ProductID>
            <ProductID>P-9617V-7.0.2</ProductID>
            <ProductID>P-9617V-7.0.3</ProductID>
            <ProductID>P-9617V-7.5</ProductID>
            <ProductID>P-9617V-7.6.1</ProductID>
            <ProductID>P-9617V-7.6.2</ProductID>
            <ProductID>P-9617V-11.1.1.6.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.9</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-9617V-6.1</ProductID>
            <ProductID>P-9617V-6.2</ProductID>
            <ProductID>P-9617V-6.3.x</ProductID>
            <ProductID>P-9617V-7</ProductID>
            <ProductID>P-9617V-7.0.1</ProductID>
            <ProductID>P-9617V-7.0.2</ProductID>
            <ProductID>P-9617V-7.0.3</ProductID>
            <ProductID>P-9617V-7.5</ProductID>
            <ProductID>P-9617V-7.6.1</ProductID>
            <ProductID>P-9617V-7.6.2</ProductID>
            <ProductID>P-9617V-11.1.1.6.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="63" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3187</Title>
      <Notes>
         <Note Type="Details" Ordinal="63" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: Kernel).   The supported version that is affected is 10. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.  CVSS Base Score 6.9 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:L/AC:M/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3187</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.9</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8752V-10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="64" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3188</Title>
      <Notes>
         <Note Type="Details" Ordinal="64" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: PIA Core Technology).  Supported versions that are affected are 8.50 and  8.51. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3188</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="65" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3189</Title>
      <Notes>
         <Note Type="Details" Ordinal="65" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: COMSTAR).   The supported version that is affected is 11. Easily exploitable vulnerability allows successful unauthenticated network attacks via TCP/IP(iSCSI).  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 7.8 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3189</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.8</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8752V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="66" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3191</Title>
      <Notes>
         <Note Type="Details" Ordinal="66" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Data Mover).  Supported versions that are affected are 8.50, 8.51 and  8.52. Very difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools.  CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:H/Au:S/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3191</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:N/AC:H/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="67" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3193</Title>
      <Notes>
         <Note Type="Details" Ordinal="67" Title="Details" Audience="All">Vulnerability in the Oracle BI Publisher  component of Oracle Fusion Middleware (subcomponent: Administration).  Supported versions that are affected are 10.3.4.2, 11.1.1.5.0,11.1.1.6.0 and 11.1.1.6.2. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle BI Publisher  accessible data.  CVSS Base Score 3.5 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3193</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1479V-10.3.4.2</ProductID>
            <ProductID>P-1479V-11.1.1.5.0</ProductID>
            <ProductID>P-1479V-11.1.1.6.0</ProductID>
            <ProductID>P-1479V-11.1.1.6.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-1479V-10.3.4.2</ProductID>
            <ProductID>P-1479V-11.1.1.5.0</ProductID>
            <ProductID>P-1479V-11.1.1.6.0</ProductID>
            <ProductID>P-1479V-11.1.1.6.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="68" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3194</Title>
      <Notes>
         <Note Type="Details" Ordinal="68" Title="Details" Audience="All">Vulnerability in the Oracle BI Publisher  component of Oracle Fusion Middleware (subcomponent: Administration).  Supported versions that are affected are 10.1.3.4.2, 11.1.1.5.0, 11.1.1.6.0 and 11.1.1.6.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle BI Publisher  accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3194</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1479V-10.1.3.4.2</ProductID>
            <ProductID>P-1479V-11.1.1.5.0</ProductID>
            <ProductID>P-1479V-11.1.1.6.0</ProductID>
            <ProductID>P-1479V-11.1.1.6.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-1479V-10.1.3.4.2</ProductID>
            <ProductID>P-1479V-11.1.1.5.0</ProductID>
            <ProductID>P-1479V-11.1.1.6.0</ProductID>
            <ProductID>P-1479V-11.1.1.6.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="69" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3195</Title>
      <Notes>
         <Note Type="Details" Ordinal="69" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Portal).  Supported versions that are affected are 8.50, 8.51 and  8.52. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3195</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="70" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3196</Title>
      <Notes>
         <Note Type="Details" Ordinal="70" Title="Details" Audience="All">Vulnerability in the Oracle Human Resources component of Oracle E-Business Suite (subcomponent: PDF generation).  Supported versions that are affected are 11.5.10.2, 12.0.6, 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Human Resources accessible data and ability to cause a partial denial of service (partial DOS) of Oracle Human Resources.  CVSS Base Score 6.4 (Confidentiality and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3196</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-507V-11.5.10.2</ProductID>
            <ProductID>P-507V-12.0.6</ProductID>
            <ProductID>P-507V-12.1.1</ProductID>
            <ProductID>P-507V-12.1.2</ProductID>
            <ProductID>P-507V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-507V-11.5.10.2</ProductID>
            <ProductID>P-507V-12.0.6</ProductID>
            <ProductID>P-507V-12.1.1</ProductID>
            <ProductID>P-507V-12.1.2</ProductID>
            <ProductID>P-507V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="71" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3197</Title>
      <Notes>
         <Note Type="Details" Ordinal="71" Title="Details" Audience="All">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server Replication).  Supported versions that are affected are 5.1.64 and earlier and  5.5.26 and earlier. Difficult to exploit vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 3.5 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3197</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.1.64 and earlier</ProductID>
            <ProductID>P-8478V-5.5.26 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8478V-5.1.64 and earlier</ProductID>
            <ProductID>P-8478V-5.5.26 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="72" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3198</Title>
      <Notes>
         <Note Type="Details" Ordinal="72" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Query).  Supported versions that are affected are 8.51 and  8.52. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3198</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="73" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3199</Title>
      <Notes>
         <Note Type="Details" Ordinal="73" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: Gnome Trusted Extension).  Supported versions that are affected are 10 and  11. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.  CVSS Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:L/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3199</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.2</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="74" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3200</Title>
      <Notes>
         <Note Type="Details" Ordinal="74" Title="Details" Audience="All">Vulnerability in the Oracle Agile PLM Framework component of Oracle Supply Chain Products Suite (subcomponent: ROLESPRV).   The supported version that is affected is 9.3.1.1. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Agile PLM Framework accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3200</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-4461V-9.3.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="75" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3201</Title>
      <Notes>
         <Note Type="Details" Ordinal="75" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise Campus Solutions component of Oracle PeopleSoft Products (subcomponent: Self-Service (Student Records)).   The supported version that is affected is 9.0. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of PeopleSoft Enterprise Campus Solutions accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3201</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5182V-9.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-5182V-9.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="76" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3202</Title>
      <Notes>
         <Note Type="Details" Ordinal="76" Title="Details" Audience="All">Vulnerability in the Oracle JRockit component of Oracle Fusion Middleware.  Supported versions that are affected are 28.2.4 and before: JDK/JRE 5 and 6 and  27.7.3 and before: JKD/JRE 5. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Oracle released a &lt;a href="http://www.oracle.com/technetwork/topics/security/javacpuoct2012-1515924.html"&gt;Java SE Critical Patch Update&lt;/a&gt; on October 16, 2012 to address multiple vulnerabilities affecting the Java Runtime Environment. Oracle CVE-2012-3202 refers to the advisories that are applicable to JRockit from the Java SE Critical Patch Update. The CVSS score of this vulnerability CVE# reflects the highest among those fixed in JRockit. The complete list of all vulnerabilities addressed in JRockit under CVE-2012-3202 is as follows: CVE-2012-5083, CVE-2012-1531, CVE-2012-5081, and CVE-2012-5085. CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3202</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5260V-28.2.4 and before: JDK/JRE 5 and 6</ProductID>
            <ProductID>P-5260V-27.7.3 and before: JKD/JRE 5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-5260V-28.2.4 and before: JDK/JRE 5 and 6</ProductID>
            <ProductID>P-5260V-27.7.3 and before: JKD/JRE 5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="77" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3203</Title>
      <Notes>
         <Note Type="Details" Ordinal="77" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: Gnome Display Manager(GDM)).   The supported version that is affected is 11. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Solaris.  CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3203</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8752V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="78" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3204</Title>
      <Notes>
         <Note Type="Details" Ordinal="78" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: Power Management).   The supported version that is affected is 11. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.  CVSS Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:L/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3204</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.2</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8752V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="79" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3205</Title>
      <Notes>
         <Note Type="Details" Ordinal="79" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: Vino server).   The supported version that is affected is 11. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Solaris accessible data.  CVSS Base Score 2.1 (Integrity impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3205</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8752V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="80" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3206</Title>
      <Notes>
         <Note Type="Details" Ordinal="80" Title="Details" Audience="All">Vulnerability in the SPARC T3, Netra SPARC T3, SPARC T4, Netra SPARC T4 component of Oracle Sun Products Suite (subcomponent: Integrated Lights Out Manager CLI).  Supported versions that are affected are SysFW 8.2.0.a for SPARC T3 and  T4 based servers; see 1475188.1 for other servers. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of SPARC T3, Netra SPARC T3, SPARC T4, Netra SPARC T4 accessible data.   Note: Specific products affected by CVE-2012-3206 are: SPARC T3-1, SPARC T3-2, SPARC T3-4, SPARC T3-1B, Netra SPARC T3-1, Netra SPARC T3-1B, SPARC T4-1, SPARC T4-2, SPARC T4-4, SPARC T4-1B, Netra SPARC T4-1, Netra SPARC T4-2, Netra SPARC T4-2B. CVSS Base Score 2.1 (Confidentiality impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:L/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3206</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-SysFW 8.2.0.a for SPARC T3</ProductID>
            <ProductID>P-8752V-T4 based servers; see 1475188.1 for other servers</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8752V-SysFW 8.2.0.a for SPARC T3</ProductID>
            <ProductID>P-8752V-T4 based servers; see 1475188.1 for other servers</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="81" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3207</Title>
      <Notes>
         <Note Type="Details" Ordinal="81" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: Kernel).  Supported versions that are affected are 9, 10 and  11. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 4.9 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3207</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.9</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="82" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3208</Title>
      <Notes>
         <Note Type="Details" Ordinal="82" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: Kernel/RCTL).  Supported versions that are affected are 10 and  11. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 4.9 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3208</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.9</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="83" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3209</Title>
      <Notes>
         <Note Type="Details" Ordinal="83" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: Logical Domain(LDOM)).  Supported versions that are affected are 10 and  11. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS) as well as  update, insert or delete access to some Solaris accessible data.   Note: CVE-2012-3209 and CVE-2012-3215 only affects Solaris on the SPARC platform. CVSS Base Score 5.6 (Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:P/A:C).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:P/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3209</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.6</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:P/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="84" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3210</Title>
      <Notes>
         <Note Type="Details" Ordinal="84" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: Kernel).   The supported version that is affected is 11. Easily exploitable vulnerability allows successful unauthenticated network attacks via TCP/IP.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 7.8 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3210</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.8</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8752V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="85" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3211</Title>
      <Notes>
         <Note Type="Details" Ordinal="85" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: Kernel/System Call).  Supported versions that are affected are 10 and  11. Easily exploitable vulnerability requiring logon to Operating System plus additional login/authentication to component or subcomponent.  Successful attack of this vulnerability can escalate attacker privileges resulting in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 4.6 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:S/C:N/I:N/A:C).  Oracle Vector: (AV:L/AC:L/Au:S/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3211</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.6</BaseScore>
            <Vector>AV:L/AC:L/Au:S/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="86" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3212</Title>
      <Notes>
         <Note Type="Details" Ordinal="86" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: Kernel).  Supported versions that are affected are 10 and  11. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).   Note: CVE-2012-3212 affects only Solaris on SPARC T4 servers. CVSS Base Score 4.7 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:L/AC:M/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3212</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.7</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="87" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3214</Title>
      <Notes>
         <Note Type="Details" Ordinal="87" Title="Details" Audience="All">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).   The supported version that is affected is 8.3.7.0. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology.   Note: Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. If the hosting software passes data received over the network to Outside In Technology code, the CVSS score would increase to 6.8. CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3214</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.3.7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-2276V-8.3.7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="88" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3215</Title>
      <Notes>
         <Note Type="Details" Ordinal="88" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: Kernel).  Supported versions that are affected are 10 and  11. Easily exploitable vulnerability requiring logon to Operating System plus additional login/authentication to component or subcomponent.  Successful attack of this vulnerability can escalate attacker privileges resulting in unauthorized  read access to a subset of Solaris accessible data.   Note: CVE-2012-3209 and CVE-2012-3215 only affects Solaris on the SPARC platform. CVSS Base Score 1.7 (Confidentiality impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:L/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3215</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>1.7</BaseScore>
            <Vector>AV:L/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="89" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3217</Title>
      <Notes>
         <Note Type="Details" Ordinal="89" Title="Details" Audience="All">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In HTML Export SDK).   The supported version that is affected is 8.3.7.0. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology.   Note: Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. If the hosting software passes data received over the network to Outside In Technology code, the CVSS score would increase to 6.8. CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3217</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.3.7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-2276V-8.3.7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="90" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3217</Title>
      <Notes>
         <Note Type="Details" Ordinal="90" Title="Details" Audience="All">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In HTML Export SDK).   The supported version that is affected is 8.3.7.0. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology.   Note: Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. If the hosting software passes data received over the network to Outside In Technology code, the CVSS score would increase to 6.8. CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3217</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.3.7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-2276V-8.3.7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="91" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3221</Title>
      <Notes>
         <Note Type="Details" Ordinal="91" Title="Details" Audience="All">Vulnerability in the Oracle VM Virtual Box component of Oracle Virtualization (subcomponent: VirtualBox Core).  Supported versions that are affected are 3.2, 4.0 and  4.1. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM Virtual Box.  CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3221</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-3.2</ProductID>
            <ProductID>P-8370V-4.0</ProductID>
            <ProductID>P-8370V-4.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8370V-3.2</ProductID>
            <ProductID>P-8370V-4.0</ProductID>
            <ProductID>P-8370V-4.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="92" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3222</Title>
      <Notes>
         <Note Type="Details" Ordinal="92" Title="Details" Audience="All">Vulnerability in the Oracle iRecruitment component of Oracle E-Business Suite (subcomponent: Signon (local only)).  Supported versions that are affected are 11.5.10.2, 12.0.6, 12.1.1, 12.1.2 and  12.1.3. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle iRecruitment.  CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3222</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1193V-11.5.10.2</ProductID>
            <ProductID>P-1193V-12.0.6</ProductID>
            <ProductID>P-1193V-12.1.1</ProductID>
            <ProductID>P-1193V-12.1.2</ProductID>
            <ProductID>P-1193V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-1193V-11.5.10.2</ProductID>
            <ProductID>P-1193V-12.0.6</ProductID>
            <ProductID>P-1193V-12.1.1</ProductID>
            <ProductID>P-1193V-12.1.2</ProductID>
            <ProductID>P-1193V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="93" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3223</Title>
      <Notes>
         <Note Type="Details" Ordinal="93" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Software (subcomponent: BASE).  Supported versions that are affected are 5.0.2, 5.0.5, 5.1.0, 5.2.0, 5.3.0 - 5.3.4 and  6.0.1. Very difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle FLEXCUBE Direct Banking accessible data.  CVSS Base Score 2.1 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:H/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3223</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9111V-5.0.2</ProductID>
            <ProductID>P-9111V-5.0.5</ProductID>
            <ProductID>P-9111V-5.1.0</ProductID>
            <ProductID>P-9111V-5.2.0</ProductID>
            <ProductID>P-9111V-5.3.0 - 5.3.4</ProductID>
            <ProductID>P-9111V-6.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:N/AC:H/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-9111V-5.0.2</ProductID>
            <ProductID>P-9111V-5.0.5</ProductID>
            <ProductID>P-9111V-5.1.0</ProductID>
            <ProductID>P-9111V-5.2.0</ProductID>
            <ProductID>P-9111V-5.3.0 - 5.3.4</ProductID>
            <ProductID>P-9111V-6.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="94" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3224</Title>
      <Notes>
         <Note Type="Details" Ordinal="94" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Software (subcomponent: BASE).  Supported versions that are affected are 5.1.0, 5.2.0 and  5.3.0 - 5.3.4. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle FLEXCUBE Direct Banking accessible data.  CVSS Base Score 3.5 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3224</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9111V-5.1.0</ProductID>
            <ProductID>P-9111V-5.2.0</ProductID>
            <ProductID>P-9111V-5.3.0 - 5.3.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-9111V-5.1.0</ProductID>
            <ProductID>P-9111V-5.2.0</ProductID>
            <ProductID>P-9111V-5.3.0 - 5.3.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="95" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3225</Title>
      <Notes>
         <Note Type="Details" Ordinal="95" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Software (subcomponent: BASE).  Supported versions that are affected are 5.3.0 - 5.3.4. Very difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle FLEXCUBE Direct Banking accessible data as well as  read access to a subset of Oracle FLEXCUBE Direct Banking accessible data.  CVSS Base Score 3.6 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:H/Au:S/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3225</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9111V-5.3.0 - 5.3.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.6</BaseScore>
            <Vector>AV:N/AC:H/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-9111V-5.3.0 - 5.3.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="96" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3226</Title>
      <Notes>
         <Note Type="Details" Ordinal="96" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Software (subcomponent: BASE).  Supported versions that are affected are 10.0.0, 10.0.2, 10.1.0, 10.2.0, 10.2.2, 10.3.0, 10.5.0 and  11.0.0 - 11.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle FLEXCUBE Universal Banking accessible data as well as  read access to a subset of Oracle FLEXCUBE Universal Banking accessible data.  CVSS Base Score 5.5 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3226</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9052V-10.0.0</ProductID>
            <ProductID>P-9052V-10.0.2</ProductID>
            <ProductID>P-9052V-10.1.0</ProductID>
            <ProductID>P-9052V-10.2.0</ProductID>
            <ProductID>P-9052V-10.2.2</ProductID>
            <ProductID>P-9052V-10.3.0</ProductID>
            <ProductID>P-9052V-10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-9052V-10.0.0</ProductID>
            <ProductID>P-9052V-10.0.2</ProductID>
            <ProductID>P-9052V-10.1.0</ProductID>
            <ProductID>P-9052V-10.2.0</ProductID>
            <ProductID>P-9052V-10.2.2</ProductID>
            <ProductID>P-9052V-10.3.0</ProductID>
            <ProductID>P-9052V-10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="97" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3226</Title>
      <Notes>
         <Note Type="Details" Ordinal="97" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Software (subcomponent: BASE).  Supported versions that are affected are 10.0.0, 10.0.2, 10.1.0, 10.2.0, 10.2.2, 10.3.0, 10.5.0, 11.0.0 - 11.4.0 and  12.0.0. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle FLEXCUBE Universal Banking accessible data as well as  read access to a subset of Oracle FLEXCUBE Universal Banking accessible data.  CVSS Base Score 5.5 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3226</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9052V-10.0.0</ProductID>
            <ProductID>P-9052V-10.0.2</ProductID>
            <ProductID>P-9052V-10.1.0</ProductID>
            <ProductID>P-9052V-10.2.0</ProductID>
            <ProductID>P-9052V-10.2.2</ProductID>
            <ProductID>P-9052V-10.3.0</ProductID>
            <ProductID>P-9052V-10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.4.0</ProductID>
            <ProductID>P-9052V-12.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-9052V-10.0.0</ProductID>
            <ProductID>P-9052V-10.0.2</ProductID>
            <ProductID>P-9052V-10.1.0</ProductID>
            <ProductID>P-9052V-10.2.0</ProductID>
            <ProductID>P-9052V-10.2.2</ProductID>
            <ProductID>P-9052V-10.3.0</ProductID>
            <ProductID>P-9052V-10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.4.0</ProductID>
            <ProductID>P-9052V-12.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="98" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3227</Title>
      <Notes>
         <Note Type="Details" Ordinal="98" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Software (subcomponent: BASE).  Supported versions that are affected are 10.0.0, 10.0.2, 10.1.0, 10.2.0, 10.2.2, 10.3.0, 10.5.0 and  11.0.0 - 11.2.0. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle FLEXCUBE Universal Banking accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3227</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9052V-10.0.0</ProductID>
            <ProductID>P-9052V-10.0.2</ProductID>
            <ProductID>P-9052V-10.1.0</ProductID>
            <ProductID>P-9052V-10.2.0</ProductID>
            <ProductID>P-9052V-10.2.2</ProductID>
            <ProductID>P-9052V-10.3.0</ProductID>
            <ProductID>P-9052V-10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-9052V-10.0.0</ProductID>
            <ProductID>P-9052V-10.0.2</ProductID>
            <ProductID>P-9052V-10.1.0</ProductID>
            <ProductID>P-9052V-10.2.0</ProductID>
            <ProductID>P-9052V-10.2.2</ProductID>
            <ProductID>P-9052V-10.3.0</ProductID>
            <ProductID>P-9052V-10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="99" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3228</Title>
      <Notes>
         <Note Type="Details" Ordinal="99" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Software (subcomponent: BASE).  Supported versions that are affected are 5.0.2, 5.0.5, 5.1.0, 5.2.0, 5.3.0 - 5.3.4, 6.0.1 and  6.2.0. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle FLEXCUBE Direct Banking accessible data and ability to cause a partial denial of service (partial DOS) of Oracle FLEXCUBE Direct Banking.  CVSS Base Score 4.9 (Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:P).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3228</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9111V-5.0.2</ProductID>
            <ProductID>P-9111V-5.0.5</ProductID>
            <ProductID>P-9111V-5.1.0</ProductID>
            <ProductID>P-9111V-5.2.0</ProductID>
            <ProductID>P-9111V-5.3.0 - 5.3.4</ProductID>
            <ProductID>P-9111V-6.0.1</ProductID>
            <ProductID>P-9111V-6.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.9</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-9111V-5.0.2</ProductID>
            <ProductID>P-9111V-5.0.5</ProductID>
            <ProductID>P-9111V-5.1.0</ProductID>
            <ProductID>P-9111V-5.2.0</ProductID>
            <ProductID>P-9111V-5.3.0 - 5.3.4</ProductID>
            <ProductID>P-9111V-6.0.1</ProductID>
            <ProductID>P-9111V-6.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="100" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3229</Title>
      <Notes>
         <Note Type="Details" Ordinal="100" Title="Details" Audience="All">Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: Siebel Documentation).   The supported version that is affected is 8.1.1. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Siebel UI Framework accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3229</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8962V-8.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8962V-8.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="101" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3230</Title>
      <Notes>
         <Note Type="Details" Ordinal="101" Title="Details" Audience="All">Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: Portal Framework).   The supported version that is affected is 8.1.1. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Siebel UI Framework accessible data.  CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3230</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9011V-8.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-9011V-8.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="102" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5058</Title>
      <Notes>
         <Note Type="Details" Ordinal="102" Title="Details" Audience="All">Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: Web interface).  Supported versions that are affected are 11.5.10.2, 12.0.6, 12.1.1, 12.1.2 and 12.1.3. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle iStore accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5058</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-384V-11.5.10.2</ProductID>
            <ProductID>P-384V-12.0.6</ProductID>
            <ProductID>P-384V-12.1.1</ProductID>
            <ProductID>P-384V-12.1.2</ProductID>
            <ProductID>P-384V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-384V-11.5.10.2</ProductID>
            <ProductID>P-384V-12.0.6</ProductID>
            <ProductID>P-384V-12.1.1</ProductID>
            <ProductID>P-384V-12.1.2</ProductID>
            <ProductID>P-384V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="103" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5061</Title>
      <Notes>
         <Note Type="Details" Ordinal="103" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Software (subcomponent: BASE).  Supported versions that are affected are 10.0.0, 10.0.2, 10.1.0, 10.2.0, 10.2.2, 10.3.0, 10.5.0, 11.0.0 - 11.4.0 and  12.0.0. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle FLEXCUBE Universal Banking accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5061</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9052V-10.0.0</ProductID>
            <ProductID>P-9052V-10.0.2</ProductID>
            <ProductID>P-9052V-10.1.0</ProductID>
            <ProductID>P-9052V-10.2.0</ProductID>
            <ProductID>P-9052V-10.2.2</ProductID>
            <ProductID>P-9052V-10.3.0</ProductID>
            <ProductID>P-9052V-10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.4.0</ProductID>
            <ProductID>P-9052V-12.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-9052V-10.0.0</ProductID>
            <ProductID>P-9052V-10.0.2</ProductID>
            <ProductID>P-9052V-10.1.0</ProductID>
            <ProductID>P-9052V-10.2.0</ProductID>
            <ProductID>P-9052V-10.2.2</ProductID>
            <ProductID>P-9052V-10.3.0</ProductID>
            <ProductID>P-9052V-10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.4.0</ProductID>
            <ProductID>P-9052V-12.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="104" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5063</Title>
      <Notes>
         <Note Type="Details" Ordinal="104" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Software (subcomponent: BASE).  Supported versions that are affected are 10.0.0, 10.0.2, 10.1.0, 10.2.0, 10.2.2, 10.3.0, 10.5.0, 11.0.0 - 11.4.0 and  12.0.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle FLEXCUBE Universal Banking accessible data.  CVSS Base Score 5.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5063</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9052V-10.0.0</ProductID>
            <ProductID>P-9052V-10.0.2</ProductID>
            <ProductID>P-9052V-10.1.0</ProductID>
            <ProductID>P-9052V-10.2.0</ProductID>
            <ProductID>P-9052V-10.2.2</ProductID>
            <ProductID>P-9052V-10.3.0</ProductID>
            <ProductID>P-9052V-10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.4.0</ProductID>
            <ProductID>P-9052V-12.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-9052V-10.0.0</ProductID>
            <ProductID>P-9052V-10.0.2</ProductID>
            <ProductID>P-9052V-10.1.0</ProductID>
            <ProductID>P-9052V-10.2.0</ProductID>
            <ProductID>P-9052V-10.2.2</ProductID>
            <ProductID>P-9052V-10.3.0</ProductID>
            <ProductID>P-9052V-10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.4.0</ProductID>
            <ProductID>P-9052V-12.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="105" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5064</Title>
      <Notes>
         <Note Type="Details" Ordinal="105" Title="Details" Audience="All">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Software (subcomponent: BASE).  Supported versions that are affected are 10.0.0, 10.0.2, 10.1.0, 10.2.0, 10.2.2, 10.3.0, 10.5.0 and  11.0.0 - 11.2.0. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle FLEXCUBE Universal Banking accessible data.  CVSS Base Score 3.5 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5064</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9052V-10.0.0</ProductID>
            <ProductID>P-9052V-10.0.2</ProductID>
            <ProductID>P-9052V-10.1.0</ProductID>
            <ProductID>P-9052V-10.2.0</ProductID>
            <ProductID>P-9052V-10.2.2</ProductID>
            <ProductID>P-9052V-10.3.0</ProductID>
            <ProductID>P-9052V-10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-9052V-10.0.0</ProductID>
            <ProductID>P-9052V-10.0.2</ProductID>
            <ProductID>P-9052V-10.1.0</ProductID>
            <ProductID>P-9052V-10.2.0</ProductID>
            <ProductID>P-9052V-10.2.2</ProductID>
            <ProductID>P-9052V-10.3.0</ProductID>
            <ProductID>P-9052V-10.5.0</ProductID>
            <ProductID>P-9052V-11.0.0 - 11.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="106" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5065</Title>
      <Notes>
         <Note Type="Details" Ordinal="106" Title="Details" Audience="All">Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: ImagePicker).  Supported versions that are affected are 6.1, 6.2, 6.3.x, 7, 7.0.1, 7.0.2, 7.0.3, 7.5, 7.6.1, 7.6.2 and 11.1.1.6.0. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle WebCenter Sites accessible data.  CVSS Base Score 2.1 (Integrity impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5065</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9617V-6.1</ProductID>
            <ProductID>P-9617V-6.2</ProductID>
            <ProductID>P-9617V-6.3.x</ProductID>
            <ProductID>P-9617V-7</ProductID>
            <ProductID>P-9617V-7.0.1</ProductID>
            <ProductID>P-9617V-7.0.2</ProductID>
            <ProductID>P-9617V-7.0.3</ProductID>
            <ProductID>P-9617V-7.5</ProductID>
            <ProductID>P-9617V-7.6.1</ProductID>
            <ProductID>P-9617V-7.6.2</ProductID>
            <ProductID>P-9617V-11.1.1.6.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-9617V-6.1</ProductID>
            <ProductID>P-9617V-6.2</ProductID>
            <ProductID>P-9617V-6.3.x</ProductID>
            <ProductID>P-9617V-7</ProductID>
            <ProductID>P-9617V-7.0.1</ProductID>
            <ProductID>P-9617V-7.0.2</ProductID>
            <ProductID>P-9617V-7.0.3</ProductID>
            <ProductID>P-9617V-7.5</ProductID>
            <ProductID>P-9617V-7.6.1</ProductID>
            <ProductID>P-9617V-7.6.2</ProductID>
            <ProductID>P-9617V-11.1.1.6.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="107" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5066</Title>
      <Notes>
         <Note Type="Details" Ordinal="107" Title="Details" Audience="All">Vulnerability in the Oracle Central Designer component of Oracle Industry Applications.  Supported versions that are affected are 1.3, 1.4 and  1.4.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Central Designer accessible data as well as  read access to all Oracle Central Designer accessible data and ability to cause a partial denial of service (partial DOS) of Oracle Central Designer.  CVSS Base Score 6.8 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:P+/I:P+/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5066</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9132V-1.3</ProductID>
            <ProductID>P-9132V-1.4</ProductID>
            <ProductID>P-9132V-1.4.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-9132V-1.3</ProductID>
            <ProductID>P-9132V-1.4</ProductID>
            <ProductID>P-9132V-1.4.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="108" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5090</Title>
      <Notes>
         <Note Type="Details" Ordinal="108" Title="Details" Audience="All">Vulnerability in the Oracle Agile PLM for Process component of Oracle Supply Chain Products Suite (subcomponent: Document Reference Library).  Supported versions that are affected are 5.2.2 and  6.1.0.0. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Agile PLM for Process accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5090</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4445V-5.2.2</ProductID>
            <ProductID>P-4445V-6.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-4445V-5.2.2</ProductID>
            <ProductID>P-4445V-6.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="109" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5091</Title>
      <Notes>
         <Note Type="Details" Ordinal="109" Title="Details" Audience="All">Vulnerability in the Oracle Agile Product Supplier Collaboration for Process component of Oracle Supply Chain Products Suite (subcomponent: Supplier Portal).  Supported versions that are affected are 5.2.2 and  6.1.0.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Agile Product Supplier Collaboration for Process accessible data.  CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5091</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4447V-5.2.2</ProductID>
            <ProductID>P-4447V-6.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-4447V-5.2.2</ProductID>
            <ProductID>P-4447V-6.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="110" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5092</Title>
      <Notes>
         <Note Type="Details" Ordinal="110" Title="Details" Audience="All">Vulnerability in the Oracle Agile PLM for Process component of Oracle Supply Chain Products Suite (subcomponent: Supply Chain Relationship Mgmt).  Supported versions that are affected are 5.2.2 and  6.1.0.0. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Agile PLM for Process accessible data as well as  read access to a subset of Oracle Agile PLM for Process accessible data.  CVSS Base Score 5.5 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5092</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4445V-5.2.2</ProductID>
            <ProductID>P-4445V-6.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-4445V-5.2.2</ProductID>
            <ProductID>P-4445V-6.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="111" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5093</Title>
      <Notes>
         <Note Type="Details" Ordinal="111" Title="Details" Audience="All">Vulnerability in the Oracle Agile PLM for Process component of Oracle Supply Chain Products Suite (subcomponent: Global Spec Management).  Supported versions that are affected are 5.2.2 and  6.1.0.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Agile PLM for Process accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5093</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4445V-5.2.2</ProductID>
            <ProductID>P-4445V-6.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-4445V-5.2.2</ProductID>
            <ProductID>P-4445V-6.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="112" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5094</Title>
      <Notes>
         <Note Type="Details" Ordinal="112" Title="Details" Audience="All">Vulnerability in the Oracle Agile PLM for Process component of Oracle Supply Chain Products Suite (subcomponent: User Group Management).  Supported versions that are affected are 5.2.2 and  6.1.0.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Agile PLM for Process accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5094</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4445V-5.2.2</ProductID>
            <ProductID>P-4445V-6.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-4445V-5.2.2</ProductID>
            <ProductID>P-4445V-6.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="113" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5095</Title>
      <Notes>
         <Note Type="Details" Ordinal="113" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: inetd(1M)).   The supported version that is affected is 10. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Solaris accessible data as well as  read access to a subset of Solaris accessible data and ability to cause a partial denial of service (partial DOS) of Solaris.  CVSS Base Score 4.4 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:L/AC:M/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5095</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.4</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</URL>
            <ProductID>P-8752V-10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
</cvrf:cvrfdoc>
