<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet type="text/xsl" href="http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/1687073.xsl"?>
<?xml-stylesheet type="text/css" href="http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/1686935.css"?>
<cvrf:cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
   <DocumentTitle xml:lang="en">Oracle Critical Patch Update Advisory - January 2015 - Beta Oracle CVRF</DocumentTitle>
   <DocumentType xml:lang="en">Oracle Critical Patch Update Advisory</DocumentType>
   <DocumentPublisher Type="Vendor"/>
   <DocumentTracking>
      <Identification>
         <ID>CPUJan2015</ID>
      </Identification>
      <Status>Final</Status>
      <Version>1.0</Version>
      <RevisionHistory>
         <Revision>
            <Number>1.0</Number>
            <Date>2015-01-20T13:00:00-07:00</Date>
            <Description>Initial Distribution</Description>
         </Revision>
      </RevisionHistory>
      <InitialReleaseDate>2015-01-20T13:00:00-07:00</InitialReleaseDate>
      <CurrentReleaseDate>2015-01-20T13:00:00-07:00</CurrentReleaseDate>
   </DocumentTracking>
   <DocumentNotes>
      <Note Audience="All" Ordinal="1" Title="Summary" Type="Summary" xml:lang="en">This document contains descriptions of Oracle product security vulnerabilities which have had fixes released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including fix distribution information can be found at the Oracle sites referenced in this document.</Note>
   </DocumentNotes>
   <DocumentDistribution>This document is published at: http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/2367957.xml</DocumentDistribution>
   <DocumentReferences>
      <Reference Type="External">
         <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
         <Description>URL to html version of Advisory</Description>
      </Reference>
   </DocumentReferences>
   <Acknowledgments>
      <Acknowledgment>
         <Name>Abdullah Erdem</Name>
         <Organization>Abdullah Erdem</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Adam Willard</Name>
         <Organization>Foreground Security</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Advanced Threat Research Team, Intel Security</Name>
         <Organization>Intel</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Alexander Chizhov</Name>
         <Organization>Alexander Chizhov</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Alexander Kornbrust</Name>
         <Organization>Red Database Security</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Alexey Makhmutov</Name>
         <Organization>Wouter Coekaerts</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Amir Sohail</Name>
         <Organization>Amir Sohail</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Arjun V</Name>
         <Organization>Arjun V</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Avik Sarkar</Name>
         <Organization>Avik Sarkar</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ayoub Nait Lamine</Name>
         <Organization>Ayoub Nait Lamine</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Bart Kulach</Name>
         <Organization>NN Group N.V.</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ben Khlifa Fahmi</Name>
         <Organization>Ben Khlifa Fahmi</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Bruce Robb</Name>
         <Organization>J&amp;B Computing Services</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Cameron Crowley</Name>
         <Organization>Cameron Crowley</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Christian Galeone</Name>
         <Organization>Christian Galeone</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>David Litchfield</Name>
         <Organization>Datacom TSS</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Diego Matos</Name>
         <Organization>CIPHER Intelligence Lab</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Edmund Goh</Name>
         <Organization>KPMG Management Consulting, Singapore</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Edward Torkington</Name>
         <Organization>NCC Group</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Frank Cozijnsen</Name>
         <Organization>KPN</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Gabor Pesti</Name>
         <Organization>Gabor Pesti</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Gaurav Mishra</Name>
         <Organization>Gaurav Mishra</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>George Nosenko</Name>
         <Organization>Digital Security Research Group</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Gopal Bisht</Name>
         <Organization>Gopal Bisht</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Gurjant Singh Sadhra</Name>
         <Organization>Gurjant Singh Sadhra</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Joeri de Ruiter</Name>
         <Organization>Radboud University Nijmegen</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>John Munoz</Name>
         <Organization>Google</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Karthik E C</Name>
         <Organization>Karthik E C</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Karthikeyan Bhargavan</Name>
         <Organization>Karthikeyan Bhargavan</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Khai Tran</Name>
         <Organization>Netspi</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Khalifa Al Shamsi</Name>
         <Organization>Help AG</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Koutrouss Naddara on gmail</Name>
         <Organization>Koutrouss Naddara on gmail</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>M.Asim Shahzad</Name>
         <Organization>M.Asim Shahzad</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Mohammed Osman</Name>
         <Organization>Mohammed Osman</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Monendra Sahu</Name>
         <Organization>Monendra Sahu</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Mousab Elhag</Name>
         <Organization>Mousab Elhag</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Muhammad Sarmad Shafiq</Name>
         <Organization>Muhammad Sarmad Shafiq</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Oliver Gruskovnjak</Name>
         <Organization>Portcullis Inc</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Rakesh Singh</Name>
         <Organization>Zero Day Guys</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Sandeep Venkatesan</Name>
         <Organization>Sandeep Venkatesan</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Sky_BlaCk</Name>
         <Organization>Sky_BlaCk</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Sreehari</Name>
         <Organization>Sreehari</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Srikanth Y</Name>
         <Organization>Srikanth Y</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Tomas Hoger</Name>
         <Organization>Red Hat</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Tor Erling Bjorstad</Name>
         <Organization>Tor Erling Bjorstad</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Tudor Enache</Name>
         <Organization>Help AG</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Vivek Singh</Name>
         <Organization>FINRA</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Wouter Coekaerts</Name>
         <Organization>Wouter Coekaerts</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Yann CAM</Name>
         <Organization>Yann CAM</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Yasumasa Suenaga</Name>
         <Organization>Yasumasa Suenaga</Organization>
      </Acknowledgment>
   </Acknowledgments>
   <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
      <Branch Name="Oracle" Type="Vendor">
         <Branch Name="Oracle Communications Applications" Type="Product Family">
            <Branch Name="Communications Messaging Server" Type="Product Name">
               <Branch Name="7.0.5.33.0 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8496V-7.0.5.33.0 and earlier">Communications Messaging Server Version 7.0.5.33.0 and earlier</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Diameter Signaling Router (DSR)" Type="Product Name">
               <Branch Name="3.x" Type="Product Version">
                  <FullProductName ProductID="P-10899V-3.x">Communications Diameter Signaling Router (DSR) Version 3.x</FullProductName>
               </Branch>
               <Branch Name="4.x" Type="Product Version">
                  <FullProductName ProductID="P-10899V-4.x">Communications Diameter Signaling Router (DSR) Version 4.x</FullProductName>
               </Branch>
               <Branch Name="5.0" Type="Product Version">
                  <FullProductName ProductID="P-10899V-5.0">Communications Diameter Signaling Router (DSR) Version 5.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Database Server" Type="Product Family">
            <Branch Name="Oracle Database" Type="Product Name">
               <Branch Name="11.1.0.7" Type="Product Version">
                  <FullProductName ProductID="P-5V-11.1.0.7">Oracle Database Version 11.1.0.7</FullProductName>
               </Branch>
               <Branch Name="11.2.0.3" Type="Product Version">
                  <FullProductName ProductID="P-5V-11.2.0.3">Oracle Database Version 11.2.0.3</FullProductName>
               </Branch>
               <Branch Name="11.2.0.4" Type="Product Version">
                  <FullProductName ProductID="P-5V-11.2.0.4">Oracle Database Version 11.2.0.4</FullProductName>
               </Branch>
               <Branch Name="12.1.0.1" Type="Product Version">
                  <FullProductName ProductID="P-5V-12.1.0.1">Oracle Database Version 12.1.0.1</FullProductName>
               </Branch>
               <Branch Name="12.1.0.2" Type="Product Version">
                  <FullProductName ProductID="P-5V-12.1.0.2">Oracle Database Version 12.1.0.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="PL/SQL" Type="Product Name">
               <Branch Name="11.1.0.7" Type="Product Version">
                  <FullProductName ProductID="P-11V-11.1.0.7">PL/SQL Version 11.1.0.7</FullProductName>
               </Branch>
               <Branch Name="11.2.0.3" Type="Product Version">
                  <FullProductName ProductID="P-11V-11.2.0.3">PL/SQL Version 11.2.0.3</FullProductName>
               </Branch>
               <Branch Name="11.2.0.4" Type="Product Version">
                  <FullProductName ProductID="P-11V-11.2.0.4">PL/SQL Version 11.2.0.4</FullProductName>
               </Branch>
               <Branch Name="12.1.0.1" Type="Product Version">
                  <FullProductName ProductID="P-11V-12.1.0.1">PL/SQL Version 12.1.0.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="XML Developers Kit" Type="Product Name">
               <Branch Name="11.2.0.3" Type="Product Version">
                  <FullProductName ProductID="P-1068V-11.2.0.3">XML Developers Kit Version 11.2.0.3</FullProductName>
               </Branch>
               <Branch Name="11.2.0.4" Type="Product Version">
                  <FullProductName ProductID="P-1068V-11.2.0.4">XML Developers Kit Version 11.2.0.4</FullProductName>
               </Branch>
               <Branch Name="12.1.0.1" Type="Product Version">
                  <FullProductName ProductID="P-1068V-12.1.0.1">XML Developers Kit Version 12.1.0.1</FullProductName>
               </Branch>
               <Branch Name="12.1.0.2" Type="Product Version">
                  <FullProductName ProductID="P-1068V-12.1.0.2">XML Developers Kit Version 12.1.0.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Workspace Manager" Type="Product Name">
               <Branch Name="11.1.0.7" Type="Product Version">
                  <FullProductName ProductID="P-1105V-11.1.0.7">Workspace Manager Version 11.1.0.7</FullProductName>
               </Branch>
               <Branch Name="11.2.0.3" Type="Product Version">
                  <FullProductName ProductID="P-1105V-11.2.0.3">Workspace Manager Version 11.2.0.3</FullProductName>
               </Branch>
               <Branch Name="11.2.0.4" Type="Product Version">
                  <FullProductName ProductID="P-1105V-11.2.0.4">Workspace Manager Version 11.2.0.4</FullProductName>
               </Branch>
               <Branch Name="12.1.0.1" Type="Product Version">
                  <FullProductName ProductID="P-1105V-12.1.0.1">Workspace Manager Version 12.1.0.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="OLAP" Type="Product Name">
               <Branch Name="11.1.0.7" Type="Product Version">
                  <FullProductName ProductID="P-1163V-11.1.0.7">OLAP Version 11.1.0.7</FullProductName>
               </Branch>
               <Branch Name="11.2.0.3" Type="Product Version">
                  <FullProductName ProductID="P-1163V-11.2.0.3">OLAP Version 11.2.0.3</FullProductName>
               </Branch>
               <Branch Name="11.2.0.4" Type="Product Version">
                  <FullProductName ProductID="P-1163V-11.2.0.4">OLAP Version 11.2.0.4</FullProductName>
               </Branch>
               <Branch Name="12.1.0.1" Type="Product Version">
                  <FullProductName ProductID="P-1163V-12.1.0.1">OLAP Version 12.1.0.1</FullProductName>
               </Branch>
               <Branch Name="12.1.0.2" Type="Product Version">
                  <FullProductName ProductID="P-1163V-12.1.0.2">OLAP Version 12.1.0.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle E-Business Suite" Type="Product Family">
            <Branch Name="Applications DBA" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-166V-11.5.10.2">Applications DBA Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Name="12.0.6" Type="Product Version">
                  <FullProductName ProductID="P-166V-12.0.6">Applications DBA Version 12.0.6</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-166V-12.1.3">Applications DBA Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.2" Type="Product Version">
                  <FullProductName ProductID="P-166V-12.2.2">Applications DBA Version 12.2.2</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-166V-12.2.3">Applications DBA Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-166V-12.2.4">Applications DBA Version 12.2.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Marketing" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-229V-11.5.10.2">Marketing Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Name="12.0.4" Type="Product Version">
                  <FullProductName ProductID="P-229V-12.0.4">Marketing Version 12.0.4</FullProductName>
               </Branch>
               <Branch Name="12.0.5" Type="Product Version">
                  <FullProductName ProductID="P-229V-12.0.5">Marketing Version 12.0.5</FullProductName>
               </Branch>
               <Branch Name="12.0.6" Type="Product Version">
                  <FullProductName ProductID="P-229V-12.0.6">Marketing Version 12.0.6</FullProductName>
               </Branch>
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-229V-12.1.1">Marketing Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-229V-12.1.2">Marketing Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3." Type="Product Version">
                  <FullProductName ProductID="P-229V-12.1.3.">Marketing Version 12.1.3.</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Customer Intelligence" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-390V-11.5.10.2">Customer Intelligence Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Name="12.0.4" Type="Product Version">
                  <FullProductName ProductID="P-390V-12.0.4">Customer Intelligence Version 12.0.4</FullProductName>
               </Branch>
               <Branch Name="12.0.5" Type="Product Version">
                  <FullProductName ProductID="P-390V-12.0.5">Customer Intelligence Version 12.0.5</FullProductName>
               </Branch>
               <Branch Name="12.0.6" Type="Product Version">
                  <FullProductName ProductID="P-390V-12.0.6">Customer Intelligence Version 12.0.6</FullProductName>
               </Branch>
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-390V-12.1.1">Customer Intelligence Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-390V-12.1.2">Customer Intelligence Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-390V-12.1.3">Customer Intelligence Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.2" Type="Product Version">
                  <FullProductName ProductID="P-390V-12.2.2">Customer Intelligence Version 12.2.2</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-390V-12.2.3">Customer Intelligence Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-390V-12.2.4">Customer Intelligence Version 12.2.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Application Object Library" Type="Product Name">
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-510V-12.1.3">Application Object Library Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Web Applications Desktop Integrator" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-1171V-11.5.10.2">Web Applications Desktop Integrator Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Name="12.0.6" Type="Product Version">
                  <FullProductName ProductID="P-1171V-12.0.6">Web Applications Desktop Integrator Version 12.0.6</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1171V-12.1.3">Web Applications Desktop Integrator Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.2" Type="Product Version">
                  <FullProductName ProductID="P-1171V-12.2.2">Web Applications Desktop Integrator Version 12.2.2</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-1171V-12.2.3">Web Applications Desktop Integrator Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-1171V-12.2.4">Web Applications Desktop Integrator Version 12.2.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Telecommunications Billing Integrator" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-1300V-11.5.10.2">Telecommunications Billing Integrator Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Name="12.0.4" Type="Product Version">
                  <FullProductName ProductID="P-1300V-12.0.4">Telecommunications Billing Integrator Version 12.0.4</FullProductName>
               </Branch>
               <Branch Name="12.0.5" Type="Product Version">
                  <FullProductName ProductID="P-1300V-12.0.5">Telecommunications Billing Integrator Version 12.0.5</FullProductName>
               </Branch>
               <Branch Name="12.0.6" Type="Product Version">
                  <FullProductName ProductID="P-1300V-12.0.6">Telecommunications Billing Integrator Version 12.0.6</FullProductName>
               </Branch>
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-1300V-12.1.1">Telecommunications Billing Integrator Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-1300V-12.1.2">Telecommunications Billing Integrator Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1300V-12.1.3">Telecommunications Billing Integrator Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.2" Type="Product Version">
                  <FullProductName ProductID="P-1300V-12.2.2">Telecommunications Billing Integrator Version 12.2.2</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-1300V-12.2.3">Telecommunications Billing Integrator Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-1300V-12.2.4">Telecommunications Billing Integrator Version 12.2.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Customer Interaction History" Type="Product Name">
               <Branch Name="12.0.4" Type="Product Version">
                  <FullProductName ProductID="P-1374V-12.0.4">Customer Interaction History Version 12.0.4</FullProductName>
               </Branch>
               <Branch Name="12.0.5" Type="Product Version">
                  <FullProductName ProductID="P-1374V-12.0.5">Customer Interaction History Version 12.0.5</FullProductName>
               </Branch>
               <Branch Name="12.0.6" Type="Product Version">
                  <FullProductName ProductID="P-1374V-12.0.6">Customer Interaction History Version 12.0.6</FullProductName>
               </Branch>
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-1374V-12.1.1">Customer Interaction History Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-1374V-12.1.2">Customer Interaction History Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1374V-12.1.3">Customer Interaction History Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.2" Type="Product Version">
                  <FullProductName ProductID="P-1374V-12.2.2">Customer Interaction History Version 12.2.2</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-1374V-12.2.3">Customer Interaction History Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-1374V-12.2.4">Customer Interaction History Version 12.2.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Applications Framework" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-1472V-11.5.10.2">Applications Framework Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Name="12.0.6" Type="Product Version">
                  <FullProductName ProductID="P-1472V-12.0.6">Applications Framework Version 12.0.6</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1472V-12.1.3">Applications Framework Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.2" Type="Product Version">
                  <FullProductName ProductID="P-1472V-12.2.2">Applications Framework Version 12.2.2</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-1472V-12.2.3">Applications Framework Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-1472V-12.2.4">Applications Framework Version 12.2.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="HCM Configuration Workbench" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-2011V-11.5.10.2">HCM Configuration Workbench Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Name="12.0.4" Type="Product Version">
                  <FullProductName ProductID="P-2011V-12.0.4">HCM Configuration Workbench Version 12.0.4</FullProductName>
               </Branch>
               <Branch Name="12.0.5" Type="Product Version">
                  <FullProductName ProductID="P-2011V-12.0.5">HCM Configuration Workbench Version 12.0.5</FullProductName>
               </Branch>
               <Branch Name="12.0.6" Type="Product Version">
                  <FullProductName ProductID="P-2011V-12.0.6">HCM Configuration Workbench Version 12.0.6</FullProductName>
               </Branch>
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-2011V-12.1.1">HCM Configuration Workbench Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-2011V-12.1.2">HCM Configuration Workbench Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-2011V-12.1.3">HCM Configuration Workbench Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.2" Type="Product Version">
                  <FullProductName ProductID="P-2011V-12.2.2">HCM Configuration Workbench Version 12.2.2</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-2011V-12.2.3">HCM Configuration Workbench Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-2011V-12.2.4">HCM Configuration Workbench Version 12.2.4</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Enterprise Manager Grid Control" Type="Product Family">
            <Branch Name="Enterprise Manager Base Platform" Type="Product Name">
               <Branch Name="12.1.0.3" Type="Product Version">
                  <FullProductName ProductID="P-1370V-12.1.0.3">Enterprise Manager Base Platform Version 12.1.0.3</FullProductName>
               </Branch>
               <Branch Name="12.1.0.4" Type="Product Version">
                  <FullProductName ProductID="P-1370V-12.1.0.4">Enterprise Manager Base Platform Version 12.1.0.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Enterprise Manager Ops Center" Type="Product Name">
               <Branch Name="11.1" Type="Product Version">
                  <FullProductName ProductID="P-9835V-11.1">Enterprise Manager Ops Center Version 11.1</FullProductName>
               </Branch>
               <Branch Name="11.1.3" Type="Product Version">
                  <FullProductName ProductID="P-9835V-11.1.3">Enterprise Manager Ops Center Version 11.1.3</FullProductName>
               </Branch>
               <Branch Name="12.1" Type="Product Version">
                  <FullProductName ProductID="P-9835V-12.1">Enterprise Manager Ops Center Version 12.1</FullProductName>
               </Branch>
               <Branch Name="12.1.4" Type="Product Version">
                  <FullProductName ProductID="P-9835V-12.1.4">Enterprise Manager Ops Center Version 12.1.4</FullProductName>
               </Branch>
               <Branch Name="12.2" Type="Product Version">
                  <FullProductName ProductID="P-9835V-12.2">Enterprise Manager Ops Center Version 12.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Fusion Middleware" Type="Product Family">
            <Branch Name="Forms" Type="Product Name">
               <Branch Name="11.1.1.7" Type="Product Version">
                  <FullProductName ProductID="P-45V-11.1.1.7">Forms Version 11.1.1.7</FullProductName>
               </Branch>
               <Branch Name="11.1.2.2" Type="Product Version">
                  <FullProductName ProductID="P-45V-11.1.2.2">Forms Version 11.1.2.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Reports Developer" Type="Product Name">
               <Branch Name="11.1.1.7" Type="Product Version">
                  <FullProductName ProductID="P-159V-11.1.1.7">Reports Developer Version 11.1.1.7</FullProductName>
               </Branch>
               <Branch Name="11.1.2.2" Type="Product Version">
                  <FullProductName ProductID="P-159V-11.1.2.2">Reports Developer Version 11.1.2.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Security Service" Type="Product Name">
               <Branch Name="FMW: 12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-991V-FMW: 12.1.3">Security Service Version FMW: 12.1.3</FullProductName>
               </Branch>
               <Branch Name="OHS: 12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-991V-OHS: 12.1.2">Security Service Version OHS: 12.1.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="HTTP Server" Type="Product Name">
               <Branch Name="10.1.3.5.0" Type="Product Version">
                  <FullProductName ProductID="P-1042V-10.1.3.5.0">HTTP Server Version 10.1.3.5.0</FullProductName>
               </Branch>
               <Branch Name="11.1.1.7.0" Type="Product Version">
                  <FullProductName ProductID="P-1042V-11.1.1.7.0">HTTP Server Version 11.1.1.7.0</FullProductName>
               </Branch>
               <Branch Name="12.1.2.0" Type="Product Version">
                  <FullProductName ProductID="P-1042V-12.1.2.0">HTTP Server Version 12.1.2.0</FullProductName>
               </Branch>
               <Branch Name="12.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1042V-12.1.3.0">HTTP Server Version 12.1.3.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="SOA Suite" Type="Product Name">
               <Branch Name="11.1.1.7" Type="Product Version">
                  <FullProductName ProductID="P-1162V-11.1.1.7">SOA Suite Version 11.1.1.7</FullProductName>
               </Branch>
               <Branch Name="12.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1162V-12.1.3.0">SOA Suite Version 12.1.3.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Containers for J2EE" Type="Product Name">
               <Branch Name="10.1.3.5" Type="Product Version">
                  <FullProductName ProductID="P-1270V-10.1.3.5">Containers for J2EE Version 10.1.3.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="BI Publisher (formerly XML Publisher)" Type="Product Name">
               <Branch Name="10.1.3.4.2" Type="Product Version">
                  <FullProductName ProductID="P-1479V-10.1.3.4.2">BI Publisher (formerly XML Publisher) Version 10.1.3.4.2</FullProductName>
               </Branch>
               <Branch Name="11.1.1.7" Type="Product Version">
                  <FullProductName ProductID="P-1479V-11.1.1.7">BI Publisher (formerly XML Publisher) Version 11.1.1.7</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Business Intelligence Enterprise Edition" Type="Product Name">
               <Branch Name="10.1.3.4.2" Type="Product Version">
                  <FullProductName ProductID="P-2025V-10.1.3.4.2">Business Intelligence Enterprise Edition Version 10.1.3.4.2</FullProductName>
               </Branch>
               <Branch Name="11.1.1.7" Type="Product Version">
                  <FullProductName ProductID="P-2025V-11.1.1.7">Business Intelligence Enterprise Edition Version 11.1.1.7</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Real-Time Decision Server" Type="Product Name">
               <Branch Name="11.1.1.7" Type="Product Version">
                  <FullProductName ProductID="P-2104V-11.1.1.7">Real-Time Decision Server Version 11.1.1.7</FullProductName>
               </Branch>
               <Branch Name="RTD Platform 3.0.x" Type="Product Version">
                  <FullProductName ProductID="P-2104V-RTD Platform 3.0.x">Real-Time Decision Server Version RTD Platform 3.0.x</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="WebCenter Content" Type="Product Name">
               <Branch Name="11.1.1.8.0" Type="Product Version">
                  <FullProductName ProductID="P-2271V-11.1.1.8.0">WebCenter Content Version 11.1.1.8.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Adaptive Access Manager" Type="Product Name">
               <Branch Name="11.1.1.5" Type="Product Version">
                  <FullProductName ProductID="P-4419V-11.1.1.5">Adaptive Access Manager Version 11.1.1.5</FullProductName>
               </Branch>
               <Branch Name="11.1.1.7" Type="Product Version">
                  <FullProductName ProductID="P-4419V-11.1.1.7">Adaptive Access Manager Version 11.1.1.7</FullProductName>
               </Branch>
               <Branch Name="11.1.2.1" Type="Product Version">
                  <FullProductName ProductID="P-4419V-11.1.2.1">Adaptive Access Manager Version 11.1.2.1</FullProductName>
               </Branch>
               <Branch Name="11.1.2.2" Type="Product Version">
                  <FullProductName ProductID="P-4419V-11.1.2.2">Adaptive Access Manager Version 11.1.2.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="WebLogic Server" Type="Product Name">
               <Branch Name="10.0.2.0" Type="Product Version">
                  <FullProductName ProductID="P-5242V-10.0.2.0">WebLogic Server Version 10.0.2.0</FullProductName>
               </Branch>
               <Branch Name="10.3.6.0" Type="Product Version">
                  <FullProductName ProductID="P-5242V-10.3.6.0">WebLogic Server Version 10.3.6.0</FullProductName>
               </Branch>
               <Branch Name="12.1.1.0" Type="Product Version">
                  <FullProductName ProductID="P-5242V-12.1.1.0">WebLogic Server Version 12.1.1.0</FullProductName>
               </Branch>
               <Branch Name="12.1.2.0" Type="Product Version">
                  <FullProductName ProductID="P-5242V-12.1.2.0">WebLogic Server Version 12.1.2.0</FullProductName>
               </Branch>
               <Branch Name="12.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-5242V-12.1.3.0">WebLogic Server Version 12.1.3.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="WebLogic Portal" Type="Product Name">
               <Branch Name="10.0.1.0" Type="Product Version">
                  <FullProductName ProductID="P-5307V-10.0.1.0">WebLogic Portal Version 10.0.1.0</FullProductName>
               </Branch>
               <Branch Name="10.2.1.0" Type="Product Version">
                  <FullProductName ProductID="P-5307V-10.2.1.0">WebLogic Portal Version 10.2.1.0</FullProductName>
               </Branch>
               <Branch Name="10.3.6.0" Type="Product Version">
                  <FullProductName ProductID="P-5307V-10.3.6.0">WebLogic Portal Version 10.3.6.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Access Manager" Type="Product Name">
               <Branch Name="11.1.1.5" Type="Product Version">
                  <FullProductName ProductID="P-5565V-11.1.1.5">Access Manager Version 11.1.1.5</FullProductName>
               </Branch>
               <Branch Name="11.1.1.7" Type="Product Version">
                  <FullProductName ProductID="P-5565V-11.1.1.7">Access Manager Version 11.1.1.7</FullProductName>
               </Branch>
               <Branch Name="11.1.2.1" Type="Product Version">
                  <FullProductName ProductID="P-5565V-11.1.2.1">Access Manager Version 11.1.2.1</FullProductName>
               </Branch>
               <Branch Name="11.1.2.2" Type="Product Version">
                  <FullProductName ProductID="P-5565V-11.1.2.2">Access Manager Version 11.1.2.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="GlassFish Server" Type="Product Name">
               <Branch Name="3.0.1" Type="Product Version">
                  <FullProductName ProductID="P-8493V-3.0.1">GlassFish Server Version 3.0.1</FullProductName>
               </Branch>
               <Branch Name="3.1.2" Type="Product Version">
                  <FullProductName ProductID="P-8493V-3.1.2">GlassFish Server Version 3.1.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Directory Server Enterprise Edition" Type="Product Name">
               <Branch Name="11.1.1.7" Type="Product Version">
                  <FullProductName ProductID="P-8512V-11.1.1.7">Directory Server Enterprise Edition Version 11.1.1.7</FullProductName>
               </Branch>
               <Branch Name="7.0" Type="Product Version">
                  <FullProductName ProductID="P-8512V-7.0">Directory Server Enterprise Edition Version 7.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Waveset" Type="Product Name">
               <Branch Name="8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-8518V-8.1.1">Waveset Version 8.1.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="OpenSSO" Type="Product Name">
               <Branch Name="8.0 Update 2 Patch 5" Type="Product Version">
                  <FullProductName ProductID="P-8520V-8.0 Update 2 Patch 5">OpenSSO Version 8.0 Update 2 Patch 5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Exalogic Infrastructure" Type="Product Name">
               <Branch Name="2.0.6.2.0 (for all X2-2" Type="Product Version">
                  <FullProductName ProductID="P-9415V-2.0.6.2.0 (for all X2-2">Exalogic Infrastructure Version 2.0.6.2.0 (for all X2-2</FullProductName>
               </Branch>
               <Branch Name="X3-2" Type="Product Version">
                  <FullProductName ProductID="P-9415V-X3-2">Exalogic Infrastructure Version X3-2</FullProductName>
               </Branch>
               <Branch Name="X4-2)" Type="Product Version">
                  <FullProductName ProductID="P-9415V-X4-2)">Exalogic Infrastructure Version X4-2)</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Health Sciences Applications" Type="Product Family">
            <Branch Name="Healthcare Master Person Index" Type="Product Name">
               <Branch Name="1.x" Type="Product Version">
                  <FullProductName ProductID="P-8575V-1.x">Healthcare Master Person Index Version 1.x</FullProductName>
               </Branch>
               <Branch Name="2.x" Type="Product Version">
                  <FullProductName ProductID="P-8575V-2.x">Healthcare Master Person Index Version 2.x</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle JD Edwards Products" Type="Product Family">
            <Branch Name="JD Edwards EnterpriseOne Tools" Type="Product Name">
               <Branch Name="9.1.5" Type="Product Version">
                  <FullProductName ProductID="P-4781V-9.1.5">JD Edwards EnterpriseOne Tools Version 9.1.5</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Java SE" Type="Product Family">
            <Branch Name="Java" Type="Product Name">
               <Branch Name="JRockit 27.8.4" Type="Product Version">
                  <FullProductName ProductID="P-856V-JRockit 27.8.4">Java Version JRockit 27.8.4</FullProductName>
               </Branch>
               <Branch Name="JRockit 28.3.4" Type="Product Version">
                  <FullProductName ProductID="P-856V-JRockit 28.3.4">Java Version JRockit 28.3.4</FullProductName>
               </Branch>
               <Branch Name="JRockit R27.8.4" Type="Product Version">
                  <FullProductName ProductID="P-856V-JRockit R27.8.4">Java Version JRockit R27.8.4</FullProductName>
               </Branch>
               <Branch Name="JRockit R28.3.4" Type="Product Version">
                  <FullProductName ProductID="P-856V-JRockit R28.3.4">Java Version JRockit R28.3.4</FullProductName>
               </Branch>
               <Branch Name="Java SE 5.0u75" Type="Product Version">
                  <FullProductName ProductID="P-856V-Java SE 5.0u75">Java Version Java SE 5.0u75</FullProductName>
               </Branch>
               <Branch Name="Java SE 6u85" Type="Product Version">
                  <FullProductName ProductID="P-856V-Java SE 6u85">Java Version Java SE 6u85</FullProductName>
               </Branch>
               <Branch Name="Java SE 7u72" Type="Product Version">
                  <FullProductName ProductID="P-856V-Java SE 7u72">Java Version Java SE 7u72</FullProductName>
               </Branch>
               <Branch Name="Java SE 8u25" Type="Product Version">
                  <FullProductName ProductID="P-856V-Java SE 8u25">Java Version Java SE 8u25</FullProductName>
               </Branch>
               <Branch Name="Java SE Embedded 7u71" Type="Product Version">
                  <FullProductName ProductID="P-856V-Java SE Embedded 7u71">Java Version Java SE Embedded 7u71</FullProductName>
               </Branch>
               <Branch Name="Java SE Embedded 8u6" Type="Product Version">
                  <FullProductName ProductID="P-856V-Java SE Embedded 8u6">Java Version Java SE Embedded 8u6</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle MySQL" Type="Product Family">
            <Branch Name="MySQL Server" Type="Product Name">
               <Branch Name="5.5.38 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.5.38 and earlier">MySQL Server Version 5.5.38 and earlier</FullProductName>
               </Branch>
               <Branch Name="5.5.40 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.5.40 and earlier">MySQL Server Version 5.5.40 and earlier</FullProductName>
               </Branch>
               <Branch Name="5.6.19 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.6.19 and earlier">MySQL Server Version 5.6.19 and earlier</FullProductName>
               </Branch>
               <Branch Name="5.6.21 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.6.21 and earlier">MySQL Server Version 5.6.21 and earlier</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle PeopleSoft Products" Type="Product Family">
            <Branch Name="PeopleSoft Enterprise HCM Time and Labor" Type="Product Name">
               <Branch Name="9.1" Type="Product Version">
                  <FullProductName ProductID="P-5079V-9.1">PeopleSoft Enterprise HCM Time and Labor Version 9.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="PeopleSoft Enterprise PT PeopleTools" Type="Product Name">
               <Branch Name="8.52" Type="Product Version">
                  <FullProductName ProductID="P-5085V-8.52">PeopleSoft Enterprise PT PeopleTools Version 8.52</FullProductName>
               </Branch>
               <Branch Name="8.53" Type="Product Version">
                  <FullProductName ProductID="P-5085V-8.53">PeopleSoft Enterprise PT PeopleTools Version 8.53</FullProductName>
               </Branch>
               <Branch Name="8.54" Type="Product Version">
                  <FullProductName ProductID="P-5085V-8.54">PeopleSoft Enterprise PT PeopleTools Version 8.54</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Retail Applications" Type="Product Family">
            <Branch Name="MICROS Retail" Type="Product Name">
               <Branch Name="3.4.2" Type="Product Version">
                  <FullProductName ProductID="P-11435V-3.4.2">MICROS Retail Version 3.4.2</FullProductName>
               </Branch>
               <Branch Name="3.5.0" Type="Product Version">
                  <FullProductName ProductID="P-11435V-3.5.0">MICROS Retail Version 3.5.0</FullProductName>
               </Branch>
               <Branch Name="4.0.1" Type="Product Version">
                  <FullProductName ProductID="P-11435V-4.0.1">MICROS Retail Version 4.0.1</FullProductName>
               </Branch>
               <Branch Name="4.5.1" Type="Product Version">
                  <FullProductName ProductID="P-11435V-4.5.1">MICROS Retail Version 4.5.1</FullProductName>
               </Branch>
               <Branch Name="4.8.0" Type="Product Version">
                  <FullProductName ProductID="P-11435V-4.8.0">MICROS Retail Version 4.8.0</FullProductName>
               </Branch>
               <Branch Name="5.0.3" Type="Product Version">
                  <FullProductName ProductID="P-11435V-5.0.3">MICROS Retail Version 5.0.3</FullProductName>
               </Branch>
               <Branch Name="5.5.3" Type="Product Version">
                  <FullProductName ProductID="P-11435V-5.5.3">MICROS Retail Version 5.5.3</FullProductName>
               </Branch>
               <Branch Name="6.0.6" Type="Product Version">
                  <FullProductName ProductID="P-11435V-6.0.6">MICROS Retail Version 6.0.6</FullProductName>
               </Branch>
               <Branch Name="6.5.2" Type="Product Version">
                  <FullProductName ProductID="P-11435V-6.5.2">MICROS Retail Version 6.5.2</FullProductName>
               </Branch>
               <Branch Name="Xstore: 3.2.1" Type="Product Version">
                  <FullProductName ProductID="P-11435V-Xstore: 3.2.1">MICROS Retail Version Xstore: 3.2.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Siebel CRM" Type="Product Family">
            <Branch Name="Siebel Core - Server BizLogic Script" Type="Product Name">
               <Branch Name="8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-9001V-8.1.1">Siebel Core - Server BizLogic Script Version 8.1.1</FullProductName>
               </Branch>
               <Branch Name="8.2.2" Type="Product Version">
                  <FullProductName ProductID="P-9001V-8.2.2">Siebel Core - Server BizLogic Script Version 8.2.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Siebel Core - Server Infrastructure" Type="Product Name">
               <Branch Name="8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-9004V-8.1.1">Siebel Core - Server Infrastructure Version 8.1.1</FullProductName>
               </Branch>
               <Branch Name="8.2.2" Type="Product Version">
                  <FullProductName ProductID="P-9004V-8.2.2">Siebel Core - Server Infrastructure Version 8.2.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Siebel Core - Server OM Svcs" Type="Product Name">
               <Branch Name="8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-9006V-8.1.1">Siebel Core - Server OM Svcs Version 8.1.1</FullProductName>
               </Branch>
               <Branch Name="8.2.2" Type="Product Version">
                  <FullProductName ProductID="P-9006V-8.2.2">Siebel Core - Server OM Svcs Version 8.2.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Siebel Core - System Management" Type="Product Name">
               <Branch Name="8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-9009V-8.1.1">Siebel Core - System Management Version 8.1.1</FullProductName>
               </Branch>
               <Branch Name="8.2.2" Type="Product Version">
                  <FullProductName ProductID="P-9009V-8.2.2">Siebel Core - System Management Version 8.2.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Siebel UI Framework" Type="Product Name">
               <Branch Name="8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-9011V-8.1.1">Siebel UI Framework Version 8.1.1</FullProductName>
               </Branch>
               <Branch Name="8.2.2" Type="Product Version">
                  <FullProductName ProductID="P-9011V-8.2.2">Siebel UI Framework Version 8.2.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Siebel Core - Unix/Windows" Type="Product Name">
               <Branch Name="8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-9016V-8.1.1">Siebel Core - Unix/Windows Version 8.1.1</FullProductName>
               </Branch>
               <Branch Name="8.2.2" Type="Product Version">
                  <FullProductName ProductID="P-9016V-8.2.2">Siebel Core - Unix/Windows Version 8.2.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Siebel Core - EAI" Type="Product Name">
               <Branch Name="8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-9021V-8.1.1">Siebel Core - EAI Version 8.1.1</FullProductName>
               </Branch>
               <Branch Name="8.2.2" Type="Product Version">
                  <FullProductName ProductID="P-9021V-8.2.2">Siebel Core - EAI Version 8.2.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Siebel Public Sector" Type="Product Name">
               <Branch Name="8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-9165V-8.1.1">Siebel Public Sector Version 8.1.1</FullProductName>
               </Branch>
               <Branch Name="8.2.2" Type="Product Version">
                  <FullProductName ProductID="P-9165V-8.2.2">Siebel Public Sector Version 8.2.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Siebel Life Sciences" Type="Product Name">
               <Branch Name="8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-9173V-8.1.1">Siebel Life Sciences Version 8.1.1</FullProductName>
               </Branch>
               <Branch Name="8.2.2" Type="Product Version">
                  <FullProductName ProductID="P-9173V-8.2.2">Siebel Life Sciences Version 8.2.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Siebel Core - Common Components" Type="Product Name">
               <Branch Name="8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-9747V-8.1.1">Siebel Core - Common Components Version 8.1.1</FullProductName>
               </Branch>
               <Branch Name="8.2.2" Type="Product Version">
                  <FullProductName ProductID="P-9747V-8.2.2">Siebel Core - Common Components Version 8.2.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Sun Systems Products Suite" Type="Product Family">
            <Branch Name="SPARC - OPL Service Processor (XCP)" Type="Product Name">
               <Branch Name="XCP prior to XCP 1118" Type="Product Version">
                  <FullProductName ProductID="P-9845V-XCP prior to XCP 1118">SPARC - OPL Service Processor (XCP) Version XCP prior to XCP 1118</FullProductName>
               </Branch>
               <Branch Name="XCP prior to XCP 1119" Type="Product Version">
                  <FullProductName ProductID="P-9845V-XCP prior to XCP 1119">SPARC - OPL Service Processor (XCP) Version XCP prior to XCP 1119</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="SSM - (hot-tamale) ILOM: Integrated Lights Out Manager" Type="Product Name">
               <Branch Name="ILOM prior to 3.2.4" Type="Product Version">
                  <FullProductName ProductID="P-9849V-ILOM prior to 3.2.4">SSM - (hot-tamale) ILOM: Integrated Lights Out Manager Version ILOM prior to 3.2.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Solaris Cluster" Type="Product Name">
               <Branch Name="3.3" Type="Product Version">
                  <FullProductName ProductID="P-10005V-3.3">Solaris Cluster Version 3.3</FullProductName>
               </Branch>
               <Branch Name="4.1" Type="Product Version">
                  <FullProductName ProductID="P-10005V-4.1">Solaris Cluster Version 4.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Solaris Operating System" Type="Product Name">
               <Branch Name="10" Type="Product Version">
                  <FullProductName ProductID="P-10006V-10">Solaris Operating System Version 10</FullProductName>
               </Branch>
               <Branch Name="11" Type="Product Version">
                  <FullProductName ProductID="P-10006V-11">Solaris Operating System Version 11</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Fujitsu M10 Firmware" Type="Product Name">
               <Branch Name="XCP prior to XCP 2232" Type="Product Version">
                  <FullProductName ProductID="P-10656V-XCP prior to XCP 2232">Fujitsu M10 Firmware Version XCP prior to XCP 2232</FullProductName>
               </Branch>
               <Branch Name="XCP prior to XCP 2240" Type="Product Version">
                  <FullProductName ProductID="P-10656V-XCP prior to XCP 2240">Fujitsu M10 Firmware Version XCP prior to XCP 2240</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Supply Chain Products Suite" Type="Product Family">
            <Branch Name="Transportation Management" Type="Product Name">
               <Branch Name="6.1" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.1">Transportation Management Version 6.1</FullProductName>
               </Branch>
               <Branch Name="6.2" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.2">Transportation Management Version 6.2</FullProductName>
               </Branch>
               <Branch Name="6.3" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.3">Transportation Management Version 6.3</FullProductName>
               </Branch>
               <Branch Name="6.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.3.0">Transportation Management Version 6.3.0</FullProductName>
               </Branch>
               <Branch Name="6.3.0 6.3.1" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.3.0 6.3.1">Transportation Management Version 6.3.0 6.3.1</FullProductName>
               </Branch>
               <Branch Name="6.3.1" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.3.1">Transportation Management Version 6.3.1</FullProductName>
               </Branch>
               <Branch Name="6.3.2" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.3.2">Transportation Management Version 6.3.2</FullProductName>
               </Branch>
               <Branch Name="6.3.3" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.3.3">Transportation Management Version 6.3.3</FullProductName>
               </Branch>
               <Branch Name="6.3.4" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.3.4">Transportation Management Version 6.3.4</FullProductName>
               </Branch>
               <Branch Name="6.3.5" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.3.5">Transportation Management Version 6.3.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Agile Product Collaboration" Type="Product Name">
               <Branch Name="9.3.3" Type="Product Version">
                  <FullProductName ProductID="P-4429V-9.3.3">Agile Product Collaboration Version 9.3.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Agile Product Lifecycle Management for Process" Type="Product Name">
               <Branch Name="6.1.0.3" Type="Product Version">
                  <FullProductName ProductID="P-4445V-6.1.0.3">Agile Product Lifecycle Management for Process Version 6.1.0.3</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Virtualization" Type="Product Family">
            <Branch Name="Oracle VM VirtualBox" Type="Product Name">
               <Branch Name="4.0.26" Type="Product Version">
                  <FullProductName ProductID="P-8370V-4.0.26">Oracle VM VirtualBox Version 4.0.26</FullProductName>
               </Branch>
               <Branch Name="4.0.28" Type="Product Version">
                  <FullProductName ProductID="P-8370V-4.0.28">Oracle VM VirtualBox Version 4.0.28</FullProductName>
               </Branch>
               <Branch Name="4.1.34" Type="Product Version">
                  <FullProductName ProductID="P-8370V-4.1.34">Oracle VM VirtualBox Version 4.1.34</FullProductName>
               </Branch>
               <Branch Name="4.1.36" Type="Product Version">
                  <FullProductName ProductID="P-8370V-4.1.36">Oracle VM VirtualBox Version 4.1.36</FullProductName>
               </Branch>
               <Branch Name="4.2.26" Type="Product Version">
                  <FullProductName ProductID="P-8370V-4.2.26">Oracle VM VirtualBox Version 4.2.26</FullProductName>
               </Branch>
               <Branch Name="4.2.28" Type="Product Version">
                  <FullProductName ProductID="P-8370V-4.2.28">Oracle VM VirtualBox Version 4.2.28</FullProductName>
               </Branch>
               <Branch Name="4.3.14" Type="Product Version">
                  <FullProductName ProductID="P-8370V-4.3.14">Oracle VM VirtualBox Version 4.3.14</FullProductName>
               </Branch>
               <Branch Name="VirtualBox prior to 3.2.24" Type="Product Version">
                  <FullProductName ProductID="P-8370V-VirtualBox prior to 3.2.24">Oracle VM VirtualBox Version VirtualBox prior to 3.2.24</FullProductName>
               </Branch>
               <Branch Name="VirtualBox prior to 3.2.26" Type="Product Version">
                  <FullProductName ProductID="P-8370V-VirtualBox prior to 3.2.26">Oracle VM VirtualBox Version VirtualBox prior to 3.2.26</FullProductName>
               </Branch>
               <Branch Name="VirtualBox prior to 4.3.20" Type="Product Version">
                  <FullProductName ProductID="P-8370V-VirtualBox prior to 4.3.20">Oracle VM VirtualBox Version VirtualBox prior to 4.3.20</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Secure Global Desktop" Type="Product Name">
               <Branch Name="4.63" Type="Product Version">
                  <FullProductName ProductID="P-8539V-4.63">Secure Global Desktop Version 4.63</FullProductName>
               </Branch>
               <Branch Name="4.71" Type="Product Version">
                  <FullProductName ProductID="P-8539V-4.71">Secure Global Desktop Version 4.71</FullProductName>
               </Branch>
               <Branch Name="5.0" Type="Product Version">
                  <FullProductName ProductID="P-8539V-5.0">Secure Global Desktop Version 5.0</FullProductName>
               </Branch>
               <Branch Name="5.1" Type="Product Version">
                  <FullProductName ProductID="P-8539V-5.1">Secure Global Desktop Version 5.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle iLearning" Type="Product Family">
            <Branch Name="iLearning" Type="Product Name">
               <Branch Name="6.0" Type="Product Version">
                  <FullProductName ProductID="P-902V-6.0">iLearning Version 6.0</FullProductName>
               </Branch>
               <Branch Name="6.1" Type="Product Version">
                  <FullProductName ProductID="P-902V-6.1">iLearning Version 6.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
      </Branch>
   </ProductTree>
   <Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2003-0001</Title>
      <Notes>
         <Note Audience="All" Ordinal="1" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: AMD pcnet driver).  Supported versions that are affected are 10 and  11. Easily exploitable vulnerability allows successful unauthenticated network attacks via TCP/IP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Solaris accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2003-0001</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-10</ProductID>
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-10006V-10</ProductID>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2004-0230</Title>
      <Notes>
         <Note Audience="All" Ordinal="2" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Network).  Supported versions that are affected are 10 and  11. Easily exploitable vulnerability allows successful unauthenticated network attacks via TCP/IP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Solaris.  CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2004-0230</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-10</ProductID>
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-10006V-10</ProductID>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="3" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2010-5107</Title>
      <Notes>
         <Note Audience="All" Ordinal="3" Title="Details" Type="Details">Vulnerability in the SPARC Enterprise M3000, M4000, M5000, M8000, M9000 Servers component of Oracle Sun Systems Products Suite (subcomponent: XCP Firmware).   The supported version that is affected is XCP prior to XCP 1118. Easily exploitable vulnerability allows successful unauthenticated network attacks via SSH.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of SPARC Enterprise M3000, M4000, M5000, M8000, M9000 Servers.  CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2010-5107</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9845V-XCP prior to XCP 1118</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9845V-XCP prior to XCP 1118</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="4" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2011-1944</Title>
      <Notes>
         <Note Audience="All" Ordinal="4" Title="Details" Type="Details">Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: Web Listener).  Supported versions that are affected are 11.1.1.7.0, 12.1.2.0 and  12.1.3.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.  CVSS Base Score 9.3 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2011-1944</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1042V-11.1.1.7.0</ProductID>
            <ProductID>P-1042V-12.1.2.0</ProductID>
            <ProductID>P-1042V-12.1.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>9.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1042V-11.1.1.7.0</ProductID>
            <ProductID>P-1042V-12.1.2.0</ProductID>
            <ProductID>P-1042V-12.1.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="5" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2011-3368</Title>
      <Notes>
         <Note Audience="All" Ordinal="5" Title="Details" Type="Details">Vulnerability in the SPARC Enterprise M3000, M4000, M5000, M8000, M9000 Servers component of Oracle Sun Systems Products Suite (subcomponent: XCP Firmware).   The supported version that is affected is XCP prior to XCP 1118. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of SPARC Enterprise M3000, M4000, M5000, M8000, M9000 Servers accessible data.   Note: This fix also addresses CVE-2011-4317 and CVE-2012-0053. CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2011-3368</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9845V-XCP prior to XCP 1118</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9845V-XCP prior to XCP 1118</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="6" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2011-3389</Title>
      <Notes>
         <Note Audience="All" Ordinal="6" Title="Details" Type="Details">Vulnerability in the Oracle Security Service component of Oracle Fusion Middleware (subcomponent: None).  Supported versions that are affected are OHS: 12.1.2 and  FMW: 12.1.3. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTPS.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Security Service accessible data.  CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2011-3389</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-991V-OHS: 12.1.2</ProductID>
            <ProductID>P-991V-FMW: 12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-991V-OHS: 12.1.2</ProductID>
            <ProductID>P-991V-FMW: 12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="7" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2011-3607</Title>
      <Notes>
         <Note Audience="All" Ordinal="7" Title="Details" Type="Details">Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: Web Listener).  Supported versions that are affected are 10.1.3.5.0, 11.1.1.7.0 and  12.1.2.0. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle HTTP Server accessible data as well as  read access to a subset of Oracle HTTP Server accessible data and ability to cause a partial denial of service (partial DOS) of Oracle HTTP Server.  CVSS Base Score 4.4 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:L/AC:M/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2011-3607</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1042V-10.1.3.5.0</ProductID>
            <ProductID>P-1042V-11.1.1.7.0</ProductID>
            <ProductID>P-1042V-12.1.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.4</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1042V-10.1.3.5.0</ProductID>
            <ProductID>P-1042V-11.1.1.7.0</ProductID>
            <ProductID>P-1042V-12.1.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="8" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2011-4461</Title>
      <Notes>
         <Note Audience="All" Ordinal="8" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Agent).   The supported version that is affected is 12.1.0.3. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Enterprise Manager Base Platform.  CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2011-4461</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-12.1.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1370V-12.1.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="9" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-0338</Title>
      <Notes>
         <Note Audience="All" Ordinal="9" Title="Details" Type="Details">Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: Web Listener).  Supported versions that are affected are 11.1.1.7.0, 12.1.2.0 and  12.1.3.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HTTP Server.  CVSS Base Score 4.3 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-0338</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1042V-11.1.1.7.0</ProductID>
            <ProductID>P-1042V-12.1.2.0</ProductID>
            <ProductID>P-1042V-12.1.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1042V-11.1.1.7.0</ProductID>
            <ProductID>P-1042V-12.1.2.0</ProductID>
            <ProductID>P-1042V-12.1.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="10" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-1620</Title>
      <Notes>
         <Note Audience="All" Ordinal="10" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Ops Center component of Oracle Enterprise Manager Grid Control (subcomponent: Network).  Supported versions that are affected are 11.1, 12.1 and  12.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via SSL/TLS.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Enterprise Manager Ops Center accessible data.  CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-1620</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9835V-11.1</ProductID>
            <ProductID>P-9835V-12.1</ProductID>
            <ProductID>P-9835V-12.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9835V-11.1</ProductID>
            <ProductID>P-9835V-12.1</ProductID>
            <ProductID>P-9835V-12.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="11" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-1741</Title>
      <Notes>
         <Note Audience="All" Ordinal="11" Title="Details" Type="Details">Vulnerability in the Oracle Directory Server Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Admin Server).  Supported versions that are affected are 7.0 and 11.1.1.7. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTPS.  Successful attack of this vulnerability can result in unauthorized takeover of Oracle Directory Server Enterprise Edition possibly including arbitrary code execution within the Oracle Directory Server Enterprise Edition.   Note: This fix also addresses CVE-2013-1620, CVE-2013-1739,CVE-2013-1740, CVE-2013-5605, CVE-2013-5606,CVE-2014-1490, CVE-2014-1491 and CVE-2014-1492. CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-1741</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8512V-7.0</ProductID>
            <ProductID>P-8512V-11.1.1.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8512V-7.0</ProductID>
            <ProductID>P-8512V-11.1.1.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="12" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-2186</Title>
      <Notes>
         <Note Audience="All" Ordinal="12" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Config, WLS Console).  Supported versions that are affected are 10.3.6.0, 12.1.1.0, 12.1.2.0 and  12.1.3.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle WebLogic Server accessible data as well as  read access to a subset of Oracle WebLogic Server accessible data and ability to cause a partial denial of service (partial DOS) of Oracle WebLogic Server.   Note: This fix also addresses CVE-2014-0050. The CVSS score is taken from 
&lt;A HREF="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-2186"&gt;http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-2186&lt;/a&gt;. CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-2186</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.3.6.0</ProductID>
            <ProductID>P-5242V-12.1.1.0</ProductID>
            <ProductID>P-5242V-12.1.2.0</ProductID>
            <ProductID>P-5242V-12.1.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-5242V-10.3.6.0</ProductID>
            <ProductID>P-5242V-12.1.1.0</ProductID>
            <ProductID>P-5242V-12.1.2.0</ProductID>
            <ProductID>P-5242V-12.1.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="13" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-2186</Title>
      <Notes>
         <Note Audience="All" Ordinal="13" Title="Details" Type="Details">Vulnerability in the Oracle Healthcare Master Person Index component of Oracle Health Sciences Applications (subcomponent: Internal Operations).  Supported versions that are affected are 1.x and  2.x. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Healthcare Master Person Index accessible data as well as  read access to a subset of Oracle Healthcare Master Person Index accessible data and ability to cause a partial denial of service (partial DOS) of Oracle Healthcare Master Person Index.   Note: This fix also addresses CVE-2014-0050. The CVSS score is taken from 
&lt;A HREF="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-2186"&gt;http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-2186&lt;/a&gt;. CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-2186</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8575V-1.x</ProductID>
            <ProductID>P-8575V-2.x</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8575V-1.x</ProductID>
            <ProductID>P-8575V-2.x</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="14" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-2186</Title>
      <Notes>
         <Note Audience="All" Ordinal="14" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Ops Center component of Oracle Enterprise Manager Grid Control (subcomponent: File Upload Utility).  Supported versions that are affected are 11.1.3 and  12.1.4. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Enterprise Manager Ops Center accessible data as well as  read access to a subset of Enterprise Manager Ops Center accessible data and ability to cause a partial denial of service (partial DOS) of Enterprise Manager Ops Center.   Note: This fix also addresses CVE-2014-0050. The CVSS score is taken from 
&lt;A HREF="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-2186"&gt;http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-2186&lt;/a&gt;. CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-2186</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9835V-11.1.3</ProductID>
            <ProductID>P-9835V-12.1.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9835V-11.1.3</ProductID>
            <ProductID>P-9835V-12.1.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="15" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-2877</Title>
      <Notes>
         <Note Audience="All" Ordinal="15" Title="Details" Type="Details">Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: Web Listener).  Supported versions that are affected are 11.1.1.7.0, 12.1.2.0 and  12.1.3.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HTTP Server.  CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-2877</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1042V-11.1.1.7.0</ProductID>
            <ProductID>P-1042V-12.1.2.0</ProductID>
            <ProductID>P-1042V-12.1.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1042V-11.1.1.7.0</ProductID>
            <ProductID>P-1042V-12.1.2.0</ProductID>
            <ProductID>P-1042V-12.1.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="16" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-4286</Title>
      <Notes>
         <Note Audience="All" Ordinal="16" Title="Details" Type="Details">Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security).  Supported versions that are affected are 10.1.3.4.2 and  11.1.1.7. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some BI Publisher (formerly XML Publisher) accessible data as well as  read access to a subset of BI Publisher (formerly XML Publisher) accessible data.  CVSS Base Score 5.8 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-4286</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1479V-10.1.3.4.2</ProductID>
            <ProductID>P-1479V-11.1.1.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1479V-10.1.3.4.2</ProductID>
            <ProductID>P-1479V-11.1.1.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="17" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-4545</Title>
      <Notes>
         <Note Audience="All" Ordinal="17" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Ops Center component of Oracle Enterprise Manager Grid Control (subcomponent: Update Provisioning).  Supported versions that are affected are 11.1.3 and  12.1.4. Difficult to exploit vulnerability allows successful unauthenticated network attacks via SSL/TLS.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Enterprise Manager Ops Center accessible data.   Note: This fix also addresses CVE-2014-0015. CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-4545</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9835V-11.1.3</ProductID>
            <ProductID>P-9835V-12.1.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9835V-11.1.3</ProductID>
            <ProductID>P-9835V-12.1.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="18" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-4784</Title>
      <Notes>
         <Note Audience="All" Ordinal="18" Title="Details" Type="Details">Vulnerability in the Fujitsu M10-1, M10-4, M10-4S Servers component of Oracle Sun Systems Products Suite (subcomponent: XCP Firmware).   The supported version that is affected is XCP prior to XCP 2232. Easily exploitable vulnerability allows successful unauthenticated network attacks via SSL/TLS.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.  CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-4784</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10656V-XCP prior to XCP 2232</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-10656V-XCP prior to XCP 2232</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="19" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5704</Title>
      <Notes>
         <Note Audience="All" Ordinal="19" Title="Details" Type="Details">Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: Web Listener).  Supported versions that are affected are 10.1.3.5.0, 11.1.1.7.0, 12.1.2.0 and  12.1.3.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle HTTP Server accessible data.  CVSS Base Score 5.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5704</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1042V-10.1.3.5.0</ProductID>
            <ProductID>P-1042V-11.1.1.7.0</ProductID>
            <ProductID>P-1042V-12.1.2.0</ProductID>
            <ProductID>P-1042V-12.1.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1042V-10.1.3.5.0</ProductID>
            <ProductID>P-1042V-11.1.1.7.0</ProductID>
            <ProductID>P-1042V-12.1.2.0</ProductID>
            <ProductID>P-1042V-12.1.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="20" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-6438</Title>
      <Notes>
         <Note Audience="All" Ordinal="20" Title="Details" Type="Details">Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: Web Listener).  Supported versions that are affected are 10.1.3.5.0, 11.1.1.7.0, 12.1.2.0 and  12.1.3.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HTTP Server.  CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-6438</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1042V-10.1.3.5.0</ProductID>
            <ProductID>P-1042V-11.1.1.7.0</ProductID>
            <ProductID>P-1042V-12.1.2.0</ProductID>
            <ProductID>P-1042V-12.1.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1042V-10.1.3.5.0</ProductID>
            <ProductID>P-1042V-11.1.1.7.0</ProductID>
            <ProductID>P-1042V-12.1.2.0</ProductID>
            <ProductID>P-1042V-12.1.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="21" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-6450</Title>
      <Notes>
         <Note Audience="All" Ordinal="21" Title="Details" Type="Details">Vulnerability in the Integrated Lights Out Manager(ILOM) component of Oracle Sun Systems Products Suite (subcomponent: OpenSSL).   The supported version that is affected is ILOM prior to 3.2.4. Very difficult to exploit vulnerability allows successful authenticated network attacks via SSL/TLS.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Integrated Lights Out Manager(ILOM).   Note: This fix also addresses CVE-2013-6449. CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:H/Au:S/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-6450</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9849V-ILOM prior to 3.2.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:N/AC:H/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9849V-ILOM prior to 3.2.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="22" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-0098</Title>
      <Notes>
         <Note Audience="All" Ordinal="22" Title="Details" Type="Details">Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: Web Listener).  Supported versions that are affected are 10.1.3.5.0, 11.1.1.7.0, 12.1.2.0 and  12.1.3.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HTTP Server.  CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-0098</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1042V-10.1.3.5.0</ProductID>
            <ProductID>P-1042V-11.1.1.7.0</ProductID>
            <ProductID>P-1042V-12.1.2.0</ProductID>
            <ProductID>P-1042V-12.1.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1042V-10.1.3.5.0</ProductID>
            <ProductID>P-1042V-11.1.1.7.0</ProductID>
            <ProductID>P-1042V-12.1.2.0</ProductID>
            <ProductID>P-1042V-12.1.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="23" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-0114</Title>
      <Notes>
         <Note Audience="All" Ordinal="23" Title="Details" Type="Details">Vulnerability in the Oracle Real-Time Decision Server component of Oracle Fusion Middleware (subcomponent: Decision Server).  Supported versions that are affected are 11.1.1.7 and  RTD Platform 3.0.x. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Real-Time Decision Server accessible data as well as  read access to a subset of Oracle Real-Time Decision Server accessible data and ability to cause a partial denial of service (partial DOS) of Oracle Real-Time Decision Server.  CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-0114</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2104V-11.1.1.7</ProductID>
            <ProductID>P-2104V-RTD Platform 3.0.x</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-2104V-11.1.1.7</ProductID>
            <ProductID>P-2104V-RTD Platform 3.0.x</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="24" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-0114</Title>
      <Notes>
         <Note Audience="All" Ordinal="24" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Portal component of Oracle Fusion Middleware (subcomponent: Third Party Tools).  Supported versions that are affected are 10.0.1.0, 10.2.1.0 and 10.3.6.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized takeover of Oracle WebLogic Portal possibly including arbitrary code execution within the Oracle WebLogic Portal.  CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-0114</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5307V-10.0.1.0</ProductID>
            <ProductID>P-5307V-10.2.1.0</ProductID>
            <ProductID>P-5307V-10.3.6.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-5307V-10.0.1.0</ProductID>
            <ProductID>P-5307V-10.2.1.0</ProductID>
            <ProductID>P-5307V-10.3.6.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="25" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-0114</Title>
      <Notes>
         <Note Audience="All" Ordinal="25" Title="Details" Type="Details">Vulnerability in the Oracle Waveset component of Oracle Fusion Middleware (subcomponent: Struts).   The supported version that is affected is 8.1.1. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Waveset accessible data as well as  read access to a subset of Oracle Waveset accessible data and ability to cause a partial denial of service (partial DOS) of Oracle Waveset.  CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-0114</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8518V-8.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8518V-8.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="26" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-0191</Title>
      <Notes>
         <Note Audience="All" Ordinal="26" Title="Details" Type="Details">Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: Web Listener).  Supported versions that are affected are 11.1.1.7.0, 12.1.2.0 and  12.1.3.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HTTP Server.  CVSS Base Score 4.3 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-0191</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1042V-11.1.1.7.0</ProductID>
            <ProductID>P-1042V-12.1.2.0</ProductID>
            <ProductID>P-1042V-12.1.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1042V-11.1.1.7.0</ProductID>
            <ProductID>P-1042V-12.1.2.0</ProductID>
            <ProductID>P-1042V-12.1.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="27" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-0224</Title>
      <Notes>
         <Note Audience="All" Ordinal="27" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: OpenSSL).  Supported versions that are affected are VirtualBox prior to 3.2.24, 4.0.26, 4.1.34, 4.2.26 and  4.3.14. Difficult to exploit vulnerability allows successful unauthenticated network attacks via SSL/TLS.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle VM VirtualBox accessible data as well as  read access to a subset of Oracle VM VirtualBox accessible data and ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox.   Note: This fix also addresses CVE-2014-0221, CVE-2014-0195, CVE-2014-0198, CVE-2010-5298, CVE-2014-3470 and CVE-2014-0076. CVSS Base Score 6.8 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-0224</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-VirtualBox prior to 3.2.24</ProductID>
            <ProductID>P-8370V-4.0.26</ProductID>
            <ProductID>P-8370V-4.1.34</ProductID>
            <ProductID>P-8370V-4.2.26</ProductID>
            <ProductID>P-8370V-4.3.14</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8370V-VirtualBox prior to 3.2.24</ProductID>
            <ProductID>P-8370V-4.0.26</ProductID>
            <ProductID>P-8370V-4.1.34</ProductID>
            <ProductID>P-8370V-4.2.26</ProductID>
            <ProductID>P-8370V-4.3.14</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="28" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-0224</Title>
      <Notes>
         <Note Audience="All" Ordinal="28" Title="Details" Type="Details">Vulnerability in the Oracle Exalogic Infrastructure component of Oracle Fusion Middleware (subcomponent: Network Infra Framework).  Supported versions that are affected are 2.0.6.2.0 (for all X2-2, X3-2 and  X4-2). Very difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.  CVSS Base Score 7.6 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:H/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-0224</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9415V-2.0.6.2.0 (for all X2-2</ProductID>
            <ProductID>P-9415V-X3-2</ProductID>
            <ProductID>P-9415V-X4-2)</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.6</BaseScore>
            <Vector>AV:N/AC:H/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9415V-2.0.6.2.0 (for all X2-2</ProductID>
            <ProductID>P-9415V-X3-2</ProductID>
            <ProductID>P-9415V-X4-2)</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="29" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-0224</Title>
      <Notes>
         <Note Audience="All" Ordinal="29" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Ops Center component of Oracle Enterprise Manager Grid Control (subcomponent: Networking).  Supported versions that are affected are 11.1.3 and  12.1.4. Difficult to exploit vulnerability allows successful unauthenticated network attacks via SSL/TLS.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Enterprise Manager Ops Center accessible data as well as  read access to a subset of Enterprise Manager Ops Center accessible data and ability to cause a partial denial of service (partial DOS) of Enterprise Manager Ops Center.  CVSS Base Score 6.8 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-0224</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9835V-11.1.3</ProductID>
            <ProductID>P-9835V-12.1.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9835V-11.1.3</ProductID>
            <ProductID>P-9835V-12.1.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="30" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-0224</Title>
      <Notes>
         <Note Audience="All" Ordinal="30" Title="Details" Type="Details">Vulnerability in the SPARC Enterprise M3000, M4000, M5000, M8000, M9000 Servers component of Oracle Sun Systems Products Suite (subcomponent: XCP Firmware).   The supported version that is affected is XCP prior to XCP 1118. Very difficult to exploit vulnerability allows successful authenticated network attacks via SSL/TLS.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some SPARC Enterprise M3000, M4000, M5000, M8000, M9000 Servers accessible data as well as  read access to a subset of SPARC Enterprise M3000, M4000, M5000, M8000, M9000 Servers accessible data.  CVSS Base Score 3.6 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:H/Au:S/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-0224</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9845V-XCP prior to XCP 1118</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.6</BaseScore>
            <Vector>AV:N/AC:H/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9845V-XCP prior to XCP 1118</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="31" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-0224</Title>
      <Notes>
         <Note Audience="All" Ordinal="31" Title="Details" Type="Details">Vulnerability in the Integrated Lights Out Manager(ILOM) component of Oracle Sun Systems Products Suite (subcomponent: OpenSSL).   The supported version that is affected is ILOM prior to 3.2.4. Very difficult to exploit vulnerability allows successful authenticated network attacks via SSL/TLS.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Integrated Lights Out Manager(ILOM) accessible data as well as  read access to a subset of Integrated Lights Out Manager(ILOM) accessible data.  CVSS Base Score 3.6 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:H/Au:S/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-0224</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9849V-ILOM prior to 3.2.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.6</BaseScore>
            <Vector>AV:N/AC:H/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9849V-ILOM prior to 3.2.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="32" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-0226</Title>
      <Notes>
         <Note Audience="All" Ordinal="32" Title="Details" Type="Details">Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: Web Listener).  Supported versions that are affected are 10.1.3.5.0, 11.1.1.7.0, 12.1.2.0 and  12.1.3.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle HTTP Server accessible data as well as  read access to a subset of Oracle HTTP Server accessible data and ability to cause a partial denial of service (partial DOS) of Oracle HTTP Server.   Note: This fix also addresses CVE-2014-0117, CVE-2014-0118 and CVE-2014-0231. CVSS Base Score 6.8 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-0226</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1042V-10.1.3.5.0</ProductID>
            <ProductID>P-1042V-11.1.1.7.0</ProductID>
            <ProductID>P-1042V-12.1.2.0</ProductID>
            <ProductID>P-1042V-12.1.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1042V-10.1.3.5.0</ProductID>
            <ProductID>P-1042V-11.1.1.7.0</ProductID>
            <ProductID>P-1042V-12.1.2.0</ProductID>
            <ProductID>P-1042V-12.1.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="33" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-0226</Title>
      <Notes>
         <Note Audience="All" Ordinal="33" Title="Details" Type="Details">Vulnerability in the Oracle Secure Global Desktop component of Oracle Virtualization (subcomponent: Apache HTTP Server).  Supported versions that are affected are 4.63, 4.71, 5.0 and  5.1. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Secure Global Desktop accessible data as well as  read access to a subset of Oracle Secure Global Desktop accessible data and ability to cause a partial denial of service (partial DOS) of Oracle Secure Global Desktop.   Note: This fix also addresses CVE-2014-0231, CVE-2014-0118 and CVE-2014-5704. CVSS Base Score 6.8 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-0226</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8539V-4.63</ProductID>
            <ProductID>P-8539V-4.71</ProductID>
            <ProductID>P-8539V-5.0</ProductID>
            <ProductID>P-8539V-5.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8539V-4.63</ProductID>
            <ProductID>P-8539V-4.71</ProductID>
            <ProductID>P-8539V-5.0</ProductID>
            <ProductID>P-8539V-5.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="34" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-0226</Title>
      <Notes>
         <Note Audience="All" Ordinal="34" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Ops Center component of Oracle Enterprise Manager Grid Control (subcomponent: Update Provisioning).  Supported versions that are affected are 11.1.3 and  12.1.4. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Enterprise Manager Ops Center accessible data as well as  read access to a subset of Enterprise Manager Ops Center accessible data and ability to cause a partial denial of service (partial DOS) of Enterprise Manager Ops Center.   Note: This fix also addresses CVE-2014-0117, CVE-2014-0118 and CVE-2014-0231. CVSS Base Score 6.8 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-0226</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9835V-11.1.3</ProductID>
            <ProductID>P-9835V-12.1.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9835V-11.1.3</ProductID>
            <ProductID>P-9835V-12.1.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="35" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-1568</Title>
      <Notes>
         <Note Audience="All" Ordinal="35" Title="Details" Type="Details">Vulnerability in the Oracle Communications Messaging Server component of Oracle Communications Applications (subcomponent: Security).  Supported versions that are affected are 7.0.5.33.0 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via SSL/TLS.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Communications Messaging Server accessible data as well as  read access to a subset of Oracle Communications Messaging Server accessible data and ability to cause a partial denial of service (partial DOS) of Oracle Communications Messaging Server.  CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-1568</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8496V-7.0.5.33.0 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8496V-7.0.5.33.0 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="36" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-3566</Title>
      <Notes>
         <Note Audience="All" Ordinal="36" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JSSE).  Supported versions that are affected are Java SE 5.0u75, Java SE 6u85, Java SE 7u72, Java SE 8u25, Java SE Embedded 7u71, Java SE Embedded 8u6, JRockit 27.8.4 and  JRockit 28.3.4. Difficult to exploit vulnerability allows successful unauthenticated network attacks via SSL/TLS.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Java SE, Java SE Embedded, JRockit accessible data.   Note: Applies to client and server deployment of JSSE. CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-3566</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 5.0u75</ProductID>
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u71</ProductID>
            <ProductID>P-856V-Java SE Embedded 8u6</ProductID>
            <ProductID>P-856V-JRockit 27.8.4</ProductID>
            <ProductID>P-856V-JRockit 28.3.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-856V-Java SE 5.0u75</ProductID>
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u71</ProductID>
            <ProductID>P-856V-Java SE Embedded 8u6</ProductID>
            <ProductID>P-856V-JRockit 27.8.4</ProductID>
            <ProductID>P-856V-JRockit 28.3.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="37" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-3566</Title>
      <Notes>
         <Note Audience="All" Ordinal="37" Title="Details" Type="Details">Vulnerability in the Oracle Secure Global Desktop component of Oracle Virtualization (subcomponent: Client, Gateway JARP module, Gateway Reverse Proxy, Print Servlet (only in 5.0 &amp; 5.1), SSL Daemon (ttassl), Web Server).  Supported versions that are affected are 4.63, 4.71, 5.0 and  5.1. Difficult to exploit vulnerability allows successful unauthenticated network attacks via SSL/TLS.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Secure Global Desktop accessible data.  CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-3566</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8539V-4.63</ProductID>
            <ProductID>P-8539V-4.71</ProductID>
            <ProductID>P-8539V-5.0</ProductID>
            <ProductID>P-8539V-5.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8539V-4.63</ProductID>
            <ProductID>P-8539V-4.71</ProductID>
            <ProductID>P-8539V-5.0</ProductID>
            <ProductID>P-8539V-5.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="38" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-3566</Title>
      <Notes>
         <Note Audience="All" Ordinal="38" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Ops Center component of Oracle Enterprise Manager Grid Control (subcomponent: Update Provisioning).  Supported versions that are affected are 11.1.3 and  12.1.4. Difficult to exploit vulnerability allows successful unauthenticated network attacks via SSL/TLS.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Enterprise Manager Ops Center accessible data.  CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-3566</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9835V-11.1.3</ProductID>
            <ProductID>P-9835V-12.1.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9835V-11.1.3</ProductID>
            <ProductID>P-9835V-12.1.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="39" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-3566</Title>
      <Notes>
         <Note Audience="All" Ordinal="39" Title="Details" Type="Details">Vulnerability in the SPARC Enterprise M3000, M4000, M5000, M8000, M9000 Servers component of Oracle Sun Systems Products Suite (subcomponent: XCP Firmware).   The supported version that is affected is XCP prior to XCP 1119. Difficult to exploit vulnerability allows successful unauthenticated network attacks via SSL/TLS.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of SPARC Enterprise M3000, M4000, M5000, M8000, M9000 Servers accessible data.  CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-3566</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9845V-XCP prior to XCP 1119</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9845V-XCP prior to XCP 1119</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="40" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-3566</Title>
      <Notes>
         <Note Audience="All" Ordinal="40" Title="Details" Type="Details">Vulnerability in the Fujitsu M10-1, M10-4, M10-4S Servers component of Oracle Sun Systems Products Suite (subcomponent: XCP Firmware).   The supported version that is affected is XCP prior to XCP 2240. Difficult to exploit vulnerability allows successful unauthenticated network attacks via SSL/TLS.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Fujitsu M10-1, M10-4, M10-4S Servers accessible data.  CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-3566</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10656V-XCP prior to XCP 2240</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-10656V-XCP prior to XCP 2240</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="41" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-3567</Title>
      <Notes>
         <Note Audience="All" Ordinal="41" Title="Details" Type="Details">Vulnerability in the Oracle Secure Global Desktop component of Oracle Virtualization (subcomponent: OpenSSL).  Supported versions that are affected are 4.63, 4.71, 5.0 and  5.1. Difficult to exploit vulnerability allows successful unauthenticated network attacks via SSL/TLS.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 7.1 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-3567</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8539V-4.63</ProductID>
            <ProductID>P-8539V-4.71</ProductID>
            <ProductID>P-8539V-5.0</ProductID>
            <ProductID>P-8539V-5.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.1</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8539V-4.63</ProductID>
            <ProductID>P-8539V-4.71</ProductID>
            <ProductID>P-8539V-5.0</ProductID>
            <ProductID>P-8539V-5.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="42" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-4212</Title>
      <Notes>
         <Note Audience="All" Ordinal="42" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Process Management &amp; Notification).  Supported versions that are affected are 12.1.0.3 and  12.1.0.4. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTPS.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Enterprise Manager Base Platform accessible data.  CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-4212</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-12.1.0.3</ProductID>
            <ProductID>P-1370V-12.1.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1370V-12.1.0.3</ProductID>
            <ProductID>P-1370V-12.1.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="43" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-4259</Title>
      <Notes>
         <Note Audience="All" Ordinal="43" Title="Details" Type="Details">Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: System management).  Supported versions that are affected are 3.3 and  4.1. Easily exploitable vulnerability allows successful authenticated network attacks via TCP/IP.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.  CVSS Base Score 9.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:S/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-4259</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10005V-3.3</ProductID>
            <ProductID>P-10005V-4.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>9.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-10005V-3.3</ProductID>
            <ProductID>P-10005V-4.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="44" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-4279</Title>
      <Notes>
         <Note Audience="All" Ordinal="44" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: PIA Core Technology ).   The supported version that is affected is 8.53. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-4279</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.53</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-5085V-8.53</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="45" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6480</Title>
      <Notes>
         <Note Audience="All" Ordinal="45" Title="Details" Type="Details">Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: System management).  Supported versions that are affected are 3.3 and  4.1. Easily exploitable vulnerability requiring logon to Operating System plus additional, multiple logins to components.  Successful attack of this vulnerability can escalate attacker privileges resulting in unauthorized Operating System takeover including arbitrary code execution.  CVSS Base Score 6.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:M/C:C/I:C/A:C).  Oracle Vector: (AV:L/AC:L/Au:M/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6480</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10005V-3.3</ProductID>
            <ProductID>P-10005V-4.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.5</BaseScore>
            <Vector>AV:L/AC:L/Au:M/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-10005V-3.3</ProductID>
            <ProductID>P-10005V-4.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="46" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6481</Title>
      <Notes>
         <Note Audience="All" Ordinal="46" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: KSSL).  Supported versions that are affected are 10 and  11. Difficult to exploit vulnerability allows successful unauthenticated network attacks via SSL/TLS.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Solaris accessible data.  CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6481</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-10</ProductID>
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-10006V-10</ProductID>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="47" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6509</Title>
      <Notes>
         <Note Audience="All" Ordinal="47" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel).   The supported version that is affected is 10. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 4.9 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6509</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.9</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-10006V-10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="48" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6510</Title>
      <Notes>
         <Note Audience="All" Ordinal="48" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Power Management Utility).   The supported version that is affected is 11. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.  CVSS Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:L/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6510</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.2</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="49" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6514</Title>
      <Notes>
         <Note Audience="All" Ordinal="49" Title="Details" Type="Details">Vulnerability in the PL/SQL component of Oracle Database Server.  This vulnerability requires Create Session privileges for a successful attack.  Supported versions that are affected are 11.1.0.7, 11.2.0.3, 11.2.0.4 and  12.1.0.1. Easily exploitable vulnerability allows successful authenticated network attacks via Oracle Net.  Successful attack of this vulnerability can result in unauthorized  read access to all PL/SQL accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P+/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6514</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11V-11.1.0.7</ProductID>
            <ProductID>P-11V-11.2.0.3</ProductID>
            <ProductID>P-11V-11.2.0.4</ProductID>
            <ProductID>P-11V-12.1.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-11V-11.1.0.7</ProductID>
            <ProductID>P-11V-11.2.0.3</ProductID>
            <ProductID>P-11V-11.2.0.4</ProductID>
            <ProductID>P-11V-12.1.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="50" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6518</Title>
      <Notes>
         <Note Audience="All" Ordinal="50" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Unix File System(UFS)).  Supported versions that are affected are 10 and  11. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  write access to any arbitrary Operating System location and Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 6.6 (Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:C/A:C).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6518</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-10</ProductID>
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.6</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-10006V-10</ProductID>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="51" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6521</Title>
      <Notes>
         <Note Audience="All" Ordinal="51" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: CDE - Power Management Utility).   The supported version that is affected is 10. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.  CVSS Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:L/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6521</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.2</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-10006V-10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="52" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6524</Title>
      <Notes>
         <Note Audience="All" Ordinal="52" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel).   The supported version that is affected is 10. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.  CVSS Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:L/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6524</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.2</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-10006V-10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="53" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6525</Title>
      <Notes>
         <Note Audience="All" Ordinal="53" Title="Details" Type="Details">Vulnerability in the Oracle Web Applications Desktop Integrator component of Oracle E-Business Suite (subcomponent: Templates).  Supported versions that are affected are 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, 12.2.3 and  12.2.4. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Web Applications Desktop Integrator accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6525</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1171V-11.5.10.2</ProductID>
            <ProductID>P-1171V-12.0.6</ProductID>
            <ProductID>P-1171V-12.1.3</ProductID>
            <ProductID>P-1171V-12.2.2</ProductID>
            <ProductID>P-1171V-12.2.3</ProductID>
            <ProductID>P-1171V-12.2.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1171V-11.5.10.2</ProductID>
            <ProductID>P-1171V-12.0.6</ProductID>
            <ProductID>P-1171V-12.1.3</ProductID>
            <ProductID>P-1171V-12.2.2</ProductID>
            <ProductID>P-1171V-12.2.3</ProductID>
            <ProductID>P-1171V-12.2.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="54" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6526</Title>
      <Notes>
         <Note Audience="All" Ordinal="54" Title="Details" Type="Details">Vulnerability in the Oracle Directory Server Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Admin Console).   The supported version that is affected is 7.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Directory Server Enterprise Edition accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6526</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8512V-7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8512V-7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="55" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6528</Title>
      <Notes>
         <Note Audience="All" Ordinal="55" Title="Details" Type="Details">Vulnerability in the Siebel Core - System Management component of Oracle Siebel CRM (subcomponent: Server Infrastructure).  Supported versions that are affected are 8.1.1 and  8.2.2. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Siebel Core - System Management accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6528</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9009V-8.1.1</ProductID>
            <ProductID>P-9009V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9009V-8.1.1</ProductID>
            <ProductID>P-9009V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="56" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6541</Title>
      <Notes>
         <Note Audience="All" Ordinal="56" Title="Details" Type="Details">Vulnerability in the Recovery component of Oracle Database Server.  This vulnerability requires Execute on DBMS_IR privileges for a successful attack.  Supported versions that are affected are 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1 and  12.1.0.2. Difficult to exploit vulnerability allows successful authenticated network attacks via Oracle Net.  Successful attack of this vulnerability can result in unauthorized  read access to any arbitrary Operating System location.   Note: This vulnerability is only applicable on a Windows operating system. The CVSS score is 6.3 for Database versions prior to 12&lt;i&gt;c&lt;/i&gt;. The CVSS is 3.5 (Confidentiality  is "Partial+") for Database 12&lt;i&gt;c&lt;/i&gt;. CVSS Base Score 6.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:C/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:C/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6541</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-11.1.0.7</ProductID>
            <ProductID>P-5V-11.2.0.3</ProductID>
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.1</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.3</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:C/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-5V-11.1.0.7</ProductID>
            <ProductID>P-5V-11.2.0.3</ProductID>
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.1</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="57" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6548</Title>
      <Notes>
         <Note Audience="All" Ordinal="57" Title="Details" Type="Details">Vulnerability in the Oracle SOA Suite component of Oracle Fusion Middleware (subcomponent: B2B Engine).   The supported version that is affected is 11.1.1.7. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized takeover of Oracle SOA Suite possibly including arbitrary code execution within the Oracle SOA Suite.   Note: Please refer to &lt;a href="https://support.oracle.com/CSP/main/article?cmd=show&amp;type=NOT&amp;id=1962206.1"&gt;My Oracle Support Note 1962206.1&lt;/a&gt; for instructions on how to address this issue. CVSS Base Score 4.6 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6548</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1162V-11.1.1.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.6</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1162V-11.1.1.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="58" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6549</Title>
      <Notes>
         <Note Audience="All" Ordinal="58" Title="Details" Type="Details">Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries).   The supported version that is affected is Java SE 8u25. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6549</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="59" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6556</Title>
      <Notes>
         <Note Audience="All" Ordinal="59" Title="Details" Type="Details">Vulnerability in the Oracle Applications DBA component of Oracle E-Business Suite (subcomponent: AD_DDL).  Supported versions that are affected are 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, 12.2.3 and  12.2.4. Very difficult to exploit vulnerability allows successful authenticated network attacks via Oracle Net.  Successful attack of this vulnerability can result in unauthorized takeover of Oracle Applications DBA possibly including arbitrary code execution within the Oracle Applications DBA.  CVSS Base Score 4.6 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:S/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:H/Au:S/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6556</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-166V-11.5.10.2</ProductID>
            <ProductID>P-166V-12.0.6</ProductID>
            <ProductID>P-166V-12.1.3</ProductID>
            <ProductID>P-166V-12.2.2</ProductID>
            <ProductID>P-166V-12.2.3</ProductID>
            <ProductID>P-166V-12.2.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.6</BaseScore>
            <Vector>AV:N/AC:H/Au:S/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-166V-11.5.10.2</ProductID>
            <ProductID>P-166V-12.0.6</ProductID>
            <ProductID>P-166V-12.1.3</ProductID>
            <ProductID>P-166V-12.2.2</ProductID>
            <ProductID>P-166V-12.2.3</ProductID>
            <ProductID>P-166V-12.2.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="60" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6565</Title>
      <Notes>
         <Note Audience="All" Ordinal="60" Title="Details" Type="Details">Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Portal SEC).   The supported version that is affected is 9.1.5. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some JD Edwards EnterpriseOne Tools accessible data as well as  read access to a subset of JD Edwards EnterpriseOne Tools accessible data and ability to cause a partial denial of service (partial DOS) of JD Edwards EnterpriseOne Tools.  CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6565</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4781V-9.1.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-4781V-9.1.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="61" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6566</Title>
      <Notes>
         <Note Audience="All" Ordinal="61" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Portal).   The supported version that is affected is 8.53. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 4.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6566</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.53</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-5085V-8.53</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="62" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6567</Title>
      <Notes>
         <Note Audience="All" Ordinal="62" Title="Details" Type="Details">Vulnerability in the Core RDBMS component of Oracle Database Server.  This vulnerability requires Create Session privileges for a successful attack.  Supported versions that are affected are 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1 and  12.1.0.2. Easily exploitable vulnerability allows successful authenticated network attacks via Oracle Net.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: The CVSS Score is 9.0 only on Windows for Database versions prior to 12&lt;i&gt;c&lt;/i&gt;. The CVSS Base Score is 6.5 (Confidentiality, Integrity and Availability are Partial+) for Database 12&lt;i&gt;c&lt;/i&gt; on Windows and for all versions of Database on Linux, Unix and other platforms. CVSS Base Score 9.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:S/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6567</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1163V-11.1.0.7</ProductID>
            <ProductID>P-1163V-11.2.0.3</ProductID>
            <ProductID>P-1163V-11.2.0.4</ProductID>
            <ProductID>P-1163V-12.1.0.1</ProductID>
            <ProductID>P-1163V-12.1.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>9.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1163V-11.1.0.7</ProductID>
            <ProductID>P-1163V-11.2.0.3</ProductID>
            <ProductID>P-1163V-11.2.0.4</ProductID>
            <ProductID>P-1163V-12.1.0.1</ProductID>
            <ProductID>P-1163V-12.1.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="63" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6568</Title>
      <Notes>
         <Note Audience="All" Ordinal="63" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : InnoDB : DML).  Supported versions that are affected are 5.5.40 and earlier and  5.6.21 and earlier. Difficult to exploit vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 3.5 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6568</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.40 and earlier</ProductID>
            <ProductID>P-8478V-5.6.21 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8478V-5.5.40 and earlier</ProductID>
            <ProductID>P-8478V-5.6.21 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="64" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6569</Title>
      <Notes>
         <Note Audience="All" Ordinal="64" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: CIE Related Components).  Supported versions that are affected are 10.0.2.0, 10.3.6.0, 12.1.1.0 and  12.1.2.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle WebLogic Server accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6569</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.0.2.0</ProductID>
            <ProductID>P-5242V-10.3.6.0</ProductID>
            <ProductID>P-5242V-12.1.1.0</ProductID>
            <ProductID>P-5242V-12.1.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-5242V-10.0.2.0</ProductID>
            <ProductID>P-5242V-10.3.6.0</ProductID>
            <ProductID>P-5242V-12.1.1.0</ProductID>
            <ProductID>P-5242V-12.1.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="65" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6570</Title>
      <Notes>
         <Note Audience="All" Ordinal="65" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: File System).   The supported version that is affected is 11. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 4.9 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6570</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.9</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="66" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6571</Title>
      <Notes>
         <Note Audience="All" Ordinal="66" Title="Details" Type="Details">Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: Web Listener).  Supported versions that are affected are 11.1.1.7.0, 12.1.2.0 and  12.1.3.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle HTTP Server accessible data as well as  read access to a subset of Oracle HTTP Server accessible data and ability to cause a partial denial of service (partial DOS) of Oracle HTTP Server.  CVSS Base Score 6.8 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6571</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1042V-11.1.1.7.0</ProductID>
            <ProductID>P-1042V-12.1.2.0</ProductID>
            <ProductID>P-1042V-12.1.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1042V-11.1.1.7.0</ProductID>
            <ProductID>P-1042V-12.1.2.0</ProductID>
            <ProductID>P-1042V-12.1.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="67" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6572</Title>
      <Notes>
         <Note Audience="All" Ordinal="67" Title="Details" Type="Details">Vulnerability in the Oracle Customer Interaction History component of Oracle E-Business Suite (subcomponent: List of Values).  Supported versions that are affected are 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2, 12.1.3, 12.2.2, 12.2.3 and  12.2.4. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Customer Interaction History accessible data as well as  read access to a subset of Oracle Customer Interaction History accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6572</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1374V-12.0.4</ProductID>
            <ProductID>P-1374V-12.0.5</ProductID>
            <ProductID>P-1374V-12.0.6</ProductID>
            <ProductID>P-1374V-12.1.1</ProductID>
            <ProductID>P-1374V-12.1.2</ProductID>
            <ProductID>P-1374V-12.1.3</ProductID>
            <ProductID>P-1374V-12.2.2</ProductID>
            <ProductID>P-1374V-12.2.3</ProductID>
            <ProductID>P-1374V-12.2.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1374V-12.0.4</ProductID>
            <ProductID>P-1374V-12.0.5</ProductID>
            <ProductID>P-1374V-12.0.6</ProductID>
            <ProductID>P-1374V-12.1.1</ProductID>
            <ProductID>P-1374V-12.1.2</ProductID>
            <ProductID>P-1374V-12.1.3</ProductID>
            <ProductID>P-1374V-12.2.2</ProductID>
            <ProductID>P-1374V-12.2.3</ProductID>
            <ProductID>P-1374V-12.2.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="68" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6573</Title>
      <Notes>
         <Note Audience="All" Ordinal="68" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Ops Center component of Oracle Enterprise Manager Grid Control (subcomponent: User Interface Framework).  Supported versions that are affected are 11.1.3 and  12.1.4. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Enterprise Manager Ops Center accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6573</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9835V-11.1.3</ProductID>
            <ProductID>P-9835V-12.1.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9835V-11.1.3</ProductID>
            <ProductID>P-9835V-12.1.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="69" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6574</Title>
      <Notes>
         <Note Audience="All" Ordinal="69" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM for Process component of Oracle Supply Chain Products Suite (subcomponent: Testing Protocol Library).   The supported version that is affected is 6.1.0.3. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Agile PLM for Process accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6574</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4445V-6.1.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-4445V-6.1.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="70" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6575</Title>
      <Notes>
         <Note Audience="All" Ordinal="70" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Network).  Supported versions that are affected are 10 and  11. Easily exploitable vulnerability allows successful unauthenticated network attacks via TCP/IP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Solaris.  CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6575</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-10</ProductID>
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-10006V-10</ProductID>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="71" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6576</Title>
      <Notes>
         <Note Audience="All" Ordinal="71" Title="Details" Type="Details">Vulnerability in the Oracle Adaptive Access Manager component of Oracle Fusion Middleware (subcomponent: OAM Integration).  Supported versions that are affected are 11.1.1.5, 11.1.1.7, 11.1.2.1 and 11.1.2.2. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Adaptive Access Manager accessible data as well as  read access to a subset of Oracle Adaptive Access Manager accessible data.  CVSS Base Score 5.5 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6576</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4419V-11.1.1.5</ProductID>
            <ProductID>P-4419V-11.1.1.7</ProductID>
            <ProductID>P-4419V-11.1.2.1</ProductID>
            <ProductID>P-4419V-11.1.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-4419V-11.1.1.5</ProductID>
            <ProductID>P-4419V-11.1.1.7</ProductID>
            <ProductID>P-4419V-11.1.2.1</ProductID>
            <ProductID>P-4419V-11.1.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="72" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6577</Title>
      <Notes>
         <Note Audience="All" Ordinal="72" Title="Details" Type="Details">Vulnerability in the XML Developer's Kit for C component of Oracle Database Server.  This vulnerability requires Valid account privileges for a successful attack.  Supported versions that are affected are 11.2.0.3, 11.2.0.4, 12.1.0.1 and  12.1.0.2. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to any arbitrary Operating System location.   Note: The CVSS score is 6.8 only on Windows for Database versions prior to 12&lt;i&gt;c&lt;/i&gt;. The CVSS is 4.0 (Confidentiality is "Partial+") for Database 12&lt;i&gt;c&lt;/i&gt; on Windows and for all versions of Database on Linux, Unix and other platforms. CVSS Base Score 6.8 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:C/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:C/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6577</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1068V-11.2.0.3</ProductID>
            <ProductID>P-1068V-11.2.0.4</ProductID>
            <ProductID>P-1068V-12.1.0.1</ProductID>
            <ProductID>P-1068V-12.1.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.8</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:C/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1068V-11.2.0.3</ProductID>
            <ProductID>P-1068V-11.2.0.4</ProductID>
            <ProductID>P-1068V-12.1.0.1</ProductID>
            <ProductID>P-1068V-12.1.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="73" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6578</Title>
      <Notes>
         <Note Audience="All" Ordinal="73" Title="Details" Type="Details">Vulnerability in the Workspace Manager component of Oracle Database Server.  This vulnerability requires Create Table, Create Procedure, Execute on SDO_TOPO, Execute on WMSYS.LT privileges for a successful attack.  Supported versions that are affected are 11.1.0.7, 11.2.0.3, 11.2.0.4 and  12.1.0.1. Easily exploitable vulnerability allows successful authenticated network attacks via Oracle Net.  Successful attack of this vulnerability can result in unauthorized takeover of Workspace Manager possibly including arbitrary code execution within the Workspace Manager.  CVSS Base Score 6.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6578</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1105V-11.1.0.7</ProductID>
            <ProductID>P-1105V-11.2.0.3</ProductID>
            <ProductID>P-1105V-11.2.0.4</ProductID>
            <ProductID>P-1105V-12.1.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1105V-11.1.0.7</ProductID>
            <ProductID>P-1105V-11.2.0.3</ProductID>
            <ProductID>P-1105V-11.2.0.4</ProductID>
            <ProductID>P-1105V-12.1.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="74" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6579</Title>
      <Notes>
         <Note Audience="All" Ordinal="74" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker).  Supported versions that are affected are 8.52 and  8.53. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6579</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.52</ProductID>
            <ProductID>P-5085V-8.53</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-5085V-8.52</ProductID>
            <ProductID>P-5085V-8.53</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="75" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6580</Title>
      <Notes>
         <Note Audience="All" Ordinal="75" Title="Details" Type="Details">Vulnerability in the Oracle Reports Developer component of Oracle Fusion Middleware (subcomponent: None).  Supported versions that are affected are 11.1.1.7 and  11.1.2.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Reports Developer accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6580</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-159V-11.1.1.7</ProductID>
            <ProductID>P-159V-11.1.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-159V-11.1.1.7</ProductID>
            <ProductID>P-159V-11.1.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="76" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6581</Title>
      <Notes>
         <Note Audience="All" Ordinal="76" Title="Details" Type="Details">Vulnerability in the Oracle Customer Intelligence component of Oracle E-Business Suite (subcomponent: Extract/Load Programs).  Supported versions that are affected are 11.5.10.2, 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2, 12.1.3, 12.2.2, 12.2.3 and  12.2.4. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Customer Intelligence accessible data as well as  read access to all Oracle Customer Intelligence accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6581</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-390V-11.5.10.2</ProductID>
            <ProductID>P-390V-12.0.4</ProductID>
            <ProductID>P-390V-12.0.5</ProductID>
            <ProductID>P-390V-12.0.6</ProductID>
            <ProductID>P-390V-12.1.1</ProductID>
            <ProductID>P-390V-12.1.2</ProductID>
            <ProductID>P-390V-12.1.3</ProductID>
            <ProductID>P-390V-12.2.2</ProductID>
            <ProductID>P-390V-12.2.3</ProductID>
            <ProductID>P-390V-12.2.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-390V-11.5.10.2</ProductID>
            <ProductID>P-390V-12.0.4</ProductID>
            <ProductID>P-390V-12.0.5</ProductID>
            <ProductID>P-390V-12.0.6</ProductID>
            <ProductID>P-390V-12.1.1</ProductID>
            <ProductID>P-390V-12.1.2</ProductID>
            <ProductID>P-390V-12.1.3</ProductID>
            <ProductID>P-390V-12.2.2</ProductID>
            <ProductID>P-390V-12.2.3</ProductID>
            <ProductID>P-390V-12.2.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="77" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6582</Title>
      <Notes>
         <Note Audience="All" Ordinal="77" Title="Details" Type="Details">Vulnerability in the Oracle HCM Configuration Workbench component of Oracle E-Business Suite (subcomponent: Rapid Implementation).  Supported versions that are affected are 11.5.10.2, 12.0.4, 12.0.5, 12.0.6, 12.1.1,12.1.2, 12.1.3, 12.2.2, 12.2.3 and  12.2.4. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle HCM Configuration Workbench accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6582</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2011V-11.5.10.2</ProductID>
            <ProductID>P-2011V-12.0.4</ProductID>
            <ProductID>P-2011V-12.0.5</ProductID>
            <ProductID>P-2011V-12.0.6</ProductID>
            <ProductID>P-2011V-12.1.1</ProductID>
            <ProductID>P-2011V-12.1.2</ProductID>
            <ProductID>P-2011V-12.1.3</ProductID>
            <ProductID>P-2011V-12.2.2</ProductID>
            <ProductID>P-2011V-12.2.3</ProductID>
            <ProductID>P-2011V-12.2.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-2011V-11.5.10.2</ProductID>
            <ProductID>P-2011V-12.0.4</ProductID>
            <ProductID>P-2011V-12.0.5</ProductID>
            <ProductID>P-2011V-12.0.6</ProductID>
            <ProductID>P-2011V-12.1.1</ProductID>
            <ProductID>P-2011V-12.1.2</ProductID>
            <ProductID>P-2011V-12.1.3</ProductID>
            <ProductID>P-2011V-12.2.2</ProductID>
            <ProductID>P-2011V-12.2.3</ProductID>
            <ProductID>P-2011V-12.2.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="78" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6583</Title>
      <Notes>
         <Note Audience="All" Ordinal="78" Title="Details" Type="Details">Vulnerability in the Oracle Marketing component of Oracle E-Business Suite (subcomponent: Audience).  Supported versions that are affected are 11.5.10.2, 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2 and  12.1.3.. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Marketing accessible data as well as  read access to all Oracle Marketing accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6583</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-229V-11.5.10.2</ProductID>
            <ProductID>P-229V-12.0.4</ProductID>
            <ProductID>P-229V-12.0.5</ProductID>
            <ProductID>P-229V-12.0.6</ProductID>
            <ProductID>P-229V-12.1.1</ProductID>
            <ProductID>P-229V-12.1.2</ProductID>
            <ProductID>P-229V-12.1.3.</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-229V-11.5.10.2</ProductID>
            <ProductID>P-229V-12.0.4</ProductID>
            <ProductID>P-229V-12.0.5</ProductID>
            <ProductID>P-229V-12.0.6</ProductID>
            <ProductID>P-229V-12.1.1</ProductID>
            <ProductID>P-229V-12.1.2</ProductID>
            <ProductID>P-229V-12.1.3.</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="79" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6584</Title>
      <Notes>
         <Note Audience="All" Ordinal="79" Title="Details" Type="Details">Vulnerability in the Integrated Lights Out Manager(ILOM) component of Oracle Sun Systems Products Suite (subcomponent: Backup Restore).   The supported version that is affected is ILOM prior to 3.2.4. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Integrated Lights Out Manager(ILOM) accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6584</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9849V-ILOM prior to 3.2.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9849V-ILOM prior to 3.2.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="80" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6585</Title>
      <Notes>
         <Note Audience="All" Ordinal="80" Title="Details" Type="Details">Vulnerability in the Java SE  component of Oracle Java SE (subcomponent: 2D).  Supported versions that are affected are Java SE 5.0u75, Java SE 6u85, Java SE 7u72 and  Java SE 8u25. Very difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Java SE  accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 2.6 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:H/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6585</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 5.0u75</ProductID>
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.6</BaseScore>
            <Vector>AV:N/AC:H/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-856V-Java SE 5.0u75</ProductID>
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="81" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6586</Title>
      <Notes>
         <Note Audience="All" Ordinal="81" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise HRMS component of Oracle PeopleSoft Products (subcomponent: Time and Labor).   The supported version that is affected is 9.1. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some PeopleSoft Enterprise HRMS accessible data as well as  read access to a subset of PeopleSoft Enterprise HRMS accessible data.  CVSS Base Score 5.5 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6586</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5079V-9.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-5079V-9.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="82" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6587</Title>
      <Notes>
         <Note Audience="All" Ordinal="82" Title="Details" Type="Details">Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries).  Supported versions that are affected are Java SE 6u85, Java SE 7u72 and  Java SE 8u25. Easily exploitable vulnerability requiring logon to Operating System plus additional login/authentication to component or subcomponent.  Successful attack of this vulnerability can escalate attacker privileges resulting in unauthorized  update, insert or delete access to some Java SE accessible data as well as  read access to a subset of Java SE accessible data and ability to cause a partial denial of service (partial DOS) of Java SE.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 4.3 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:S/C:P/I:P/A:P).  Oracle Vector: (AV:L/AC:L/Au:S/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6587</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:L/AC:L/Au:S/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="83" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6588</Title>
      <Notes>
         <Note Audience="All" Ordinal="83" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: VMSVGA device).   The supported version that is affected is VirtualBox prior to 4.3.20. Easily exploitable vulnerability requiring logon to Operating System plus additional login/authentication to component or subcomponent.  Successful attack of this vulnerability can escalate attacker privileges resulting in unauthorized  update, insert or delete access to all Oracle VM VirtualBox accessible data and ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox.   Note: VMSVGA virtual graphics device is not documented and is disabled by default. CVSS Base Score 3.2 (Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:S/C:N/I:P/A:P).  Oracle Vector: (AV:L/AC:L/Au:S/C:N/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6588</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-VirtualBox prior to 4.3.20</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.2</BaseScore>
            <Vector>AV:L/AC:L/Au:S/C:N/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8370V-VirtualBox prior to 4.3.20</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="84" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6589</Title>
      <Notes>
         <Note Audience="All" Ordinal="84" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: VMSVGA device).   The supported version that is affected is VirtualBox prior to 4.3.20. Easily exploitable vulnerability requiring logon to Operating System plus additional login/authentication to component or subcomponent.  Successful attack of this vulnerability can escalate attacker privileges resulting in unauthorized  update, insert or delete access to all Oracle VM VirtualBox accessible data and ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox.   Note: VMSVGA virtual graphics device is not documented and is disabled by default. CVSS Base Score 3.2 (Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:S/C:N/I:P/A:P).  Oracle Vector: (AV:L/AC:L/Au:S/C:N/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6589</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-VirtualBox prior to 4.3.20</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.2</BaseScore>
            <Vector>AV:L/AC:L/Au:S/C:N/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8370V-VirtualBox prior to 4.3.20</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="85" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6590</Title>
      <Notes>
         <Note Audience="All" Ordinal="85" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: VMSVGA device).   The supported version that is affected is VirtualBox prior to 4.3.20. Easily exploitable vulnerability requiring logon to Operating System plus additional login/authentication to component or subcomponent.  Successful attack of this vulnerability can escalate attacker privileges resulting in unauthorized  update, insert or delete access to all Oracle VM VirtualBox accessible data and ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox.   Note: VMSVGA virtual graphics device is not documented and is disabled by default. CVSS Base Score 3.2 (Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:S/C:N/I:P/A:P).  Oracle Vector: (AV:L/AC:L/Au:S/C:N/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6590</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-VirtualBox prior to 4.3.20</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.2</BaseScore>
            <Vector>AV:L/AC:L/Au:S/C:N/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8370V-VirtualBox prior to 4.3.20</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="86" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6591</Title>
      <Notes>
         <Note Audience="All" Ordinal="86" Title="Details" Type="Details">Vulnerability in the Java SE  component of Oracle Java SE (subcomponent: 2D).  Supported versions that are affected are Java SE 5.0u75, Java SE 6u85, Java SE 7u72 and  Java SE 8u25. Very difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Java SE  accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 2.6 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:H/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6591</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 5.0u75</ProductID>
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.6</BaseScore>
            <Vector>AV:N/AC:H/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-856V-Java SE 5.0u75</ProductID>
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="87" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6592</Title>
      <Notes>
         <Note Audience="All" Ordinal="87" Title="Details" Type="Details">Vulnerability in the Oracle OpenSSO component of Oracle Fusion Middleware (subcomponent: SAML).   The supported version that is affected is 8.0 Update 2 Patch 5. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle OpenSSO accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6592</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8520V-8.0 Update 2 Patch 5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8520V-8.0 Update 2 Patch 5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="88" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6593</Title>
      <Notes>
         <Note Audience="All" Ordinal="88" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JSSE).  Supported versions that are affected are Java SE 5.0u75, Java SE 6u85, Java SE 7u72, Java SE 8u25, Java SE Embedded 7u71, Java SE Embedded 8u6, JRockit 27.8.4 and  JRockit 28.3.4. Very difficult to exploit vulnerability allows successful unauthenticated network attacks via SSL/TLS.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java SE, Java SE Embedded, JRockit accessible data as well as  read access to a subset of Java SE, Java SE Embedded, JRockit accessible data.   Note: Applies to client and server deployment of JSSE. CVSS Base Score 4.0 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:H/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6593</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 5.0u75</ProductID>
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u71</ProductID>
            <ProductID>P-856V-Java SE Embedded 8u6</ProductID>
            <ProductID>P-856V-JRockit 27.8.4</ProductID>
            <ProductID>P-856V-JRockit 28.3.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-856V-Java SE 5.0u75</ProductID>
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u71</ProductID>
            <ProductID>P-856V-Java SE Embedded 8u6</ProductID>
            <ProductID>P-856V-JRockit 27.8.4</ProductID>
            <ProductID>P-856V-JRockit 28.3.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="89" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6594</Title>
      <Notes>
         <Note Audience="All" Ordinal="89" Title="Details" Type="Details">Vulnerability in the Oracle iLearning component of Oracle iLearning (subcomponent: Learner Pages).  Supported versions that are affected are 6.0 and  6.1. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle iLearning accessible data.  CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6594</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-902V-6.0</ProductID>
            <ProductID>P-902V-6.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-902V-6.0</ProductID>
            <ProductID>P-902V-6.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="90" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6595</Title>
      <Notes>
         <Note Audience="All" Ordinal="90" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: VMSVGA device).   The supported version that is affected is VirtualBox prior to 4.3.20. Easily exploitable vulnerability requiring logon to Operating System plus additional login/authentication to component or subcomponent.  Successful attack of this vulnerability can escalate attacker privileges resulting in unauthorized  update, insert or delete access to all Oracle VM VirtualBox accessible data and ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox.   Note: VMSVGA virtual graphics device is not documented and is disabled by default. CVSS Base Score 3.2 (Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:S/C:N/I:P/A:P).  Oracle Vector: (AV:L/AC:L/Au:S/C:N/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6595</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-VirtualBox prior to 4.3.20</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.2</BaseScore>
            <Vector>AV:L/AC:L/Au:S/C:N/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8370V-VirtualBox prior to 4.3.20</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="91" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6596</Title>
      <Notes>
         <Note Audience="All" Ordinal="91" Title="Details" Type="Details">Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: Portal Framework).  Supported versions that are affected are 8.1.1 and  8.2.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Siebel UI Framework accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6596</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="92" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6597</Title>
      <Notes>
         <Note Audience="All" Ordinal="92" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: PIA Core Technology).  Supported versions that are affected are 8.52, 8.53 and  8.54. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 4.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6597</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.52</ProductID>
            <ProductID>P-5085V-8.53</ProductID>
            <ProductID>P-5085V-8.54</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-5085V-8.52</ProductID>
            <ProductID>P-5085V-8.53</ProductID>
            <ProductID>P-5085V-8.54</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="93" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6598</Title>
      <Notes>
         <Note Audience="All" Ordinal="93" Title="Details" Type="Details">Vulnerability in the Oracle Communications Diameter Signaling Router component of Oracle Communications Applications (subcomponent: Signaling - DPI).  Supported versions that are affected are 3.x, 4.x and  5.0. Very difficult to exploit vulnerability allows successful unauthenticated network attacks via Diameter.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.  CVSS Base Score 7.6 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:H/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6598</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10899V-3.x</ProductID>
            <ProductID>P-10899V-4.x</ProductID>
            <ProductID>P-10899V-5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.6</BaseScore>
            <Vector>AV:N/AC:H/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-10899V-3.x</ProductID>
            <ProductID>P-10899V-4.x</ProductID>
            <ProductID>P-10899V-5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="94" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6599</Title>
      <Notes>
         <Note Audience="All" Ordinal="94" Title="Details" Type="Details">Vulnerability in the Siebel Core - Common Components component of Oracle Siebel CRM (subcomponent: Email).  Supported versions that are affected are 8.1.1 and  8.2.2. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Siebel Core - Common Components accessible data.  CVSS Base Score 3.5 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6599</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9747V-8.1.1</ProductID>
            <ProductID>P-9747V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9747V-8.1.1</ProductID>
            <ProductID>P-9747V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="95" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6600</Title>
      <Notes>
         <Note Audience="All" Ordinal="95" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: File System).   The supported version that is affected is 11. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 4.9 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6600</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.9</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="96" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-6601</Title>
      <Notes>
         <Note Audience="All" Ordinal="96" Title="Details" Type="Details">Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Hotspot).  Supported versions that are affected are Java SE 6u85, Java SE 7u72 and  Java SE 8u25. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-6601</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="97" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0362</Title>
      <Notes>
         <Note Audience="All" Ordinal="97" Title="Details" Type="Details">Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security).   The supported version that is affected is 11.1.1.7. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of BI Publisher (formerly XML Publisher) accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0362</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1479V-11.1.1.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1479V-11.1.1.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="98" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0363</Title>
      <Notes>
         <Note Audience="All" Ordinal="98" Title="Details" Type="Details">Vulnerability in the Siebel Core EAI component of Oracle Siebel CRM (subcomponent: Integration Business Services).  Supported versions that are affected are 8.1.1 and  8.2.2. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel Core EAI.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0363</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9021V-8.1.1</ProductID>
            <ProductID>P-9021V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9021V-8.1.1</ProductID>
            <ProductID>P-9021V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="99" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0364</Title>
      <Notes>
         <Note Audience="All" Ordinal="99" Title="Details" Type="Details">Vulnerability in the Siebel Core - EAI component of Oracle Siebel CRM (subcomponent: Integration Business Services).  Supported versions that are affected are 8.1.1 and  8.2.2. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel Core - EAI.  CVSS Base Score 3.5 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0364</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9021V-8.1.1</ProductID>
            <ProductID>P-9021V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9021V-8.1.1</ProductID>
            <ProductID>P-9021V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="100" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0365</Title>
      <Notes>
         <Note Audience="All" Ordinal="100" Title="Details" Type="Details">Vulnerability in the Siebel Core - Server Infrastructure component of Oracle Siebel CRM (subcomponent: Security).  Supported versions that are affected are 8.1.1 and  8.2.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Siebel Core - Server Infrastructure accessible data.  CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0365</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9004V-8.1.1</ProductID>
            <ProductID>P-9004V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9004V-8.1.1</ProductID>
            <ProductID>P-9004V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="101" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0366</Title>
      <Notes>
         <Note Audience="All" Ordinal="101" Title="Details" Type="Details">Vulnerability in the Siebel Core - EAI component of Oracle Siebel CRM (subcomponent: Java Integration).  Supported versions that are affected are 8.1.1 and  8.2.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Siebel Core - EAI accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0366</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9021V-8.1.1</ProductID>
            <ProductID>P-9021V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9021V-8.1.1</ProductID>
            <ProductID>P-9021V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="102" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0367</Title>
      <Notes>
         <Note Audience="All" Ordinal="102" Title="Details" Type="Details">Vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware (subcomponent: SSO Engine).  Supported versions that are affected are 11.1.1.5, 11.1.1.7, 11.1.2.1 and  11.1.2.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Access Manager accessible data.   Note: Please refer to &lt;a href="https://support.oracle.com/CSP/main/article?cmd=show&amp;amp;type=NOT&amp;amp;id=1952939.1"&gt;My Oracle Support Note 1952939.1&lt;/a&gt; for instructions on how to address this issue. CVSS Base Score 5.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0367</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5565V-11.1.1.5</ProductID>
            <ProductID>P-5565V-11.1.1.7</ProductID>
            <ProductID>P-5565V-11.1.2.1</ProductID>
            <ProductID>P-5565V-11.1.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-5565V-11.1.1.5</ProductID>
            <ProductID>P-5565V-11.1.1.7</ProductID>
            <ProductID>P-5565V-11.1.2.1</ProductID>
            <ProductID>P-5565V-11.1.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="103" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0368</Title>
      <Notes>
         <Note Audience="All" Ordinal="103" Title="Details" Type="Details">Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suite (subcomponent: Security).  Supported versions that are affected are 6.1, 6.2, 6.3, 6.3.1, 6.3.2, 6.3.3, 6.3.4 and  6.3.5. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Transportation Management.  CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0368</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1991V-6.1</ProductID>
            <ProductID>P-1991V-6.2</ProductID>
            <ProductID>P-1991V-6.3</ProductID>
            <ProductID>P-1991V-6.3.1</ProductID>
            <ProductID>P-1991V-6.3.2</ProductID>
            <ProductID>P-1991V-6.3.3</ProductID>
            <ProductID>P-1991V-6.3.4</ProductID>
            <ProductID>P-1991V-6.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1991V-6.1</ProductID>
            <ProductID>P-1991V-6.2</ProductID>
            <ProductID>P-1991V-6.3</ProductID>
            <ProductID>P-1991V-6.3.1</ProductID>
            <ProductID>P-1991V-6.3.2</ProductID>
            <ProductID>P-1991V-6.3.3</ProductID>
            <ProductID>P-1991V-6.3.4</ProductID>
            <ProductID>P-1991V-6.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="104" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0369</Title>
      <Notes>
         <Note Audience="All" Ordinal="104" Title="Details" Type="Details">Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: AX/HI Web UI).  Supported versions that are affected are 8.1.1 and  8.2.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Siebel UI Framework accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0369</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="105" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0370</Title>
      <Notes>
         <Note Audience="All" Ordinal="105" Title="Details" Type="Details">Vulnerability in the Core RDBMS component of Oracle Database Server.  This vulnerability requires Create Session privileges for a successful attack.  Supported versions that are affected are 11.1.0.7, 11.2.0.3, 11.2.0.4 and 12.1.0.1. Difficult to exploit vulnerability allows successful authenticated network attacks via Oracle Net.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Core RDBMS accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0370</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11V-11.1.0.7</ProductID>
            <ProductID>P-11V-11.2.0.3</ProductID>
            <ProductID>P-11V-11.2.0.4</ProductID>
            <ProductID>P-11V-12.1.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-11V-11.1.0.7</ProductID>
            <ProductID>P-11V-11.2.0.3</ProductID>
            <ProductID>P-11V-11.2.0.4</ProductID>
            <ProductID>P-11V-12.1.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="106" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0371</Title>
      <Notes>
         <Note Audience="All" Ordinal="106" Title="Details" Type="Details">Vulnerability in the Core RDBMS component of Oracle Database Server.  This vulnerability requires Create Session, Create Table privileges for a successful attack.  Supported versions that are affected are 11.1.0.7, 11.2.0.3, 11.2.0.4 and 12.1.0.1. Difficult to exploit vulnerability allows successful authenticated network attacks via Oracle Net.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Core RDBMS accessible data and ability to cause a partial denial of service (partial DOS) of Core RDBMS.  CVSS Base Score 4.9 (Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:P).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P+/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0371</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11V-11.1.0.7</ProductID>
            <ProductID>P-11V-11.2.0.3</ProductID>
            <ProductID>P-11V-11.2.0.4</ProductID>
            <ProductID>P-11V-12.1.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.9</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-11V-11.1.0.7</ProductID>
            <ProductID>P-11V-11.2.0.3</ProductID>
            <ProductID>P-11V-11.2.0.4</ProductID>
            <ProductID>P-11V-12.1.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="107" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0372</Title>
      <Notes>
         <Note Audience="All" Ordinal="107" Title="Details" Type="Details">Vulnerability in the Oracle Containers for J2EE component of Oracle Fusion Middleware (subcomponent: None).   The supported version that is affected is 10.1.3.5. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to all Oracle Containers for J2EE accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0372</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1270V-10.1.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1270V-10.1.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="108" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0373</Title>
      <Notes>
         <Note Audience="All" Ordinal="108" Title="Details" Type="Details">Vulnerability in the OJVM component of Oracle Database Server.  This vulnerability requires Create Session privileges for a successful attack.  Supported versions that are affected are 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1 and  12.1.0.2. Easily exploitable vulnerability allows successful authenticated network attacks via Oracle Net.  Successful attack of this vulnerability can result in unauthorized takeover of OJVM possibly including arbitrary code execution within the OJVM.   Note: This brings the OJVM component of Database in line with Java SE security fixes delivered as of January CPU 2015. CVSS Base Score 6.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0373</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-11.1.0.7</ProductID>
            <ProductID>P-5V-11.2.0.3</ProductID>
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.1</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-5V-11.1.0.7</ProductID>
            <ProductID>P-5V-11.2.0.3</ProductID>
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.1</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="109" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0374</Title>
      <Notes>
         <Note Audience="All" Ordinal="109" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Security : Privileges : Foreign Key).  Supported versions that are affected are 5.5.40 and earlier and  5.6.21 and earlier. Difficult to exploit vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of MySQL Server accessible data.  CVSS Base Score 3.5 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0374</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.40 and earlier</ProductID>
            <ProductID>P-8478V-5.6.21 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8478V-5.5.40 and earlier</ProductID>
            <ProductID>P-8478V-5.6.21 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="110" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0375</Title>
      <Notes>
         <Note Audience="All" Ordinal="110" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Network).  Supported versions that are affected are 10 and  11. Easily exploitable vulnerability allows successful unauthenticated network attacks via TCP/IP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Solaris accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0375</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-10</ProductID>
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-10006V-10</ProductID>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="111" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0376</Title>
      <Notes>
         <Note Audience="All" Ordinal="111" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Content component of Oracle Fusion Middleware (subcomponent: Content Server).   The supported version that is affected is 11.1.1.8.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle WebCenter Content accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0376</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2271V-11.1.1.8.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-2271V-11.1.1.8.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="112" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0377</Title>
      <Notes>
         <Note Audience="All" Ordinal="112" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core).  Supported versions that are affected are VirtualBox prior to 3.2.26, 4.0.28, 4.1.36 and  4.2.28. Difficult to exploit vulnerability requiring logon to Operating System plus additional login/authentication to component or subcomponent.  Successful attack of this vulnerability can escalate attacker privileges resulting in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 4.4 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:S/C:N/I:N/A:C).  Oracle Vector: (AV:L/AC:M/Au:S/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0377</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-VirtualBox prior to 3.2.26</ProductID>
            <ProductID>P-8370V-4.0.28</ProductID>
            <ProductID>P-8370V-4.1.36</ProductID>
            <ProductID>P-8370V-4.2.28</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.4</BaseScore>
            <Vector>AV:L/AC:M/Au:S/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8370V-VirtualBox prior to 3.2.26</ProductID>
            <ProductID>P-8370V-4.0.28</ProductID>
            <ProductID>P-8370V-4.1.36</ProductID>
            <ProductID>P-8370V-4.2.28</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="113" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0378</Title>
      <Notes>
         <Note Audience="All" Ordinal="113" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Libc).   The supported version that is affected is 11. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Solaris.  CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0378</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="114" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0379</Title>
      <Notes>
         <Note Audience="All" Ordinal="114" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: PIA Core Technology).   The supported version that is affected is 8.54. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0379</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.54</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-5085V-8.54</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="115" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0380</Title>
      <Notes>
         <Note Audience="All" Ordinal="115" Title="Details" Type="Details">Vulnerability in the Oracle Telecommunications Billing Integrator component of Oracle E-Business Suite (subcomponent: OA Based UI for Bill Summary).  Supported versions that are affected are 11.5.10.2, 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2, 12.1.3, 12.2.2, 12.2.3 and  12.2.4. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Telecommunications Billing Integrator accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0380</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1300V-11.5.10.2</ProductID>
            <ProductID>P-1300V-12.0.4</ProductID>
            <ProductID>P-1300V-12.0.5</ProductID>
            <ProductID>P-1300V-12.0.6</ProductID>
            <ProductID>P-1300V-12.1.1</ProductID>
            <ProductID>P-1300V-12.1.2</ProductID>
            <ProductID>P-1300V-12.1.3</ProductID>
            <ProductID>P-1300V-12.2.2</ProductID>
            <ProductID>P-1300V-12.2.3</ProductID>
            <ProductID>P-1300V-12.2.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1300V-11.5.10.2</ProductID>
            <ProductID>P-1300V-12.0.4</ProductID>
            <ProductID>P-1300V-12.0.5</ProductID>
            <ProductID>P-1300V-12.0.6</ProductID>
            <ProductID>P-1300V-12.1.1</ProductID>
            <ProductID>P-1300V-12.1.2</ProductID>
            <ProductID>P-1300V-12.1.3</ProductID>
            <ProductID>P-1300V-12.2.2</ProductID>
            <ProductID>P-1300V-12.2.3</ProductID>
            <ProductID>P-1300V-12.2.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="116" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0381</Title>
      <Notes>
         <Note Audience="All" Ordinal="116" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Replication).  Supported versions that are affected are 5.5.40 and earlier and  5.6.21 and earlier. Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.3 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0381</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.40 and earlier</ProductID>
            <ProductID>P-8478V-5.6.21 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8478V-5.5.40 and earlier</ProductID>
            <ProductID>P-8478V-5.6.21 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="117" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0382</Title>
      <Notes>
         <Note Audience="All" Ordinal="117" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Replication).  Supported versions that are affected are 5.5.40 and earlier and  5.6.21 and earlier. Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.3 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0382</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.40 and earlier</ProductID>
            <ProductID>P-8478V-5.6.21 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8478V-5.5.40 and earlier</ProductID>
            <ProductID>P-8478V-5.6.21 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="118" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0383</Title>
      <Notes>
         <Note Audience="All" Ordinal="118" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Hotspot).  Supported versions that are affected are Java SE 5.0u75, Java SE 6u85, Java SE 7u72, Java SE 8u25, Java SE Embedded 7u71, Java SE Embedded 8u6, JRockit R27.8.4 and  JRockit R28.3.4. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS) as well as  update, insert or delete access to some Java SE, Java SE Embedded, JRockit accessible data.   Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS Base Score 5.4 (Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:N/I:P/A:C).  Oracle Vector: (AV:L/AC:M/Au:N/C:N/I:P/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0383</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 5.0u75</ProductID>
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u71</ProductID>
            <ProductID>P-856V-Java SE Embedded 8u6</ProductID>
            <ProductID>P-856V-JRockit R27.8.4</ProductID>
            <ProductID>P-856V-JRockit R28.3.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.4</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:N/I:P/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-856V-Java SE 5.0u75</ProductID>
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u71</ProductID>
            <ProductID>P-856V-Java SE Embedded 8u6</ProductID>
            <ProductID>P-856V-JRockit R27.8.4</ProductID>
            <ProductID>P-856V-JRockit R28.3.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="119" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0384</Title>
      <Notes>
         <Note Audience="All" Ordinal="119" Title="Details" Type="Details">Vulnerability in the Siebel Public Sector component of Oracle Siebel CRM (subcomponent: Public Sector Portal).  Supported versions that are affected are 8.1.1 and  8.2.2. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Siebel Public Sector accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0384</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9165V-8.1.1</ProductID>
            <ProductID>P-9165V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9165V-8.1.1</ProductID>
            <ProductID>P-9165V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="120" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0385</Title>
      <Notes>
         <Note Audience="All" Ordinal="120" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Pluggable Auth).  Supported versions that are affected are 5.6.21 and earlier. Difficult to exploit vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 3.5 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0385</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.21 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8478V-5.6.21 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="121" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0386</Title>
      <Notes>
         <Note Audience="All" Ordinal="121" Title="Details" Type="Details">Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: Web Listener).  Supported versions that are affected are 11.1.1.7.0, 12.1.2.0 and  12.1.3.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HTTP Server.  CVSS Base Score 4.3 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0386</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1042V-11.1.1.7.0</ProductID>
            <ProductID>P-1042V-12.1.2.0</ProductID>
            <ProductID>P-1042V-12.1.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1042V-11.1.1.7.0</ProductID>
            <ProductID>P-1042V-12.1.2.0</ProductID>
            <ProductID>P-1042V-12.1.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="122" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0387</Title>
      <Notes>
         <Note Audience="All" Ordinal="122" Title="Details" Type="Details">Vulnerability in the Siebel Core - Server OM Services component of Oracle Siebel CRM (subcomponent: Security - LDAP Security Adapter).  Supported versions that are affected are 8.1.1 and  8.2.2. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Siebel Core - Server OM Services accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0387</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9006V-8.1.1</ProductID>
            <ProductID>P-9006V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9006V-8.1.1</ProductID>
            <ProductID>P-9006V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="123" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0388</Title>
      <Notes>
         <Note Audience="All" Ordinal="123" Title="Details" Type="Details">Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: Portal Framework).  Supported versions that are affected are 8.1.1 and  8.2.2. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Siebel UI Framework accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0388</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="124" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0389</Title>
      <Notes>
         <Note Audience="All" Ordinal="124" Title="Details" Type="Details">Vulnerability in the Oracle OpenSSO component of Oracle Fusion Middleware (subcomponent: SAML).   The supported version that is affected is 8.0 Update 2 Patch 5. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle OpenSSO accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0389</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8520V-8.0 Update 2 Patch 5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8520V-8.0 Update 2 Patch 5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="125" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0390</Title>
      <Notes>
         <Note Audience="All" Ordinal="125" Title="Details" Type="Details">Vulnerability in the MICROS Retail component of Oracle Retail Applications (subcomponent: Xstore Point of Sale).  Supported versions that are affected are Xstore: 3.2.1, 3.4.2, 3.5.0, 4.0.1, 4.5.1, 4.8.0, 5.0.3, 5.5.3, 6.0.6 and  6.5.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via Proprietary XML.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some MICROS Retail accessible data as well as  read access to a subset of MICROS Retail accessible data and ability to cause a partial denial of service (partial DOS) of MICROS Retail.  CVSS Base Score 6.8 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0390</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11435V-Xstore: 3.2.1</ProductID>
            <ProductID>P-11435V-3.4.2</ProductID>
            <ProductID>P-11435V-3.5.0</ProductID>
            <ProductID>P-11435V-4.0.1</ProductID>
            <ProductID>P-11435V-4.5.1</ProductID>
            <ProductID>P-11435V-4.8.0</ProductID>
            <ProductID>P-11435V-5.0.3</ProductID>
            <ProductID>P-11435V-5.5.3</ProductID>
            <ProductID>P-11435V-6.0.6</ProductID>
            <ProductID>P-11435V-6.5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-11435V-Xstore: 3.2.1</ProductID>
            <ProductID>P-11435V-3.4.2</ProductID>
            <ProductID>P-11435V-3.5.0</ProductID>
            <ProductID>P-11435V-4.0.1</ProductID>
            <ProductID>P-11435V-4.5.1</ProductID>
            <ProductID>P-11435V-4.8.0</ProductID>
            <ProductID>P-11435V-5.0.3</ProductID>
            <ProductID>P-11435V-5.5.3</ProductID>
            <ProductID>P-11435V-6.0.6</ProductID>
            <ProductID>P-11435V-6.5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="126" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0391</Title>
      <Notes>
         <Note Audience="All" Ordinal="126" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : DDL).  Supported versions that are affected are 5.5.38 and earlier and  5.6.19 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0391</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.38 and earlier</ProductID>
            <ProductID>P-8478V-5.6.19 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8478V-5.5.38 and earlier</ProductID>
            <ProductID>P-8478V-5.6.19 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="127" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0392</Title>
      <Notes>
         <Note Audience="All" Ordinal="127" Title="Details" Type="Details">Vulnerability in the Siebel Core - Server BizLogic Script component of Oracle Siebel CRM (subcomponent: Config - Scripting).  Supported versions that are affected are 8.1.1 and  8.2.2. Very difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Siebel Core - Server BizLogic Script accessible data as well as  read access to a subset of Siebel Core - Server BizLogic Script accessible data and ability to cause a partial denial of service (partial DOS) of Siebel Core - Server BizLogic Script.  CVSS Base Score 4.6 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:S/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:H/Au:S/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0392</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9001V-8.1.1</ProductID>
            <ProductID>P-9001V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.6</BaseScore>
            <Vector>AV:N/AC:H/Au:S/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9001V-8.1.1</ProductID>
            <ProductID>P-9001V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="128" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0393</Title>
      <Notes>
         <Note Audience="All" Ordinal="128" Title="Details" Type="Details">Vulnerability in the Oracle Applications DBA component of Oracle E-Business Suite (subcomponent: DB Privileges).  Supported versions that are affected are 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, 12.2.3 and  12.2.4. Difficult to exploit vulnerability allows successful authenticated network attacks via Oracle Net.  Successful attack of this vulnerability can result in unauthorized takeover of Oracle Applications DBA possibly including arbitrary code execution within the Oracle Applications DBA.  CVSS Base Score 6.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:M/Au:S/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0393</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-166V-11.5.10.2</ProductID>
            <ProductID>P-166V-12.0.6</ProductID>
            <ProductID>P-166V-12.1.3</ProductID>
            <ProductID>P-166V-12.2.2</ProductID>
            <ProductID>P-166V-12.2.3</ProductID>
            <ProductID>P-166V-12.2.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.0</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-166V-11.5.10.2</ProductID>
            <ProductID>P-166V-12.0.6</ProductID>
            <ProductID>P-166V-12.1.3</ProductID>
            <ProductID>P-166V-12.2.2</ProductID>
            <ProductID>P-166V-12.2.3</ProductID>
            <ProductID>P-166V-12.2.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="129" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0394</Title>
      <Notes>
         <Note Audience="All" Ordinal="129" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Report Distribution).  Supported versions that are affected are 8.52 and  8.53. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0394</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.52</ProductID>
            <ProductID>P-5085V-8.53</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-5085V-8.52</ProductID>
            <ProductID>P-5085V-8.53</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="130" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0395</Title>
      <Notes>
         <Note Audience="All" Ordinal="130" Title="Details" Type="Details">Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Hotspot).  Supported versions that are affected are Java SE 5.0u75, Java SE 6u85, Java SE 7u72 and  Java SE 8u25. Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 9.3 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0395</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 5.0u75</ProductID>
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>9.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-856V-Java SE 5.0u75</ProductID>
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="131" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0396</Title>
      <Notes>
         <Note Audience="All" Ordinal="131" Title="Details" Type="Details">Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Admin Console).  Supported versions that are affected are 3.0.1 and  3.1.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle GlassFish Server accessible data as well as  read access to a subset of Oracle GlassFish Server accessible data and ability to cause a partial denial of service (partial DOS) of Oracle GlassFish Server.  CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0396</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8493V-3.0.1</ProductID>
            <ProductID>P-8493V-3.1.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8493V-3.0.1</ProductID>
            <ProductID>P-8493V-3.1.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="132" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0397</Title>
      <Notes>
         <Note Audience="All" Ordinal="132" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: File System).   The supported version that is affected is 11. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Solaris.  CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0397</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="133" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0398</Title>
      <Notes>
         <Note Audience="All" Ordinal="133" Title="Details" Type="Details">Vulnerability in the Siebel Life Sciences component of Oracle Siebel CRM (subcomponent: Clinical Trip Report).  Supported versions that are affected are 8.1.1 and  8.2.2. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Siebel Life Sciences accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0398</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9173V-8.1.1</ProductID>
            <ProductID>P-9173V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9173V-8.1.1</ProductID>
            <ProductID>P-9173V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="134" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0399</Title>
      <Notes>
         <Note Audience="All" Ordinal="134" Title="Details" Type="Details">Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Analytics Web General).  Supported versions that are affected are 10.1.3.4.2 and  11.1.1.7. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0399</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2025V-10.1.3.4.2</ProductID>
            <ProductID>P-2025V-11.1.1.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-2025V-10.1.3.4.2</ProductID>
            <ProductID>P-2025V-11.1.1.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="135" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0400</Title>
      <Notes>
         <Note Audience="All" Ordinal="135" Title="Details" Type="Details">Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries).  Supported versions that are affected are Java SE 6u85, Java SE 7u72 and  Java SE 8u25. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Java SE accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0400</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="136" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0401</Title>
      <Notes>
         <Note Audience="All" Ordinal="136" Title="Details" Type="Details">Vulnerability in the Oracle Directory Server Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Admin Console).  Supported versions that are affected are 7.0 and 11.1.1.7. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Directory Server Enterprise Edition accessible data.  CVSS Base Score 4.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0401</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8512V-7.0</ProductID>
            <ProductID>P-8512V-11.1.1.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8512V-7.0</ProductID>
            <ProductID>P-8512V-11.1.1.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="137" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0402</Title>
      <Notes>
         <Note Audience="All" Ordinal="137" Title="Details" Type="Details">Vulnerability in the Siebel Core - Server BizLogic Script component of Oracle Siebel CRM (subcomponent: Integration - COM).  Supported versions that are affected are 8.1.1 and  8.2.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Siebel Core - Server BizLogic Script accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0402</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9001V-8.1.1</ProductID>
            <ProductID>P-9001V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9001V-8.1.1</ProductID>
            <ProductID>P-9001V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="138" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0403</Title>
      <Notes>
         <Note Audience="All" Ordinal="138" Title="Details" Type="Details">Vulnerability in the Java SE  component of Oracle Java SE (subcomponent: Deployment).  Supported versions that are affected are Java SE 6u85, Java SE 7u72 and  Java SE 8u25. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 6.9 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:L/AC:M/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0403</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.9</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="139" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0404</Title>
      <Notes>
         <Note Audience="All" Ordinal="139" Title="Details" Type="Details">Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: Error Messages).  Supported versions that are affected are 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, 12.2.3 and  12.2.4. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Applications Framework accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0404</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1472V-11.5.10.2</ProductID>
            <ProductID>P-1472V-12.0.6</ProductID>
            <ProductID>P-1472V-12.1.3</ProductID>
            <ProductID>P-1472V-12.2.2</ProductID>
            <ProductID>P-1472V-12.2.3</ProductID>
            <ProductID>P-1472V-12.2.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1472V-11.5.10.2</ProductID>
            <ProductID>P-1472V-12.0.6</ProductID>
            <ProductID>P-1472V-12.1.3</ProductID>
            <ProductID>P-1472V-12.2.2</ProductID>
            <ProductID>P-1472V-12.2.3</ProductID>
            <ProductID>P-1472V-12.2.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="140" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0406</Title>
      <Notes>
         <Note Audience="All" Ordinal="140" Title="Details" Type="Details">Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment).  Supported versions that are affected are Java SE 6u85, Java SE 7u72 and  Java SE 8u25. Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Java SE accessible data and ability to cause a partial denial of service (partial DOS) of Java SE.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 5.8 (Confidentiality and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0406</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="141" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0407</Title>
      <Notes>
         <Note Audience="All" Ordinal="141" Title="Details" Type="Details">Vulnerability in the Java SE  component of Oracle Java SE (subcomponent: Swing).  Supported versions that are affected are Java SE 5.0u75, Java SE 6u85, Java SE 7u72 and  Java SE 8u25. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Java SE  accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0407</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 5.0u75</ProductID>
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-856V-Java SE 5.0u75</ProductID>
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="142" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0408</Title>
      <Notes>
         <Note Audience="All" Ordinal="142" Title="Details" Type="Details">Vulnerability in the Java SE component of Oracle Java SE (subcomponent: RMI).  Supported versions that are affected are Java SE 5.0u75, Java SE 6u85, Java SE 7u72 and  Java SE 8u25. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0408</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 5.0u75</ProductID>
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-856V-Java SE 5.0u75</ProductID>
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="143" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0409</Title>
      <Notes>
         <Note Audience="All" Ordinal="143" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Optimizer).  Supported versions that are affected are 5.6.21 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0409</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.21 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8478V-5.6.21 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="144" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0410</Title>
      <Notes>
         <Note Audience="All" Ordinal="144" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security).  Supported versions that are affected are Java SE 5.0u75, Java SE 6u85, Java SE 7u72, Java SE 8u25, Java SE Embedded 7u71, Java SE Embedded 8u6, JRockit R27.8.4 and  JRockit R28.3.4. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit.   Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0410</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 5.0u75</ProductID>
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u71</ProductID>
            <ProductID>P-856V-Java SE Embedded 8u6</ProductID>
            <ProductID>P-856V-JRockit R27.8.4</ProductID>
            <ProductID>P-856V-JRockit R28.3.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-856V-Java SE 5.0u75</ProductID>
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u71</ProductID>
            <ProductID>P-856V-Java SE Embedded 8u6</ProductID>
            <ProductID>P-856V-JRockit R27.8.4</ProductID>
            <ProductID>P-856V-JRockit R28.3.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="145" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0411</Title>
      <Notes>
         <Note Audience="All" Ordinal="145" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Security : Encryption).  Supported versions that are affected are 5.5.40 and earlier and  5.6.21 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some MySQL Server accessible data as well as  read access to a subset of MySQL Server accessible data and ability to cause a partial denial of service (partial DOS) of MySQL Server.  CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0411</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.40 and earlier</ProductID>
            <ProductID>P-8478V-5.6.21 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8478V-5.5.40 and earlier</ProductID>
            <ProductID>P-8478V-5.6.21 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="146" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0412</Title>
      <Notes>
         <Note Audience="All" Ordinal="146" Title="Details" Type="Details">Vulnerability in the Java SE  component of Oracle Java SE (subcomponent: JAX-WS).  Supported versions that are affected are Java SE 6u85, Java SE 7u72 and  Java SE 8u25. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0412</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-856V-Java SE 6u85</ProductID>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="147" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0413</Title>
      <Notes>
         <Note Audience="All" Ordinal="147" Title="Details" Type="Details">Vulnerability in the Java SE  component of Oracle Java SE (subcomponent: Serviceability ).  Supported versions that are affected are Java SE 7u72 and  Java SE 8u25. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java SE  accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 1.9 (Integrity impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:L/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0413</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>1.9</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-856V-Java SE 7u72</ProductID>
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="148" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0414</Title>
      <Notes>
         <Note Audience="All" Ordinal="148" Title="Details" Type="Details">Vulnerability in the Oracle SOA Suite component of Oracle Fusion Middleware (subcomponent: Fabric Layer).  Supported versions that are affected are 11.1.1.7 and 12.1.3.0. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to all Oracle SOA Suite accessible data.  CVSS Base Score 3.5 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:P+/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0414</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1162V-11.1.1.7</ProductID>
            <ProductID>P-1162V-12.1.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1162V-11.1.1.7</ProductID>
            <ProductID>P-1162V-12.1.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="149" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0415</Title>
      <Notes>
         <Note Audience="All" Ordinal="149" Title="Details" Type="Details">Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Session 
Management).   The supported version that is affected is 12.1.3. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Application Object Library accessible data.  CVSS Base Score 4.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0415</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-510V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-510V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="150" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0416</Title>
      <Notes>
         <Note Audience="All" Ordinal="150" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Roles &amp; Privileges).   The supported version that is affected is 9.3.3. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Agile PLM accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0416</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4429V-9.3.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-4429V-9.3.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="151" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0417</Title>
      <Notes>
         <Note Audience="All" Ordinal="151" Title="Details" Type="Details">Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: Portal Framework).  Supported versions that are affected are 8.1.1 and  8.2.2. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Siebel UI Framework accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0417</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="152" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0418</Title>
      <Notes>
         <Note Audience="All" Ordinal="152" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core).  Supported versions that are affected are VirtualBox prior to 3.2.26, 4.0.28, 4.1.36 and  4.2.28. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox.  CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0418</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-VirtualBox prior to 3.2.26</ProductID>
            <ProductID>P-8370V-4.0.28</ProductID>
            <ProductID>P-8370V-4.1.36</ProductID>
            <ProductID>P-8370V-4.2.28</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8370V-VirtualBox prior to 3.2.26</ProductID>
            <ProductID>P-8370V-4.0.28</ProductID>
            <ProductID>P-8370V-4.1.36</ProductID>
            <ProductID>P-8370V-4.2.28</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="153" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0419</Title>
      <Notes>
         <Note Audience="All" Ordinal="153" Title="Details" Type="Details">Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: Portal Framework).  Supported versions that are affected are 8.1.1 and  8.2.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Siebel UI Framework accessible data.  CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0419</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="154" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0420</Title>
      <Notes>
         <Note Audience="All" Ordinal="154" Title="Details" Type="Details">Vulnerability in the Oracle Forms component of Oracle Fusion Middleware (subcomponent: Forms Services).  Supported versions that are affected are 11.1.1.7 and  11.1.2.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Forms accessible data.  CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0420</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-45V-11.1.1.7</ProductID>
            <ProductID>P-45V-11.1.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-45V-11.1.1.7</ProductID>
            <ProductID>P-45V-11.1.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="155" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0421</Title>
      <Notes>
         <Note Audience="All" Ordinal="155" Title="Details" Type="Details">Vulnerability in the Java SE  component of Oracle Java SE (subcomponent: Install).   The supported version that is affected is Java SE 8u25. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to installation process on client deployment of Java. CVSS Base Score 6.9 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:L/AC:M/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0421</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.9</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="156" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0422</Title>
      <Notes>
         <Note Audience="All" Ordinal="156" Title="Details" Type="Details">Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suite (subcomponent: UI Infrastructure).  Supported versions that are affected are 6.1, 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4 and  6.3.5. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Transportation Management accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0422</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1991V-6.1</ProductID>
            <ProductID>P-1991V-6.2</ProductID>
            <ProductID>P-1991V-6.3.0</ProductID>
            <ProductID>P-1991V-6.3.1</ProductID>
            <ProductID>P-1991V-6.3.2</ProductID>
            <ProductID>P-1991V-6.3.3</ProductID>
            <ProductID>P-1991V-6.3.4</ProductID>
            <ProductID>P-1991V-6.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1991V-6.1</ProductID>
            <ProductID>P-1991V-6.2</ProductID>
            <ProductID>P-1991V-6.3.0</ProductID>
            <ProductID>P-1991V-6.3.1</ProductID>
            <ProductID>P-1991V-6.3.2</ProductID>
            <ProductID>P-1991V-6.3.3</ProductID>
            <ProductID>P-1991V-6.3.4</ProductID>
            <ProductID>P-1991V-6.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="157" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0424</Title>
      <Notes>
         <Note Audience="All" Ordinal="157" Title="Details" Type="Details">Vulnerability in the Integrated Lights Out Manager(ILOM) component of Oracle Sun Systems Products Suite (subcomponent: IPMI).   The supported version that is affected is ILOM prior to 3.2.4. Difficult to exploit vulnerability allows successful authenticated network attacks via SSL/TLS.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS) as well as  update, insert or delete access to some Integrated Lights Out Manager(ILOM) accessible data and  read access to a subset of Integrated Lights Out Manager(ILOM) accessible data.  CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:P/A:C).  Oracle Vector: (AV:N/AC:M/Au:S/C:P/I:P/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0424</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9849V-ILOM prior to 3.2.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9849V-ILOM prior to 3.2.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="158" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0425</Title>
      <Notes>
         <Note Audience="All" Ordinal="158" Title="Details" Type="Details">Vulnerability in the Oracle Enterprise Asset Management component of Oracle Siebel CRM (subcomponent: Siebel Core - Unix/Windows).  Supported versions that are affected are 8.1.1 and  8.2.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Enterprise Asset Management accessible data.  CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0425</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9016V-8.1.1</ProductID>
            <ProductID>P-9016V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-9016V-8.1.1</ProductID>
            <ProductID>P-9016V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="159" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0426</Title>
      <Notes>
         <Note Audience="All" Ordinal="159" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: UI Framework).  Supported versions that are affected are 12.1.0.3 and  12.1.0.4. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Enterprise Manager Base Platform accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0426</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-12.1.0.3</ProductID>
            <ProductID>P-1370V-12.1.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1370V-12.1.0.3</ProductID>
            <ProductID>P-1370V-12.1.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="160" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0427</Title>
      <Notes>
         <Note Audience="All" Ordinal="160" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: VMSVGA device).   The supported version that is affected is VirtualBox prior to 4.3.20. Easily exploitable vulnerability requiring logon to Operating System plus additional login/authentication to component or subcomponent.  Successful attack of this vulnerability can escalate attacker privileges resulting in unauthorized  update, insert or delete access to all Oracle VM VirtualBox accessible data and ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox.   Note: VMSVGA virtual graphics device is not documented and is disabled by default. CVSS Base Score 3.2 (Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:S/C:N/I:P/A:P).  Oracle Vector: (AV:L/AC:L/Au:S/C:N/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0427</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-VirtualBox prior to 4.3.20</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.2</BaseScore>
            <Vector>AV:L/AC:L/Au:S/C:N/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8370V-VirtualBox prior to 4.3.20</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="161" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0428</Title>
      <Notes>
         <Note Audience="All" Ordinal="161" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Resource Control).  Supported versions that are affected are 10 and  11. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 4.9 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0428</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-10</ProductID>
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.9</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-10006V-10</ProductID>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="162" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0429</Title>
      <Notes>
         <Note Audience="All" Ordinal="162" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RPC Utility).  Supported versions that are affected are 10 and  11. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Solaris accessible data and ability to cause a partial denial of service (partial DOS) of Solaris.  CVSS Base Score 3.3 (Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:N/I:P/A:P).  Oracle Vector: (AV:L/AC:M/Au:N/C:N/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0429</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-10</ProductID>
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.3</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:N/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-10006V-10</ProductID>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="163" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0430</Title>
      <Notes>
         <Note Audience="All" Ordinal="163" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RPC Utility).  Supported versions that are affected are 10 and  11. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Solaris accessible data.  CVSS Base Score 1.9 (Confidentiality impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:L/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0430</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-10</ProductID>
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>1.9</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-10006V-10</ProductID>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="164" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0431</Title>
      <Notes>
         <Note Audience="All" Ordinal="164" Title="Details" Type="Details">Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suite (subcomponent: UI Infrastructure).  Supported versions that are affected are 6.1, 6.2, 6.3.0 6.3.1, 6.3.2, 6.3.4 and  6.3.5. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Transportation Management accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0431</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1991V-6.1</ProductID>
            <ProductID>P-1991V-6.2</ProductID>
            <ProductID>P-1991V-6.3.0 6.3.1</ProductID>
            <ProductID>P-1991V-6.3.2</ProductID>
            <ProductID>P-1991V-6.3.4</ProductID>
            <ProductID>P-1991V-6.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1991V-6.1</ProductID>
            <ProductID>P-1991V-6.2</ProductID>
            <ProductID>P-1991V-6.3.0 6.3.1</ProductID>
            <ProductID>P-1991V-6.3.2</ProductID>
            <ProductID>P-1991V-6.3.4</ProductID>
            <ProductID>P-1991V-6.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="165" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0432</Title>
      <Notes>
         <Note Audience="All" Ordinal="165" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : InnoDB : DDL : Foreign Key).  Supported versions that are affected are 5.5.40 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0432</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-8478V-5.5.40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="166" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0434</Title>
      <Notes>
         <Note Audience="All" Ordinal="166" Title="Details" Type="Details">Vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware (subcomponent: Integration with OAM).  Supported versions that are affected are 11.1.1.5, 11.1.1.7, 11.1.2.1 and 11.1.2.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Access Manager accessible data.  CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0434</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5565V-11.1.1.5</ProductID>
            <ProductID>P-5565V-11.1.1.7</ProductID>
            <ProductID>P-5565V-11.1.2.1</ProductID>
            <ProductID>P-5565V-11.1.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-5565V-11.1.1.5</ProductID>
            <ProductID>P-5565V-11.1.1.7</ProductID>
            <ProductID>P-5565V-11.1.2.1</ProductID>
            <ProductID>P-5565V-11.1.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="167" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0435</Title>
      <Notes>
         <Note Audience="All" Ordinal="167" Title="Details" Type="Details">Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suite (subcomponent: Security).  Supported versions that are affected are 6.1, 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4 and  6.3.5. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to any arbitrary Operating System location.  CVSS Base Score 6.8 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:C/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:C/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0435</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1991V-6.1</ProductID>
            <ProductID>P-1991V-6.2</ProductID>
            <ProductID>P-1991V-6.3.0</ProductID>
            <ProductID>P-1991V-6.3.1</ProductID>
            <ProductID>P-1991V-6.3.2</ProductID>
            <ProductID>P-1991V-6.3.3</ProductID>
            <ProductID>P-1991V-6.3.4</ProductID>
            <ProductID>P-1991V-6.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.8</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:C/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-1991V-6.1</ProductID>
            <ProductID>P-1991V-6.2</ProductID>
            <ProductID>P-1991V-6.3.0</ProductID>
            <ProductID>P-1991V-6.3.1</ProductID>
            <ProductID>P-1991V-6.3.2</ProductID>
            <ProductID>P-1991V-6.3.3</ProductID>
            <ProductID>P-1991V-6.3.4</ProductID>
            <ProductID>P-1991V-6.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="168" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0436</Title>
      <Notes>
         <Note Audience="All" Ordinal="168" Title="Details" Type="Details">Vulnerability in the Oracle iLearning component of Oracle iLearning (subcomponent: Login).  Supported versions that are affected are 6.0 and  6.1. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle iLearning accessible data.  CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0436</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-902V-6.0</ProductID>
            <ProductID>P-902V-6.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-902V-6.0</ProductID>
            <ProductID>P-902V-6.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="169" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0437</Title>
      <Notes>
         <Note Audience="All" Ordinal="169" Title="Details" Type="Details">Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Hotspot).   The supported version that is affected is Java SE 8u25. Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 9.3 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0437</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>9.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2015</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html</URL>
            <ProductID>P-856V-Java SE 8u25</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
</cvrf:cvrfdoc>
