<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet type="text/xsl" href="2967710.xsl"?>
<?xml-stylesheet type="text/css" href="2967708.css"?>
<cvrf:cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
   <DocumentTitle xml:lang="en">Oracle Critical Patch Update Advisory - July 2016 - Oracle CVRF</DocumentTitle>
   <DocumentType xml:lang="en">Oracle Critical Patch Update Advisory</DocumentType>
   <DocumentPublisher Type="Vendor"/>
   <DocumentTracking>
      <Identification>
         <ID>CPUJul2016</ID>
      </Identification>
      <Status>Final</Status>
      <Version>1.0</Version>
      <RevisionHistory>
         <Revision>
            <Number>1.0</Number>
            <Date>2016-07-19T13:00:00-07:00</Date>
            <Description>Initial Distribution</Description>
         </Revision>
      </RevisionHistory>
      <InitialReleaseDate>2016-07-19T13:00:00-07:00</InitialReleaseDate>
      <CurrentReleaseDate>2016-07-19T13:00:00-07:00</CurrentReleaseDate>
   </DocumentTracking>
   <DocumentNotes>
      <Note Audience="All" Ordinal="1" Title="Summary" Type="Summary" xml:lang="en">This document contains descriptions of Oracle product security vulnerabilities which have had fixes released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including fix distribution information can be found at the Oracle sites referenced in this document.</Note>
   </DocumentNotes>
   <DocumentDistribution>This document is published at: http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/3089849.xml</DocumentDistribution>
   <DocumentReferences>
      <Reference Type="External">
         <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
         <Description>URL to html version of Advisory</Description>
      </Reference>
   </DocumentReferences>
   <Acknowledgments>
      <Acknowledgment>
         <Name>Adam Willard</Name>
         <Organization>Raytheon Foreground Security</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Alexander Kornbrust</Name>
         <Organization>Red Database Security</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Alexander Mirosh</Name>
         <Organization>Hewlett Packard Enterprise</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Alexey Tyurin</Name>
         <Organization>ERPScan</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Alvaro Munoz</Name>
         <Organization>Hewlett Packard Enterprise</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Alvaro Munoz</Name>
         <Organization>Trend Micro's Zero Day Initiative</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ben Lincoln</Name>
         <Organization>NCC Group</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Brian Martin</Name>
         <Organization>Tenable Network Security</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Bruno Cirone</Name>
         <Organization>Bruno Cirone</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Cameron Dawe</Name>
         <Organization>Spam404.com</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Christian Schneider</Name>
         <Organization>Trend Micro's Zero Day Initiative</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>David Litchfield</Name>
         <Organization>Google</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Devin Rosenbauer</Name>
         <Organization>Identity Works LLC</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jack Fei</Name>
         <Organization>FINRA</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Juan Manuel Fernández Torres</Name>
         <Organization>Telefonica.com</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jubaer Al Nazi</Name>
         <Organization>Jubaer Al Nazi</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Karim Rahal</Name>
         <Organization>Karim Rahal</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Kasper Andersen</Name>
         <Organization>Kasper Andersen</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Latish Danawale</Name>
         <Organization>Pristine Infosolutions</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Martin Petran</Name>
         <Organization>Accenture</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Matias Mevied</Name>
         <Organization>Onapsis</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Matthias Kaiser</Name>
         <Organization>Code White</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Matthias-Christian Ott</Name>
         <Organization>Matthias-Christian Ott</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Nicholas Lemonias</Name>
         <Organization>Advanced Information Security Corporation</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Nicolas Collignon</Name>
         <Organization>synacktiv</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Othmane Tamagart</Name>
         <Organization>Othmane Tamagart</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Paul M. Wright</Name>
         <Organization>oraclesecurity.com</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Quan Nguyen</Name>
         <Organization>Google</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ramal Hajataliyev</Name>
         <Organization>Ramal Hajataliyev</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Regina Wilson</Name>
         <Organization>Cisco</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Reno Robert</Name>
         <Organization>Reno Robert</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Rodolfo Godalle Jr.</Name>
         <Organization>Rodolfo Godalle Jr.</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Shawar Khan</Name>
         <Organization>Shawar Khan</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Spyridon Chatzimichail</Name>
         <Organization>COSMOTE - Mobile Telecommunications S.A.</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Stephan Borosh</Name>
         <Organization>Veris Group, LLC</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Stephen Kost</Name>
         <Organization>Integrigy</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Steven Seeley</Name>
         <Organization>Beyond Security</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Sven Blumenstein</Name>
         <Organization>Google</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Tayyab Qadir</Name>
         <Organization>Tayyab Qadir</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Teemu Kääriäinen</Name>
         <Organization>Teemu Kääriäinen</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ubais PK</Name>
         <Organization>Ubais PK</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Vikas Khanna</Name>
         <Organization>Vikas Khanna</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Winnye Jakeson</Name>
         <Organization>Winnye Jakeson</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>XOR19</Name>
         <Organization>Trend Micro's Zero Day Initiative</Organization>
      </Acknowledgment>
   </Acknowledgments>
   <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
      <Branch Name="Oracle" Type="Vendor">
         <Branch Name="Oracle Communications Applications" Type="Product Family">
            <Branch Name="Communications ASAP" Type="Product Name">
               <Branch Name="7.0" Type="Product Version">
                  <FullProductName ProductID="P-2260V-7.0">Communications ASAP Version 7.0</FullProductName>
               </Branch>
               <Branch Name="7.2" Type="Product Version">
                  <FullProductName ProductID="P-2260V-7.2">Communications ASAP Version 7.2</FullProductName>
               </Branch>
               <Branch Name="7.3" Type="Product Version">
                  <FullProductName ProductID="P-2260V-7.3">Communications ASAP Version 7.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Network Charging and Control" Type="Product Name">
               <Branch Name="4.4.1.5.0" Type="Product Version">
                  <FullProductName ProductID="P-4623V-4.4.1.5.0">Communications Network Charging and Control Version 4.4.1.5.0</FullProductName>
               </Branch>
               <Branch Name="5.0.0.1.0" Type="Product Version">
                  <FullProductName ProductID="P-4623V-5.0.0.1.0">Communications Network Charging and Control Version 5.0.0.1.0</FullProductName>
               </Branch>
               <Branch Name="5.0.0.2.0" Type="Product Version">
                  <FullProductName ProductID="P-4623V-5.0.0.2.0">Communications Network Charging and Control Version 5.0.0.2.0</FullProductName>
               </Branch>
               <Branch Name="5.0.1.0.0" Type="Product Version">
                  <FullProductName ProductID="P-4623V-5.0.1.0.0">Communications Network Charging and Control Version 5.0.1.0.0</FullProductName>
               </Branch>
               <Branch Name="5.0.2.0.0" Type="Product Version">
                  <FullProductName ProductID="P-4623V-5.0.2.0.0">Communications Network Charging and Control Version 5.0.2.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Messaging Server" Type="Product Name">
               <Branch Name="6.3" Type="Product Version">
                  <FullProductName ProductID="P-8496V-6.3">Communications Messaging Server Version 6.3</FullProductName>
               </Branch>
               <Branch Name="7.0" Type="Product Version">
                  <FullProductName ProductID="P-8496V-7.0">Communications Messaging Server Version 7.0</FullProductName>
               </Branch>
               <Branch Name="8.0" Type="Product Version">
                  <FullProductName ProductID="P-8496V-8.0">Communications Messaging Server Version 8.0</FullProductName>
               </Branch>
               <Branch Name="Prior to 7.0.5.37.0 and 8.0.1.1.0" Type="Product Version">
                  <FullProductName ProductID="P-8496V-Prior to 7.0.5.37.0 and 8.0.1.1.0">Communications Messaging Server Version Prior to 7.0.5.37.0 and 8.0.1.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Session Border Controller" Type="Product Name">
               <Branch Name="7.2.0" Type="Product Version">
                  <FullProductName ProductID="P-10750V-7.2.0">Communications Session Border Controller Version 7.2.0</FullProductName>
               </Branch>
               <Branch Name="7.3.0" Type="Product Version">
                  <FullProductName ProductID="P-10750V-7.3.0">Communications Session Border Controller Version 7.3.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Unified Session Manager" Type="Product Name">
               <Branch Name="7.2.5" Type="Product Version">
                  <FullProductName ProductID="P-10753V-7.2.5">Communications Unified Session Manager Version 7.2.5</FullProductName>
               </Branch>
               <Branch Name="7.3.5" Type="Product Version">
                  <FullProductName ProductID="P-10753V-7.3.5">Communications Unified Session Manager Version 7.3.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Core Session Manager" Type="Product Name">
               <Branch Name="7.2.5" Type="Product Version">
                  <FullProductName ProductID="P-10754V-7.2.5">Communications Core Session Manager Version 7.2.5</FullProductName>
               </Branch>
               <Branch Name="7.3.5" Type="Product Version">
                  <FullProductName ProductID="P-10754V-7.3.5">Communications Core Session Manager Version 7.3.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Enterprise Communications Broker" Type="Product Name">
               <Branch Name="Prior to PCz 2.0.0m4p1" Type="Product Version">
                  <FullProductName ProductID="P-10758V-Prior to PCz 2.0.0m4p1">Enterprise Communications Broker Version Prior to PCz 2.0.0m4p1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Operations Monitor" Type="Product Name">
               <Branch Name="Prior to 3.3.92.0.0" Type="Product Version">
                  <FullProductName ProductID="P-10761V-Prior to 3.3.92.0.0">Communications Operations Monitor Version Prior to 3.3.92.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Policy Management" Type="Product Name">
               <Branch Name="Prior to 9.9.2" Type="Product Version">
                  <FullProductName ProductID="P-10900V-Prior to 9.9.2">Communications Policy Management Version Prior to 9.9.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications EAGLE Application Processor" Type="Product Name">
               <Branch Name="16.0" Type="Product Version">
                  <FullProductName ProductID="P-11122V-16.0">Communications EAGLE Application Processor Version 16.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Database Server" Type="Product Family">
            <Branch Name="Oracle Database" Type="Product Name">
               <Branch Name="11.2.0.4" Type="Product Version">
                  <FullProductName ProductID="P-5V-11.2.0.4">Oracle Database Version 11.2.0.4</FullProductName>
               </Branch>
               <Branch Name="12.1.0.1" Type="Product Version">
                  <FullProductName ProductID="P-5V-12.1.0.1">Oracle Database Version 12.1.0.1</FullProductName>
               </Branch>
               <Branch Name="12.1.0.2" Type="Product Version">
                  <FullProductName ProductID="P-5V-12.1.0.2">Oracle Database Version 12.1.0.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="JDBC" Type="Product Name">
               <Branch Name="11.2.0.4" Type="Product Version">
                  <FullProductName ProductID="P-972V-11.2.0.4">JDBC Version 11.2.0.4</FullProductName>
               </Branch>
               <Branch Name="12.1.0.1" Type="Product Version">
                  <FullProductName ProductID="P-972V-12.1.0.1">JDBC Version 12.1.0.1</FullProductName>
               </Branch>
               <Branch Name="12.1.0.2" Type="Product Version">
                  <FullProductName ProductID="P-972V-12.1.0.2">JDBC Version 12.1.0.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Application Express" Type="Product Name">
               <Branch Name="Prior to 5.0.4" Type="Product Version">
                  <FullProductName ProductID="P-1348V-Prior to 5.0.4">Application Express Version Prior to 5.0.4</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle E-Business Suite" Type="Product Family">
            <Branch Name="Applications Manager" Type="Product Name">
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-99V-12.1.3">Applications Manager Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Marketing" Type="Product Name">
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-229V-12.1.1">Marketing Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-229V-12.1.2">Marketing Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-229V-12.1.3">Marketing Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-229V-12.2.3">Marketing Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-229V-12.2.4">Marketing Version 12.2.4</FullProductName>
               </Branch>
               <Branch Name="12.2.5" Type="Product Version">
                  <FullProductName ProductID="P-229V-12.2.5">Marketing Version 12.2.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Advanced Inbound Telephony" Type="Product Name">
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-265V-12.1.1">Advanced Inbound Telephony Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-265V-12.1.2">Advanced Inbound Telephony Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-265V-12.1.3">Advanced Inbound Telephony Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Internet Expenses" Type="Product Name">
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-397V-12.1.1">Internet Expenses Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-397V-12.1.2">Internet Expenses Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-397V-12.1.3">Internet Expenses Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-397V-12.2.3">Internet Expenses Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-397V-12.2.4">Internet Expenses Version 12.2.4</FullProductName>
               </Branch>
               <Branch Name="12.2.5" Type="Product Version">
                  <FullProductName ProductID="P-397V-12.2.5">Internet Expenses Version 12.2.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Application Object Library" Type="Product Name">
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-510V-12.1.3">Application Object Library Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-510V-12.2.3">Application Object Library Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-510V-12.2.4">Application Object Library Version 12.2.4</FullProductName>
               </Branch>
               <Branch Name="12.2.5" Type="Product Version">
                  <FullProductName ProductID="P-510V-12.2.5">Application Object Library Version 12.2.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Advanced Collections" Type="Product Name">
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-782V-12.1.1">Advanced Collections Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-782V-12.1.2">Advanced Collections Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-782V-12.1.3">Advanced Collections Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Email Center" Type="Product Name">
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-950V-12.1.1">Email Center Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-950V-12.1.2">Email Center Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-950V-12.1.3">Email Center Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-950V-12.2.3">Email Center Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-950V-12.2.4">Email Center Version 12.2.4</FullProductName>
               </Branch>
               <Branch Name="12.2.5" Type="Product Version">
                  <FullProductName ProductID="P-950V-12.2.5">Email Center Version 12.2.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Installed Base" Type="Product Name">
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-1118V-12.1.1">Installed Base Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-1118V-12.1.2">Installed Base Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1118V-12.1.3">Installed Base Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-1118V-12.2.3">Installed Base Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-1118V-12.2.4">Installed Base Version 12.2.4</FullProductName>
               </Branch>
               <Branch Name="12.2.5" Type="Product Version">
                  <FullProductName ProductID="P-1118V-12.2.5">Installed Base Version 12.2.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Web Applications Desktop Integrator" Type="Product Name">
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1171V-12.1.3">Web Applications Desktop Integrator Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-1171V-12.2.3">Web Applications Desktop Integrator Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-1171V-12.2.4">Web Applications Desktop Integrator Version 12.2.4</FullProductName>
               </Branch>
               <Branch Name="12.2.5" Type="Product Version">
                  <FullProductName ProductID="P-1171V-12.2.5">Web Applications Desktop Integrator Version 12.2.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="CRM Technical Foundation" Type="Product Name">
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1199V-12.1.3">CRM Technical Foundation Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Knowledge Management" Type="Product Name">
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-1351V-12.1.1">Knowledge Management Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-1351V-12.1.2">Knowledge Management Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1351V-12.1.3">Knowledge Management Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-1351V-12.2.3">Knowledge Management Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-1351V-12.2.4">Knowledge Management Version 12.2.4</FullProductName>
               </Branch>
               <Branch Name="12.2.5" Type="Product Version">
                  <FullProductName ProductID="P-1351V-12.2.5">Knowledge Management Version 12.2.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Customer Interaction History" Type="Product Name">
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-1374V-12.1.1">Customer Interaction History Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-1374V-12.1.2">Customer Interaction History Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1374V-12.1.3">Customer Interaction History Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="One-to-One Fulfillment" Type="Product Name">
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-1379V-12.1.1">One-to-One Fulfillment Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-1379V-12.1.2">One-to-One Fulfillment Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1379V-12.1.3">One-to-One Fulfillment Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-1379V-12.2.3">One-to-One Fulfillment Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-1379V-12.2.4">One-to-One Fulfillment Version 12.2.4</FullProductName>
               </Branch>
               <Branch Name="12.2.5" Type="Product Version">
                  <FullProductName ProductID="P-1379V-12.2.5">One-to-One Fulfillment Version 12.2.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Common Applications Calendar" Type="Product Name">
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-1528V-12.1.1">Common Applications Calendar Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-1528V-12.1.2">Common Applications Calendar Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1528V-12.1.3">Common Applications Calendar Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-1528V-12.2.3">Common Applications Calendar Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-1528V-12.2.4">Common Applications Calendar Version 12.2.4</FullProductName>
               </Branch>
               <Branch Name="12.2.5" Type="Product Version">
                  <FullProductName ProductID="P-1528V-12.2.5">Common Applications Calendar Version 12.2.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Applications Technology Stack" Type="Product Name">
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1745V-12.1.3">Applications Technology Stack Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-1745V-12.2.3">Applications Technology Stack Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-1745V-12.2.4">Applications Technology Stack Version 12.2.4</FullProductName>
               </Branch>
               <Branch Name="12.2.5" Type="Product Version">
                  <FullProductName ProductID="P-1745V-12.2.5">Applications Technology Stack Version 12.2.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="E-Business Suite Secure Enterprise Search" Type="Product Name">
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-4574V-12.1.3">E-Business Suite Secure Enterprise Search Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-4574V-12.2.3">E-Business Suite Secure Enterprise Search Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-4574V-12.2.4">E-Business Suite Secure Enterprise Search Version 12.2.4</FullProductName>
               </Branch>
               <Branch Name="12.2.5" Type="Product Version">
                  <FullProductName ProductID="P-4574V-12.2.5">E-Business Suite Secure Enterprise Search Version 12.2.5</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Enterprise Manager Grid Control" Type="Product Family">
            <Branch Name="Enterprise Manager for Fusion Middleware" Type="Product Name">
               <Branch Name="11.1.1.7" Type="Product Version">
                  <FullProductName ProductID="P-1369V-11.1.1.7">Enterprise Manager for Fusion Middleware Version 11.1.1.7</FullProductName>
               </Branch>
               <Branch Name="11.1.1.9" Type="Product Version">
                  <FullProductName ProductID="P-1369V-11.1.1.9">Enterprise Manager for Fusion Middleware Version 11.1.1.9</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Enterprise Manager Base Platform" Type="Product Name">
               <Branch Name="12.1.0.5" Type="Product Version">
                  <FullProductName ProductID="P-1370V-12.1.0.5">Enterprise Manager Base Platform Version 12.1.0.5</FullProductName>
               </Branch>
               <Branch Name="13.1.0.0" Type="Product Version">
                  <FullProductName ProductID="P-1370V-13.1.0.0">Enterprise Manager Base Platform Version 13.1.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Enterprise Manager Ops Center" Type="Product Name">
               <Branch Name="12.1.4" Type="Product Version">
                  <FullProductName ProductID="P-9835V-12.1.4">Enterprise Manager Ops Center Version 12.1.4</FullProductName>
               </Branch>
               <Branch Name="12.2.2" Type="Product Version">
                  <FullProductName ProductID="P-9835V-12.2.2">Enterprise Manager Ops Center Version 12.2.2</FullProductName>
               </Branch>
               <Branch Name="12.3.2" Type="Product Version">
                  <FullProductName ProductID="P-9835V-12.3.2">Enterprise Manager Ops Center Version 12.3.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Financial Services Applications" Type="Product Family">
            <Branch Name="FLEXCUBE Direct Banking" Type="Product Name">
               <Branch Name="12.0.1" Type="Product Version">
                  <FullProductName ProductID="P-9111V-12.0.1">FLEXCUBE Direct Banking Version 12.0.1</FullProductName>
               </Branch>
               <Branch Name="12.0.2" Type="Product Version">
                  <FullProductName ProductID="P-9111V-12.0.2">FLEXCUBE Direct Banking Version 12.0.2</FullProductName>
               </Branch>
               <Branch Name="12.0.3" Type="Product Version">
                  <FullProductName ProductID="P-9111V-12.0.3">FLEXCUBE Direct Banking Version 12.0.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Banking Platform" Type="Product Name">
               <Branch Name="2.3.0" Type="Product Version">
                  <FullProductName ProductID="P-9178V-2.3.0">Banking Platform Version 2.3.0</FullProductName>
               </Branch>
               <Branch Name="2.4.0" Type="Product Version">
                  <FullProductName ProductID="P-9178V-2.4.0">Banking Platform Version 2.4.0</FullProductName>
               </Branch>
               <Branch Name="2.4.1" Type="Product Version">
                  <FullProductName ProductID="P-9178V-2.4.1">Banking Platform Version 2.4.1</FullProductName>
               </Branch>
               <Branch Name="2.5.0" Type="Product Version">
                  <FullProductName ProductID="P-9178V-2.5.0">Banking Platform Version 2.5.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Lending and Leasing" Type="Product Name">
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-10484V-14.1">Financial Services Lending and Leasing Version 14.1</FullProductName>
               </Branch>
               <Branch Name="14.2" Type="Product Version">
                  <FullProductName ProductID="P-10484V-14.2">Financial Services Lending and Leasing Version 14.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Fusion Middleware" Type="Product Family">
            <Branch Name="Portal" Type="Product Name">
               <Branch Name="11.1.1.6" Type="Product Version">
                  <FullProductName ProductID="P-96V-11.1.1.6">Portal Version 11.1.1.6</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="JDeveloper" Type="Product Name">
               <Branch Name="11.1.1.7.0" Type="Product Version">
                  <FullProductName ProductID="P-807V-11.1.1.7.0">JDeveloper Version 11.1.1.7.0</FullProductName>
               </Branch>
               <Branch Name="11.1.1.9.0" Type="Product Version">
                  <FullProductName ProductID="P-807V-11.1.1.9.0">JDeveloper Version 11.1.1.9.0</FullProductName>
               </Branch>
               <Branch Name="11.1.2.4.0" Type="Product Version">
                  <FullProductName ProductID="P-807V-11.1.2.4.0">JDeveloper Version 11.1.2.4.0</FullProductName>
               </Branch>
               <Branch Name="12.1.3.0.0" Type="Product Version">
                  <FullProductName ProductID="P-807V-12.1.3.0.0">JDeveloper Version 12.1.3.0.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.0.0" Type="Product Version">
                  <FullProductName ProductID="P-807V-12.2.1.0.0">JDeveloper Version 12.2.1.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="HTTP Server" Type="Product Name">
               <Branch Name="11.1.1.9" Type="Product Version">
                  <FullProductName ProductID="P-1042V-11.1.1.9">HTTP Server Version 11.1.1.9</FullProductName>
               </Branch>
               <Branch Name="12.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1042V-12.1.3.0">HTTP Server Version 12.1.3.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="TopLink" Type="Product Name">
               <Branch Name="12.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1339V-12.1.3.0">TopLink Version 12.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.0" Type="Product Version">
                  <FullProductName ProductID="P-1339V-12.2.1.0">TopLink Version 12.2.1.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.1" Type="Product Version">
                  <FullProductName ProductID="P-1339V-12.2.1.1">TopLink Version 12.2.1.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="BI Publisher (formerly XML Publisher)" Type="Product Name">
               <Branch Name="11.1.1.7.0" Type="Product Version">
                  <FullProductName ProductID="P-1479V-11.1.1.7.0">BI Publisher (formerly XML Publisher) Version 11.1.1.7.0</FullProductName>
               </Branch>
               <Branch Name="11.1.1.9.0" Type="Product Version">
                  <FullProductName ProductID="P-1479V-11.1.1.9.0">BI Publisher (formerly XML Publisher) Version 11.1.1.9.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.0.0" Type="Product Version">
                  <FullProductName ProductID="P-1479V-12.2.1.0.0">BI Publisher (formerly XML Publisher) Version 12.2.1.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="COREid Access" Type="Product Name">
               <Branch Name="10.1.4.x" Type="Product Version">
                  <FullProductName ProductID="P-1773V-10.1.4.x">COREid Access Version 10.1.4.x</FullProductName>
               </Branch>
               <Branch Name="11.1.1.7" Type="Product Version">
                  <FullProductName ProductID="P-1773V-11.1.1.7">COREid Access Version 11.1.1.7</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Business Intelligence Enterprise Edition" Type="Product Name">
               <Branch Name="11.1.1.7.0" Type="Product Version">
                  <FullProductName ProductID="P-2025V-11.1.1.7.0">Business Intelligence Enterprise Edition Version 11.1.1.7.0</FullProductName>
               </Branch>
               <Branch Name="11.1.1.9.0" Type="Product Version">
                  <FullProductName ProductID="P-2025V-11.1.1.9.0">Business Intelligence Enterprise Edition Version 11.1.1.9.0</FullProductName>
               </Branch>
               <Branch Name="11.2.1.0.0" Type="Product Version">
                  <FullProductName ProductID="P-2025V-11.2.1.0.0">Business Intelligence Enterprise Edition Version 11.2.1.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Outside In Technology" Type="Product Name">
               <Branch Name="8.5.0" Type="Product Version">
                  <FullProductName ProductID="P-2276V-8.5.0">Outside In Technology Version 8.5.0</FullProductName>
               </Branch>
               <Branch Name="8.5.1" Type="Product Version">
                  <FullProductName ProductID="P-2276V-8.5.1">Outside In Technology Version 8.5.1</FullProductName>
               </Branch>
               <Branch Name="8.5.2" Type="Product Version">
                  <FullProductName ProductID="P-2276V-8.5.2">Outside In Technology Version 8.5.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="WebLogic Server" Type="Product Name">
               <Branch Name="10.3.6.0" Type="Product Version">
                  <FullProductName ProductID="P-5242V-10.3.6.0">WebLogic Server Version 10.3.6.0</FullProductName>
               </Branch>
               <Branch Name="12.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-5242V-12.1.3.0">WebLogic Server Version 12.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.0" Type="Product Version">
                  <FullProductName ProductID="P-5242V-12.2.1.0">WebLogic Server Version 12.2.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="GlassFish Server" Type="Product Name">
               <Branch Name="2.1.1" Type="Product Version">
                  <FullProductName ProductID="P-8493V-2.1.1">GlassFish Server Version 2.1.1</FullProductName>
               </Branch>
               <Branch Name="3.0.1" Type="Product Version">
                  <FullProductName ProductID="P-8493V-3.0.1">GlassFish Server Version 3.0.1</FullProductName>
               </Branch>
               <Branch Name="3.1.2" Type="Product Version">
                  <FullProductName ProductID="P-8493V-3.1.2">GlassFish Server Version 3.1.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Directory Server Enterprise Edition" Type="Product Name">
               <Branch Name="11.1.1.7.0" Type="Product Version">
                  <FullProductName ProductID="P-8512V-11.1.1.7.0">Directory Server Enterprise Edition Version 11.1.1.7.0</FullProductName>
               </Branch>
               <Branch Name="7.0" Type="Product Version">
                  <FullProductName ProductID="P-8512V-7.0">Directory Server Enterprise Edition Version 7.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Exalogic Infrastructure" Type="Product Name">
               <Branch Name="1.x" Type="Product Version">
                  <FullProductName ProductID="P-9415V-1.x">Exalogic Infrastructure Version 1.x</FullProductName>
               </Branch>
               <Branch Name="2.x" Type="Product Version">
                  <FullProductName ProductID="P-9415V-2.x">Exalogic Infrastructure Version 2.x</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="WebCenter Sites" Type="Product Name">
               <Branch Name="11.1.1.8" Type="Product Version">
                  <FullProductName ProductID="P-9617V-11.1.1.8">WebCenter Sites Version 11.1.1.8</FullProductName>
               </Branch>
               <Branch Name="12.2.1.0" Type="Product Version">
                  <FullProductName ProductID="P-9617V-12.2.1.0">WebCenter Sites Version 12.2.1.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Health Sciences Applications" Type="Product Family">
            <Branch Name="Healthcare Master Person Index" Type="Product Name">
               <Branch Name="2.0.12" Type="Product Version">
                  <FullProductName ProductID="P-8575V-2.0.12">Healthcare Master Person Index Version 2.0.12</FullProductName>
               </Branch>
               <Branch Name="3.0.0" Type="Product Version">
                  <FullProductName ProductID="P-8575V-3.0.0">Healthcare Master Person Index Version 3.0.0</FullProductName>
               </Branch>
               <Branch Name="4.0.1" Type="Product Version">
                  <FullProductName ProductID="P-8575V-4.0.1">Healthcare Master Person Index Version 4.0.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Health Sciences Information Manager" Type="Product Name">
               <Branch Name="1.2.8.3" Type="Product Version">
                  <FullProductName ProductID="P-9177V-1.2.8.3">Health Sciences Information Manager Version 1.2.8.3</FullProductName>
               </Branch>
               <Branch Name="2.0.2.3" Type="Product Version">
                  <FullProductName ProductID="P-9177V-2.0.2.3">Health Sciences Information Manager Version 2.0.2.3</FullProductName>
               </Branch>
               <Branch Name="3.0.1.0" Type="Product Version">
                  <FullProductName ProductID="P-9177V-3.0.1.0">Health Sciences Information Manager Version 3.0.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Healthcare Analytics Data Integration" Type="Product Name">
               <Branch Name="3.1.0.0.0" Type="Product Version">
                  <FullProductName ProductID="P-9314V-3.1.0.0.0">Healthcare Analytics Data Integration Version 3.1.0.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Health Sciences Clinical Development Center" Type="Product Name">
               <Branch Name="3.1.1.x" Type="Product Version">
                  <FullProductName ProductID="P-9652V-3.1.1.x">Health Sciences Clinical Development Center Version 3.1.1.x</FullProductName>
               </Branch>
               <Branch Name="3.1.2.x" Type="Product Version">
                  <FullProductName ProductID="P-9652V-3.1.2.x">Health Sciences Clinical Development Center Version 3.1.2.x</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Hyperion" Type="Product Family">
            <Branch Name="Hyperion Financial Reporting" Type="Product Name">
               <Branch Name="11.1.2.4" Type="Product Version">
                  <FullProductName ProductID="P-8776V-11.1.2.4">Hyperion Financial Reporting Version 11.1.2.4</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Insurance Applications" Type="Product Family">
            <Branch Name="Insurance Policy Administration J2EE" Type="Product Name">
               <Branch Name="10.0.1" Type="Product Version">
                  <FullProductName ProductID="P-5279V-10.0.1">Insurance Policy Administration J2EE Version 10.0.1</FullProductName>
               </Branch>
               <Branch Name="10.1.2" Type="Product Version">
                  <FullProductName ProductID="P-5279V-10.1.2">Insurance Policy Administration J2EE Version 10.1.2</FullProductName>
               </Branch>
               <Branch Name="10.2.0" Type="Product Version">
                  <FullProductName ProductID="P-5279V-10.2.0">Insurance Policy Administration J2EE Version 10.2.0</FullProductName>
               </Branch>
               <Branch Name="10.2.2" Type="Product Version">
                  <FullProductName ProductID="P-5279V-10.2.2">Insurance Policy Administration J2EE Version 10.2.2</FullProductName>
               </Branch>
               <Branch Name="9.6.1" Type="Product Version">
                  <FullProductName ProductID="P-5279V-9.6.1">Insurance Policy Administration J2EE Version 9.6.1</FullProductName>
               </Branch>
               <Branch Name="9.7.1" Type="Product Version">
                  <FullProductName ProductID="P-5279V-9.7.1">Insurance Policy Administration J2EE Version 9.7.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Insurance Rules Palette" Type="Product Name">
               <Branch Name="10.0.1" Type="Product Version">
                  <FullProductName ProductID="P-5288V-10.0.1">Insurance Rules Palette Version 10.0.1</FullProductName>
               </Branch>
               <Branch Name="10.1.2" Type="Product Version">
                  <FullProductName ProductID="P-5288V-10.1.2">Insurance Rules Palette Version 10.1.2</FullProductName>
               </Branch>
               <Branch Name="10.2.0" Type="Product Version">
                  <FullProductName ProductID="P-5288V-10.2.0">Insurance Rules Palette Version 10.2.0</FullProductName>
               </Branch>
               <Branch Name="10.2.2" Type="Product Version">
                  <FullProductName ProductID="P-5288V-10.2.2">Insurance Rules Palette Version 10.2.2</FullProductName>
               </Branch>
               <Branch Name="9.6.1" Type="Product Version">
                  <FullProductName ProductID="P-5288V-9.6.1">Insurance Rules Palette Version 9.6.1</FullProductName>
               </Branch>
               <Branch Name="9.7.1" Type="Product Version">
                  <FullProductName ProductID="P-5288V-9.7.1">Insurance Rules Palette Version 9.7.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Documaker" Type="Product Name">
               <Branch Name="Prior to 12.5" Type="Product Version">
                  <FullProductName ProductID="P-5477V-Prior to 12.5">Documaker Version Prior to 12.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Insurance Calculation Engine" Type="Product Name">
               <Branch Name="10.1.2" Type="Product Version">
                  <FullProductName ProductID="P-10837V-10.1.2">Insurance Calculation Engine Version 10.1.2</FullProductName>
               </Branch>
               <Branch Name="10.2.2" Type="Product Version">
                  <FullProductName ProductID="P-10837V-10.2.2">Insurance Calculation Engine Version 10.2.2</FullProductName>
               </Branch>
               <Branch Name="9.7.1" Type="Product Version">
                  <FullProductName ProductID="P-10837V-9.7.1">Insurance Calculation Engine Version 9.7.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle JD Edwards Products" Type="Product Family">
            <Branch Name="JD Edwards EnterpriseOne Tools" Type="Product Name">
               <Branch Name="9.2.0.5" Type="Product Version">
                  <FullProductName ProductID="P-4781V-9.2.0.5">JD Edwards EnterpriseOne Tools Version 9.2.0.5</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Java SE" Type="Product Family">
            <Branch Name="Java" Type="Product Name">
               <Branch Name="7u101" Type="Product Version">
                  <FullProductName ProductID="P-856V-7u101">Java Version 7u101</FullProductName>
               </Branch>
               <Branch Name="8u92" Type="Product Version">
                  <FullProductName ProductID="P-856V-8u92">Java Version 8u92</FullProductName>
               </Branch>
               <Branch Name="8u92; Java SE Embedded: 8u91" Type="Product Version">
                  <FullProductName ProductID="P-856V-8u92; Java SE Embedded: 8u91">Java Version 8u92; Java SE Embedded: 8u91</FullProductName>
               </Branch>
               <Branch Name="8u92; Java SE Embedded: 8u91; JRockit: R28.3.10" Type="Product Version">
                  <FullProductName ProductID="P-856V-8u92; Java SE Embedded: 8u91; JRockit: R28.3.10">Java Version 8u92; Java SE Embedded: 8u91; JRockit: R28.3.10</FullProductName>
               </Branch>
               <Branch Name="Java SE: 6u115" Type="Product Version">
                  <FullProductName ProductID="P-856V-Java SE: 6u115">Java Version Java SE: 6u115</FullProductName>
               </Branch>
               <Branch Name="Java SE: 7u101" Type="Product Version">
                  <FullProductName ProductID="P-856V-Java SE: 7u101">Java Version Java SE: 7u101</FullProductName>
               </Branch>
               <Branch Name="Java SE: 8u92" Type="Product Version">
                  <FullProductName ProductID="P-856V-Java SE: 8u92">Java Version Java SE: 8u92</FullProductName>
               </Branch>
               <Branch Name="Java SE: 8u92; Java SE Embedded: 8u91" Type="Product Version">
                  <FullProductName ProductID="P-856V-Java SE: 8u92; Java SE Embedded: 8u91">Java Version Java SE: 8u92; Java SE Embedded: 8u91</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle MySQL" Type="Product Family">
            <Branch Name="MySQL Server" Type="Product Name">
               <Branch Name="5.5.45 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.5.45 and earlier">MySQL Server Version 5.5.45 and earlier</FullProductName>
               </Branch>
               <Branch Name="5.5.48 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.5.48 and earlier">MySQL Server Version 5.5.48 and earlier</FullProductName>
               </Branch>
               <Branch Name="5.5.49 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.5.49 and earlier">MySQL Server Version 5.5.49 and earlier</FullProductName>
               </Branch>
               <Branch Name="5.6.26 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.6.26 and earlier">MySQL Server Version 5.6.26 and earlier</FullProductName>
               </Branch>
               <Branch Name="5.6.29 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.6.29 and earlier">MySQL Server Version 5.6.29 and earlier</FullProductName>
               </Branch>
               <Branch Name="5.6.30 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.6.30 and earlier">MySQL Server Version 5.6.30 and earlier</FullProductName>
               </Branch>
               <Branch Name="5.7.10 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.7.10 and earlier">MySQL Server Version 5.7.10 and earlier</FullProductName>
               </Branch>
               <Branch Name="5.7.11 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.7.11 and earlier">MySQL Server Version 5.7.11 and earlier</FullProductName>
               </Branch>
               <Branch Name="5.7.12 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.7.12 and earlier">MySQL Server Version 5.7.12 and earlier</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle PeopleSoft Products" Type="Product Family">
            <Branch Name="PeopleSoft Enterprise PT PeopleTools" Type="Product Name">
               <Branch Name="8.53" Type="Product Version">
                  <FullProductName ProductID="P-5085V-8.53">PeopleSoft Enterprise PT PeopleTools Version 8.53</FullProductName>
               </Branch>
               <Branch Name="8.54" Type="Product Version">
                  <FullProductName ProductID="P-5085V-8.54">PeopleSoft Enterprise PT PeopleTools Version 8.54</FullProductName>
               </Branch>
               <Branch Name="8.55" Type="Product Version">
                  <FullProductName ProductID="P-5085V-8.55">PeopleSoft Enterprise PT PeopleTools Version 8.55</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="PeopleSoft Enterprise SCM eProcurement" Type="Product Name">
               <Branch Name="9.1" Type="Product Version">
                  <FullProductName ProductID="P-5118V-9.1">PeopleSoft Enterprise SCM eProcurement Version 9.1</FullProductName>
               </Branch>
               <Branch Name="9.2" Type="Product Version">
                  <FullProductName ProductID="P-5118V-9.2">PeopleSoft Enterprise SCM eProcurement Version 9.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Policy Automation" Type="Product Family">
            <Branch Name="Policy Automation" Type="Product Name">
               <Branch Name="10.3.0" Type="Product Version">
                  <FullProductName ProductID="P-5624V-10.3.0">Policy Automation Version 10.3.0</FullProductName>
               </Branch>
               <Branch Name="10.3.1" Type="Product Version">
                  <FullProductName ProductID="P-5624V-10.3.1">Policy Automation Version 10.3.1</FullProductName>
               </Branch>
               <Branch Name="10.4.0" Type="Product Version">
                  <FullProductName ProductID="P-5624V-10.4.0">Policy Automation Version 10.4.0</FullProductName>
               </Branch>
               <Branch Name="10.4.1" Type="Product Version">
                  <FullProductName ProductID="P-5624V-10.4.1">Policy Automation Version 10.4.1</FullProductName>
               </Branch>
               <Branch Name="10.4.2" Type="Product Version">
                  <FullProductName ProductID="P-5624V-10.4.2">Policy Automation Version 10.4.2</FullProductName>
               </Branch>
               <Branch Name="10.4.3" Type="Product Version">
                  <FullProductName ProductID="P-5624V-10.4.3">Policy Automation Version 10.4.3</FullProductName>
               </Branch>
               <Branch Name="10.4.4" Type="Product Version">
                  <FullProductName ProductID="P-5624V-10.4.4">Policy Automation Version 10.4.4</FullProductName>
               </Branch>
               <Branch Name="10.4.5" Type="Product Version">
                  <FullProductName ProductID="P-5624V-10.4.5">Policy Automation Version 10.4.5</FullProductName>
               </Branch>
               <Branch Name="10.4.6" Type="Product Version">
                  <FullProductName ProductID="P-5624V-10.4.6">Policy Automation Version 10.4.6</FullProductName>
               </Branch>
               <Branch Name="12.1.0" Type="Product Version">
                  <FullProductName ProductID="P-5624V-12.1.0">Policy Automation Version 12.1.0</FullProductName>
               </Branch>
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-5624V-12.1.1">Policy Automation Version 12.1.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Policy Automation for Mobile Devices" Type="Product Name">
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-5626V-12.1.1">Policy Automation for Mobile Devices Version 12.1.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Policy Automation Connector for Siebel" Type="Product Name">
               <Branch Name="10.3.0" Type="Product Version">
                  <FullProductName ProductID="P-5627V-10.3.0">Policy Automation Connector for Siebel Version 10.3.0</FullProductName>
               </Branch>
               <Branch Name="10.4.0" Type="Product Version">
                  <FullProductName ProductID="P-5627V-10.4.0">Policy Automation Connector for Siebel Version 10.4.0</FullProductName>
               </Branch>
               <Branch Name="10.4.1" Type="Product Version">
                  <FullProductName ProductID="P-5627V-10.4.1">Policy Automation Connector for Siebel Version 10.4.1</FullProductName>
               </Branch>
               <Branch Name="10.4.2" Type="Product Version">
                  <FullProductName ProductID="P-5627V-10.4.2">Policy Automation Connector for Siebel Version 10.4.2</FullProductName>
               </Branch>
               <Branch Name="10.4.3" Type="Product Version">
                  <FullProductName ProductID="P-5627V-10.4.3">Policy Automation Connector for Siebel Version 10.4.3</FullProductName>
               </Branch>
               <Branch Name="10.4.4" Type="Product Version">
                  <FullProductName ProductID="P-5627V-10.4.4">Policy Automation Connector for Siebel Version 10.4.4</FullProductName>
               </Branch>
               <Branch Name="10.4.5" Type="Product Version">
                  <FullProductName ProductID="P-5627V-10.4.5">Policy Automation Connector for Siebel Version 10.4.5</FullProductName>
               </Branch>
               <Branch Name="10.4.6" Type="Product Version">
                  <FullProductName ProductID="P-5627V-10.4.6">Policy Automation Connector for Siebel Version 10.4.6</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="In-Memory Policy Analytics" Type="Product Name">
               <Branch Name="12.0.1" Type="Product Version">
                  <FullProductName ProductID="P-11368V-12.0.1">In-Memory Policy Analytics Version 12.0.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Primavera Products Suite" Type="Product Family">
            <Branch Name="Primavera P6 Enterprise Project Portfolio Management" Type="Product Name">
               <Branch Name="15.1" Type="Product Version">
                  <FullProductName ProductID="P-5579V-15.1">Primavera P6 Enterprise Project Portfolio Management Version 15.1</FullProductName>
               </Branch>
               <Branch Name="15.2" Type="Product Version">
                  <FullProductName ProductID="P-5579V-15.2">Primavera P6 Enterprise Project Portfolio Management Version 15.2</FullProductName>
               </Branch>
               <Branch Name="16.1" Type="Product Version">
                  <FullProductName ProductID="P-5579V-16.1">Primavera P6 Enterprise Project Portfolio Management Version 16.1</FullProductName>
               </Branch>
               <Branch Name="8.2" Type="Product Version">
                  <FullProductName ProductID="P-5579V-8.2">Primavera P6 Enterprise Project Portfolio Management Version 8.2</FullProductName>
               </Branch>
               <Branch Name="8.3" Type="Product Version">
                  <FullProductName ProductID="P-5579V-8.3">Primavera P6 Enterprise Project Portfolio Management Version 8.3</FullProductName>
               </Branch>
               <Branch Name="8.4" Type="Product Version">
                  <FullProductName ProductID="P-5579V-8.4">Primavera P6 Enterprise Project Portfolio Management Version 8.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Primavera P6 Professional Project Management" Type="Product Name">
               <Branch Name="15.1" Type="Product Version">
                  <FullProductName ProductID="P-5580V-15.1">Primavera P6 Professional Project Management Version 15.1</FullProductName>
               </Branch>
               <Branch Name="15.2" Type="Product Version">
                  <FullProductName ProductID="P-5580V-15.2">Primavera P6 Professional Project Management Version 15.2</FullProductName>
               </Branch>
               <Branch Name="8.3" Type="Product Version">
                  <FullProductName ProductID="P-5580V-8.3">Primavera P6 Professional Project Management Version 8.3</FullProductName>
               </Branch>
               <Branch Name="8.4" Type="Product Version">
                  <FullProductName ProductID="P-5580V-8.4">Primavera P6 Professional Project Management Version 8.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Primavera Contract Management" Type="Product Name">
               <Branch Name="14.2" Type="Product Version">
                  <FullProductName ProductID="P-5581V-14.2">Primavera Contract Management Version 14.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Retail Applications" Type="Product Family">
            <Branch Name="Retail Integration Bus" Type="Product Name">
               <Branch Name="13.0" Type="Product Version">
                  <FullProductName ProductID="P-1807V-13.0">Retail Integration Bus Version 13.0</FullProductName>
               </Branch>
               <Branch Name="13.1" Type="Product Version">
                  <FullProductName ProductID="P-1807V-13.1">Retail Integration Bus Version 13.1</FullProductName>
               </Branch>
               <Branch Name="13.2" Type="Product Version">
                  <FullProductName ProductID="P-1807V-13.2">Retail Integration Bus Version 13.2</FullProductName>
               </Branch>
               <Branch Name="14.0" Type="Product Version">
                  <FullProductName ProductID="P-1807V-14.0">Retail Integration Bus Version 14.0</FullProductName>
               </Branch>
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-1807V-14.1">Retail Integration Bus Version 14.1</FullProductName>
               </Branch>
               <Branch Name="15.0" Type="Product Version">
                  <FullProductName ProductID="P-1807V-15.0">Retail Integration Bus Version 15.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Store Inventory Management" Type="Product Name">
               <Branch Name="12.0" Type="Product Version">
                  <FullProductName ProductID="P-1838V-12.0">Retail Store Inventory Management Version 12.0</FullProductName>
               </Branch>
               <Branch Name="13.0" Type="Product Version">
                  <FullProductName ProductID="P-1838V-13.0">Retail Store Inventory Management Version 13.0</FullProductName>
               </Branch>
               <Branch Name="13.1" Type="Product Version">
                  <FullProductName ProductID="P-1838V-13.1">Retail Store Inventory Management Version 13.1</FullProductName>
               </Branch>
               <Branch Name="13.2" Type="Product Version">
                  <FullProductName ProductID="P-1838V-13.2">Retail Store Inventory Management Version 13.2</FullProductName>
               </Branch>
               <Branch Name="14.0" Type="Product Version">
                  <FullProductName ProductID="P-1838V-14.0">Retail Store Inventory Management Version 14.0</FullProductName>
               </Branch>
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-1838V-14.1">Retail Store Inventory Management Version 14.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Point-of-Service" Type="Product Name">
               <Branch Name="12.0 13.0" Type="Product Version">
                  <FullProductName ProductID="P-2017V-12.0 13.0">Retail Point-of-Service Version 12.0 13.0</FullProductName>
               </Branch>
               <Branch Name="13.1" Type="Product Version">
                  <FullProductName ProductID="P-2017V-13.1">Retail Point-of-Service Version 13.1</FullProductName>
               </Branch>
               <Branch Name="13.2" Type="Product Version">
                  <FullProductName ProductID="P-2017V-13.2">Retail Point-of-Service Version 13.2</FullProductName>
               </Branch>
               <Branch Name="13.3" Type="Product Version">
                  <FullProductName ProductID="P-2017V-13.3">Retail Point-of-Service Version 13.3</FullProductName>
               </Branch>
               <Branch Name="13.4" Type="Product Version">
                  <FullProductName ProductID="P-2017V-13.4">Retail Point-of-Service Version 13.4</FullProductName>
               </Branch>
               <Branch Name="14.0" Type="Product Version">
                  <FullProductName ProductID="P-2017V-14.0">Retail Point-of-Service Version 14.0</FullProductName>
               </Branch>
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-2017V-14.1">Retail Point-of-Service Version 14.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Service Backbone" Type="Product Name">
               <Branch Name="13.0" Type="Product Version">
                  <FullProductName ProductID="P-10867V-13.0">Retail Service Backbone Version 13.0</FullProductName>
               </Branch>
               <Branch Name="13.1" Type="Product Version">
                  <FullProductName ProductID="P-10867V-13.1">Retail Service Backbone Version 13.1</FullProductName>
               </Branch>
               <Branch Name="13.2" Type="Product Version">
                  <FullProductName ProductID="P-10867V-13.2">Retail Service Backbone Version 13.2</FullProductName>
               </Branch>
               <Branch Name="14.0" Type="Product Version">
                  <FullProductName ProductID="P-10867V-14.0">Retail Service Backbone Version 14.0</FullProductName>
               </Branch>
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-10867V-14.1">Retail Service Backbone Version 14.1</FullProductName>
               </Branch>
               <Branch Name="15.0" Type="Product Version">
                  <FullProductName ProductID="P-10867V-15.0">Retail Service Backbone Version 15.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="XBRi Cloud Service" Type="Product Name">
               <Branch Name="10.0.1" Type="Product Version">
                  <FullProductName ProductID="P-11506V-10.0.1">XBRi Cloud Service Version 10.0.1</FullProductName>
               </Branch>
               <Branch Name="10.5.0" Type="Product Version">
                  <FullProductName ProductID="P-11506V-10.5.0">XBRi Cloud Service Version 10.5.0</FullProductName>
               </Branch>
               <Branch Name="10.6.0" Type="Product Version">
                  <FullProductName ProductID="P-11506V-10.6.0">XBRi Cloud Service Version 10.6.0</FullProductName>
               </Branch>
               <Branch Name="10.7.0" Type="Product Version">
                  <FullProductName ProductID="P-11506V-10.7.0">XBRi Cloud Service Version 10.7.0</FullProductName>
               </Branch>
               <Branch Name="10.8.0" Type="Product Version">
                  <FullProductName ProductID="P-11506V-10.8.0">XBRi Cloud Service Version 10.8.0</FullProductName>
               </Branch>
               <Branch Name="10.8.1" Type="Product Version">
                  <FullProductName ProductID="P-11506V-10.8.1">XBRi Cloud Service Version 10.8.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Order Broker Cloud Service" Type="Product Name">
               <Branch Name="15.0" Type="Product Version">
                  <FullProductName ProductID="P-11520V-15.0">Retail Order Broker Cloud Service Version 15.0</FullProductName>
               </Branch>
               <Branch Name="4.1" Type="Product Version">
                  <FullProductName ProductID="P-11520V-4.1">Retail Order Broker Cloud Service Version 4.1</FullProductName>
               </Branch>
               <Branch Name="5.1" Type="Product Version">
                  <FullProductName ProductID="P-11520V-5.1">Retail Order Broker Cloud Service Version 5.1</FullProductName>
               </Branch>
               <Branch Name="5.2" Type="Product Version">
                  <FullProductName ProductID="P-11520V-5.2">Retail Order Broker Cloud Service Version 5.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Siebel CRM" Type="Product Family">
            <Branch Name="Siebel Core - Server Framework" Type="Product Name">
               <Branch Name="8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-9001V-8.1.1">Siebel Core - Server Framework Version 8.1.1</FullProductName>
               </Branch>
               <Branch Name="8.2.2" Type="Product Version">
                  <FullProductName ProductID="P-9001V-8.2.2">Siebel Core - Server Framework Version 8.2.2</FullProductName>
               </Branch>
               <Branch Name="IP2014" Type="Product Version">
                  <FullProductName ProductID="P-9001V-IP2014">Siebel Core - Server Framework Version IP2014</FullProductName>
               </Branch>
               <Branch Name="IP2015" Type="Product Version">
                  <FullProductName ProductID="P-9001V-IP2015">Siebel Core - Server Framework Version IP2015</FullProductName>
               </Branch>
               <Branch Name="IP2016" Type="Product Version">
                  <FullProductName ProductID="P-9001V-IP2016">Siebel Core - Server Framework Version IP2016</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Siebel UI Framework" Type="Product Name">
               <Branch Name="8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-9011V-8.1.1">Siebel UI Framework Version 8.1.1</FullProductName>
               </Branch>
               <Branch Name="8.2.2" Type="Product Version">
                  <FullProductName ProductID="P-9011V-8.2.2">Siebel UI Framework Version 8.2.2</FullProductName>
               </Branch>
               <Branch Name="IP2014" Type="Product Version">
                  <FullProductName ProductID="P-9011V-IP2014">Siebel UI Framework Version IP2014</FullProductName>
               </Branch>
               <Branch Name="IP2015" Type="Product Version">
                  <FullProductName ProductID="P-9011V-IP2015">Siebel UI Framework Version IP2015</FullProductName>
               </Branch>
               <Branch Name="IP2016" Type="Product Version">
                  <FullProductName ProductID="P-9011V-IP2016">Siebel UI Framework Version IP2016</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Siebel Engineering - Installer and Deployment" Type="Product Name">
               <Branch Name="8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-9023V-8.1.1">Siebel Engineering - Installer and Deployment Version 8.1.1</FullProductName>
               </Branch>
               <Branch Name="8.2.2" Type="Product Version">
                  <FullProductName ProductID="P-9023V-8.2.2">Siebel Engineering - Installer and Deployment Version 8.2.2</FullProductName>
               </Branch>
               <Branch Name="IP2014" Type="Product Version">
                  <FullProductName ProductID="P-9023V-IP2014">Siebel Engineering - Installer and Deployment Version IP2014</FullProductName>
               </Branch>
               <Branch Name="IP2015" Type="Product Version">
                  <FullProductName ProductID="P-9023V-IP2015">Siebel Engineering - Installer and Deployment Version IP2015</FullProductName>
               </Branch>
               <Branch Name="IP2016" Type="Product Version">
                  <FullProductName ProductID="P-9023V-IP2016">Siebel Engineering - Installer and Deployment Version IP2016</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Knowledge" Type="Product Name">
               <Branch Name="8.5.x" Type="Product Version">
                  <FullProductName ProductID="P-9571V-8.5.x">Knowledge Version 8.5.x</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Siebel Core - Common Components" Type="Product Name">
               <Branch Name="8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-9747V-8.1.1">Siebel Core - Common Components Version 8.1.1</FullProductName>
               </Branch>
               <Branch Name="8.2.2" Type="Product Version">
                  <FullProductName ProductID="P-9747V-8.2.2">Siebel Core - Common Components Version 8.2.2</FullProductName>
               </Branch>
               <Branch Name="IP2014" Type="Product Version">
                  <FullProductName ProductID="P-9747V-IP2014">Siebel Core - Common Components Version IP2014</FullProductName>
               </Branch>
               <Branch Name="IP2015" Type="Product Version">
                  <FullProductName ProductID="P-9747V-IP2015">Siebel Core - Common Components Version IP2015</FullProductName>
               </Branch>
               <Branch Name="IP2016" Type="Product Version">
                  <FullProductName ProductID="P-9747V-IP2016">Siebel Core - Common Components Version IP2016</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Sun Systems Products Suite" Type="Product Family">
            <Branch Name="SPARC - OPL Service Processor (XCP)" Type="Product Name">
               <Branch Name="XCP prior to XCP1121" Type="Product Version">
                  <FullProductName ProductID="P-9845V-XCP prior to XCP1121">SPARC - OPL Service Processor (XCP) Version XCP prior to XCP1121</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="SSM - (hot-tamale) ILOM: Integrated Lights Out Manager" Type="Product Name">
               <Branch Name="3.0" Type="Product Version">
                  <FullProductName ProductID="P-9849V-3.0">SSM - (hot-tamale) ILOM: Integrated Lights Out Manager Version 3.0</FullProductName>
               </Branch>
               <Branch Name="3.1" Type="Product Version">
                  <FullProductName ProductID="P-9849V-3.1">SSM - (hot-tamale) ILOM: Integrated Lights Out Manager Version 3.1</FullProductName>
               </Branch>
               <Branch Name="3.2" Type="Product Version">
                  <FullProductName ProductID="P-9849V-3.2">SSM - (hot-tamale) ILOM: Integrated Lights Out Manager Version 3.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="nm2-gw" Type="Product Name">
               <Branch Name="Versions prior to 2.2.2" Type="Product Version">
                  <FullProductName ProductID="P-9885V-Versions prior to 2.2.2">nm2-gw Version Versions prior to 2.2.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="nm2-36p" Type="Product Name">
               <Branch Name="Versions prior to 2.2.2" Type="Product Version">
                  <FullProductName ProductID="P-9886V-Versions prior to 2.2.2">nm2-36p Version Versions prior to 2.2.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="OPUS 10G Ethernet Switch Family" Type="Product Name">
               <Branch Name="1.2" Type="Product Version">
                  <FullProductName ProductID="P-9889V-1.2">OPUS 10G Ethernet Switch Family Version 1.2</FullProductName>
               </Branch>
               <Branch Name="1.3" Type="Product Version">
                  <FullProductName ProductID="P-9889V-1.3">OPUS 10G Ethernet Switch Family Version 1.3</FullProductName>
               </Branch>
               <Branch Name="2.0.0" Type="Product Version">
                  <FullProductName ProductID="P-9889V-2.0.0">OPUS 10G Ethernet Switch Family Version 2.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Solaris Cluster" Type="Product Name">
               <Branch Name="3.3" Type="Product Version">
                  <FullProductName ProductID="P-10005V-3.3">Solaris Cluster Version 3.3</FullProductName>
               </Branch>
               <Branch Name="4.3" Type="Product Version">
                  <FullProductName ProductID="P-10005V-4.3">Solaris Cluster Version 4.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Solaris Operating System" Type="Product Name">
               <Branch Name="10" Type="Product Version">
                  <FullProductName ProductID="P-10006V-10">Solaris Operating System Version 10</FullProductName>
               </Branch>
               <Branch Name="11.3" Type="Product Version">
                  <FullProductName ProductID="P-10006V-11.3">Solaris Operating System Version 11.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Fujitsu M10 Firmware" Type="Product Name">
               <Branch Name="XCP prior to XCP2280" Type="Product Version">
                  <FullProductName ProductID="P-10656V-XCP prior to XCP2280">Fujitsu M10 Firmware Version XCP prior to XCP2280</FullProductName>
               </Branch>
               <Branch Name="XCP prior to XCP2320" Type="Product Version">
                  <FullProductName ProductID="P-10656V-XCP prior to XCP2320">Fujitsu M10 Firmware Version XCP prior to XCP2320</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Supply Chain Products Suite" Type="Product Family">
            <Branch Name="Demand Planning" Type="Product Name">
               <Branch Name="12.1" Type="Product Version">
                  <FullProductName ProductID="P-723V-12.1">Demand Planning Version 12.1</FullProductName>
               </Branch>
               <Branch Name="12.2" Type="Product Version">
                  <FullProductName ProductID="P-723V-12.2">Demand Planning Version 12.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Transportation Management" Type="Product Name">
               <Branch Name="6.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.3.0">Transportation Management Version 6.3.0</FullProductName>
               </Branch>
               <Branch Name="6.3.1" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.3.1">Transportation Management Version 6.3.1</FullProductName>
               </Branch>
               <Branch Name="6.3.2" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.3.2">Transportation Management Version 6.3.2</FullProductName>
               </Branch>
               <Branch Name="6.3.3" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.3.3">Transportation Management Version 6.3.3</FullProductName>
               </Branch>
               <Branch Name="6.3.4" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.3.4">Transportation Management Version 6.3.4</FullProductName>
               </Branch>
               <Branch Name="6.3.5" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.3.5">Transportation Management Version 6.3.5</FullProductName>
               </Branch>
               <Branch Name="6.3.6" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.3.6">Transportation Management Version 6.3.6</FullProductName>
               </Branch>
               <Branch Name="6.3.7" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.3.7">Transportation Management Version 6.3.7</FullProductName>
               </Branch>
               <Branch Name="6.4.0" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.4.0">Transportation Management Version 6.4.0</FullProductName>
               </Branch>
               <Branch Name="6.4.1" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.4.1">Transportation Management Version 6.4.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Agile Engineering Data Management" Type="Product Name">
               <Branch Name="6.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-4436V-6.1.3.0">Agile Engineering Data Management Version 6.1.3.0</FullProductName>
               </Branch>
               <Branch Name="6.2.0.0" Type="Product Version">
                  <FullProductName ProductID="P-4436V-6.2.0.0">Agile Engineering Data Management Version 6.2.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Agile PLM Framework" Type="Product Name">
               <Branch Name="9.3.4" Type="Product Version">
                  <FullProductName ProductID="P-4461V-9.3.4">Agile PLM Framework Version 9.3.4</FullProductName>
               </Branch>
               <Branch Name="9.3.5" Type="Product Version">
                  <FullProductName ProductID="P-4461V-9.3.5">Agile PLM Framework Version 9.3.5</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Utilities Applications" Type="Product Family">
            <Branch Name="Utilities Network Management System" Type="Product Name">
               <Branch Name="1.10.0.6.27" Type="Product Version">
                  <FullProductName ProductID="P-2241V-1.10.0.6.27">Utilities Network Management System Version 1.10.0.6.27</FullProductName>
               </Branch>
               <Branch Name="1.11.0.4.41" Type="Product Version">
                  <FullProductName ProductID="P-2241V-1.11.0.4.41">Utilities Network Management System Version 1.11.0.4.41</FullProductName>
               </Branch>
               <Branch Name="1.11.0.5.4" Type="Product Version">
                  <FullProductName ProductID="P-2241V-1.11.0.5.4">Utilities Network Management System Version 1.11.0.5.4</FullProductName>
               </Branch>
               <Branch Name="1.12.0.1.16" Type="Product Version">
                  <FullProductName ProductID="P-2241V-1.12.0.1.16">Utilities Network Management System Version 1.12.0.1.16</FullProductName>
               </Branch>
               <Branch Name="1.12.0.2.12.1.12.0.3.5" Type="Product Version">
                  <FullProductName ProductID="P-2241V-1.12.0.2.12.1.12.0.3.5">Utilities Network Management System Version 1.12.0.2.12.1.12.0.3.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Utilities Work and Asset Management" Type="Product Name">
               <Branch Name="1.9.1.2.8" Type="Product Version">
                  <FullProductName ProductID="P-2244V-1.9.1.2.8">Utilities Work and Asset Management Version 1.9.1.2.8</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Utilities Framework" Type="Product Name">
               <Branch Name="2.2.0.0.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-2.2.0.0.0">Utilities Framework Version 2.2.0.0.0</FullProductName>
               </Branch>
               <Branch Name="4.1.0.1.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-4.1.0.1.0">Utilities Framework Version 4.1.0.1.0</FullProductName>
               </Branch>
               <Branch Name="4.1.0.2.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-4.1.0.2.0">Utilities Framework Version 4.1.0.2.0</FullProductName>
               </Branch>
               <Branch Name="4.2.0.1.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-4.2.0.1.0">Utilities Framework Version 4.2.0.1.0</FullProductName>
               </Branch>
               <Branch Name="4.2.0.2.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-4.2.0.2.0">Utilities Framework Version 4.2.0.2.0</FullProductName>
               </Branch>
               <Branch Name="4.2.0.3.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-4.2.0.3.0">Utilities Framework Version 4.2.0.3.0</FullProductName>
               </Branch>
               <Branch Name="4.3.0.1.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-4.3.0.1.0">Utilities Framework Version 4.3.0.1.0</FullProductName>
               </Branch>
               <Branch Name="4.3.0.2.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-4.3.0.2.0">Utilities Framework Version 4.3.0.2.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Virtualization" Type="Product Family">
            <Branch Name="Oracle VM VirtualBox" Type="Product Name">
               <Branch Name="VirtualBox prior to 5.0.22" Type="Product Version">
                  <FullProductName ProductID="P-8370V-VirtualBox prior to 5.0.22">Oracle VM VirtualBox Version VirtualBox prior to 5.0.22</FullProductName>
               </Branch>
               <Branch Name="VirtualBox prior to 5.0.26" Type="Product Version">
                  <FullProductName ProductID="P-8370V-VirtualBox prior to 5.0.26">Oracle VM VirtualBox Version VirtualBox prior to 5.0.26</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Secure Global Desktop" Type="Product Name">
               <Branch Name="4.63" Type="Product Version">
                  <FullProductName ProductID="P-8539V-4.63">Secure Global Desktop Version 4.63</FullProductName>
               </Branch>
               <Branch Name="4.71" Type="Product Version">
                  <FullProductName ProductID="P-8539V-4.71">Secure Global Desktop Version 4.71</FullProductName>
               </Branch>
               <Branch Name="5.2" Type="Product Version">
                  <FullProductName ProductID="P-8539V-5.2">Secure Global Desktop Version 5.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
      </Branch>
   </ProductTree>
   <Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3137</Title>
      <Notes>
         <Note Audience="All" Ordinal="1" Title="Details" Type="Details">Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web access).  Supported versions that are affected are 8.2, 8.3 and  8.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera P6 Enterprise Project Portfolio Management accessible data as well as  unauthorized read access to a subset of Primavera P6 Enterprise Project Portfolio Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Primavera P6 Enterprise Project Portfolio Management. CVSS 3.0 Base Score   6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3137</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5579V-8.2</ProductID>
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5579V-8.2</ProductID>
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3410</Title>
      <Notes>
         <Note Audience="All" Ordinal="2" Title="Details" Type="Details">Vulnerability in the ILOM component of Oracle Sun Systems Products Suite (subcomponent: Restricted Shell).  Supported versions that are affected are 3.0, 3.1 and  3.2. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise ILOM.  Successful attacks of this vulnerability can result in takeover of ILOM. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3410</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9849V-3.0</ProductID>
            <ProductID>P-9849V-3.1</ProductID>
            <ProductID>P-9849V-3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9849V-3.0</ProductID>
            <ProductID>P-9849V-3.1</ProductID>
            <ProductID>P-9849V-3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="3" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-2064</Title>
      <Notes>
         <Note Audience="All" Ordinal="3" Title="Details" Type="Details">Vulnerability in the Oracle Secure Global Desktop component of Oracle Virtualization (subcomponent: X Server).  Supported versions that are affected are 4.71 and  5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via X11 to compromise Oracle Secure Global Desktop.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Secure Global Desktop accessible data as well as  unauthorized read access to a subset of Oracle Secure Global Desktop accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Secure Global Desktop. CVSS 3.0 Base Score   7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-2064</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8539V-4.71</ProductID>
            <ProductID>P-8539V-5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8539V-4.71</ProductID>
            <ProductID>P-8539V-5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="4" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-2566</Title>
      <Notes>
         <Note Audience="All" Ordinal="4" Title="Details" Type="Details">Vulnerability in the Fujitsu M10-1, M10-4, M10-4S Servers component of Oracle Sun Systems Products Suite (subcomponent: XCP Firmware).   The supported version that is affected is XCP prior to XCP2280. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSL/TLS to compromise Fujitsu M10-1, M10-4, M10-4S Servers.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Fujitsu M10-1, M10-4, M10-4S Servers accessible data. CVSS 3.0 Base Score   5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-2566</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10656V-XCP prior to XCP2280</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-10656V-XCP prior to XCP2280</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="5" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-0224</Title>
      <Notes>
         <Note Audience="All" Ordinal="5" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Lending and Leasing component of Oracle Financial Services Applications (subcomponent: Admin and setup).  Supported versions that are affected are 14.1  and  14.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Lending and Leasing.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Lending and Leasing accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Lending and Leasing accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Financial Services Lending and Leasing. CVSS 3.0 Base Score   7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-0224</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10484V-14.1</ProductID>
            <ProductID>P-10484V-14.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-10484V-14.1</ProductID>
            <ProductID>P-10484V-14.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="6" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-3566</Title>
      <Notes>
         <Note Audience="All" Ordinal="6" Title="Details" Type="Details">Vulnerability in the Sun Network QDR InfiniBand Gateway Switch component of Oracle Sun Systems Products Suite (subcomponent: Firmware).   The supported version that is affected is Versions prior to 2.2.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Sun Network QDR InfiniBand Gateway Switch.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Sun Network QDR InfiniBand Gateway Switch accessible data. CVSS 3.0 Base Score   3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-3566</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9885V-Versions prior to 2.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9885V-Versions prior to 2.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="7" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-3566</Title>
      <Notes>
         <Note Audience="All" Ordinal="7" Title="Details" Type="Details">Vulnerability in the Sun Data Center InfiniBand Switch 36 component of Oracle Sun Systems Products Suite (subcomponent: Firmware).   The supported version that is affected is Versions prior to 2.2.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Sun Data Center InfiniBand Switch 36.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Sun Data Center InfiniBand Switch 36 accessible data. CVSS 3.0 Base Score   3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-3566</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9886V-Versions prior to 2.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9886V-Versions prior to 2.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="8" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-3571</Title>
      <Notes>
         <Note Audience="All" Ordinal="8" Title="Details" Type="Details">Vulnerability in the Oracle Communications Core Session Manager component of Oracle Communications Applications (subcomponent: Routing).  Supported versions that are affected are 7.2.5 and 7.3.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Communications Core Session Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Core Session Manager. CVSS 3.0 Base Score   7.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-3571</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10754V-7.2.5</ProductID>
            <ProductID>P-10754V-7.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-10754V-7.2.5</ProductID>
            <ProductID>P-10754V-7.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="9" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-9708</Title>
      <Notes>
         <Note Audience="All" Ordinal="9" Title="Details" Type="Details">Vulnerability in the Oracle Enterprise Communications Broker component of Oracle Communications Applications (subcomponent: GUI).   The supported version that is affected is Prior to PCz 2.0.0m4p1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Communications Broker.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Communications Broker. CVSS 3.0 Base Score   5.3 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-9708</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10758V-Prior to PCz 2.0.0m4p1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-10758V-Prior to PCz 2.0.0m4p1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="10" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0204</Title>
      <Notes>
         <Note Audience="All" Ordinal="10" Title="Details" Type="Details">Vulnerability in the RDBMS component of Oracle Database Server.  Supported versions that are affected are 12.1.0.1 and 12.1.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise RDBMS.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all RDBMS accessible data. CVSS 3.0 Base Score   5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0204</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-12.1.0.1</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5V-12.1.0.1</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="11" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0228</Title>
      <Notes>
         <Note Audience="All" Ordinal="11" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Ops Center component of Oracle Enterprise Manager Grid Control (subcomponent: Update Provisioning).  Supported versions that are affected are 12.1.4, 12.2.2 and  12.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Ops Center.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Enterprise Manager Ops Center. CVSS 3.0 Base Score   4.3 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0228</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9835V-12.1.4</ProductID>
            <ProductID>P-9835V-12.2.2</ProductID>
            <ProductID>P-9835V-12.3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9835V-12.1.4</ProductID>
            <ProductID>P-9835V-12.2.2</ProductID>
            <ProductID>P-9835V-12.3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="12" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0235</Title>
      <Notes>
         <Note Audience="All" Ordinal="12" Title="Details" Type="Details">Vulnerability in the Sun Network QDR InfiniBand Gateway Switch component of Oracle Sun Systems Products Suite (subcomponent: Firmware).   The supported version that is affected is Versions prior to 2.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Sun Network QDR InfiniBand Gateway Switch.  Successful attacks of this vulnerability can result in takeover of Sun Network QDR InfiniBand Gateway Switch. CVSS 3.0 Base Score   9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0235</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9885V-Versions prior to 2.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9885V-Versions prior to 2.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="13" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0235</Title>
      <Notes>
         <Note Audience="All" Ordinal="13" Title="Details" Type="Details">Vulnerability in the Sun Data Center InfiniBand Switch 36 component of Oracle Sun Systems Products Suite (subcomponent: Firmware).   The supported version that is affected is Versions prior to 2.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Sun Data Center InfiniBand Switch 36.  Successful attacks of this vulnerability can result in takeover of Sun Data Center InfiniBand Switch 36. CVSS 3.0 Base Score   9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0235</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9886V-Versions prior to 2.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9886V-Versions prior to 2.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="14" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0235</Title>
      <Notes>
         <Note Audience="All" Ordinal="14" Title="Details" Type="Details">Vulnerability in the Oracle Communications EAGLE Application Processor component of Oracle Communications Applications (subcomponent: Other).   The supported version that is affected is 16.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Application Processor.  Successful attacks of this vulnerability can result in takeover of Oracle Communications EAGLE Application Processor. CVSS 3.0 Base Score   9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0235</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11122V-16.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-11122V-16.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="15" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-1791</Title>
      <Notes>
         <Note Audience="All" Ordinal="15" Title="Details" Type="Details">Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Project manager).  Supported versions that are affected are 8.3, 8.4 and  15.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management.  While the vulnerability is in Primavera P6 Enterprise Project Portfolio Management, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera P6 Enterprise Project Portfolio Management accessible data as well as  unauthorized read access to a subset of Primavera P6 Enterprise Project Portfolio Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Primavera P6 Enterprise Project Portfolio Management. CVSS 3.0 Base Score   6.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-1791</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
            <ProductID>P-5579V-15.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
            <ProductID>P-5579V-15.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="16" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-1793</Title>
      <Notes>
         <Note Audience="All" Ordinal="16" Title="Details" Type="Details">Vulnerability in the ILOM component of Oracle Sun Systems Products Suite (subcomponent: OpenSSL).  Supported versions that are affected are 3.0, 3.1 and  3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via SSL/TLS to compromise ILOM.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of ILOM accessible data as well as  unauthorized read access to a subset of ILOM accessible data. CVSS 3.0 Base Score   6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-1793</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9849V-3.0</ProductID>
            <ProductID>P-9849V-3.1</ProductID>
            <ProductID>P-9849V-3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9849V-3.0</ProductID>
            <ProductID>P-9849V-3.1</ProductID>
            <ProductID>P-9849V-3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="17" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-2808</Title>
      <Notes>
         <Note Audience="All" Ordinal="17" Title="Details" Type="Details">Vulnerability in the SPARC Enterprise M3000, M4000, M5000, M8000, M9000 Servers component of Oracle Sun Systems Products Suite (subcomponent: XCP Firmware).   The supported version that is affected is XCP prior to XCP1121. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSL/TLS to compromise SPARC Enterprise M3000, M4000, M5000, M8000, M9000 Servers.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all SPARC Enterprise M3000, M4000, M5000, M8000, M9000 Servers accessible data. CVSS 3.0 Base Score   5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-2808</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9845V-XCP prior to XCP1121</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9845V-XCP prior to XCP1121</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="18" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-2808</Title>
      <Notes>
         <Note Audience="All" Ordinal="18" Title="Details" Type="Details">Vulnerability in the Oracle Communications Policy Management component of Oracle Communications Applications (subcomponent: Security).   The supported version that is affected is Prior to 9.9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Policy Management accessible data. CVSS 3.0 Base Score   3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-2808</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10900V-Prior to 9.9.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-10900V-Prior to 9.9.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="19" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-3183</Title>
      <Notes>
         <Note Audience="All" Ordinal="19" Title="Details" Type="Details">Vulnerability in the SPARC Enterprise M3000, M4000, M5000, M8000, M9000 Servers component of Oracle Sun Systems Products Suite (subcomponent: XCP Firmware).   The supported version that is affected is XCP prior to XCP1121. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise SPARC Enterprise M3000, M4000, M5000, M8000, M9000 Servers.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all SPARC Enterprise M3000, M4000, M5000, M8000, M9000 Servers accessible data. CVSS 3.0 Base Score   6.5 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-3183</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9845V-XCP prior to XCP1121</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9845V-XCP prior to XCP1121</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="20" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-3197</Title>
      <Notes>
         <Note Audience="All" Ordinal="20" Title="Details" Type="Details">Vulnerability in the Oracle Communications Network Charging and Control component of Oracle Communications Applications (subcomponent: DAP, OSD, PI).  Supported versions that are affected are 5.0.2.0.0, 5.0.1.0.0, 5.0.0.2.0, 5.0.0.1.0 and  4.4.1.5.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS/SSL to compromise Oracle Communications Network Charging and Control.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Network Charging and Control accessible data. CVSS 3.0 Base Score   5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-3197</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4623V-5.0.2.0.0</ProductID>
            <ProductID>P-4623V-5.0.1.0.0</ProductID>
            <ProductID>P-4623V-5.0.0.2.0</ProductID>
            <ProductID>P-4623V-5.0.0.1.0</ProductID>
            <ProductID>P-4623V-4.4.1.5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-4623V-5.0.2.0.0</ProductID>
            <ProductID>P-4623V-5.0.1.0.0</ProductID>
            <ProductID>P-4623V-5.0.0.2.0</ProductID>
            <ProductID>P-4623V-5.0.0.1.0</ProductID>
            <ProductID>P-4623V-4.4.1.5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="21" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-3197</Title>
      <Notes>
         <Note Audience="All" Ordinal="21" Title="Details" Type="Details">Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Enterprise Infrastructure SEC).   The supported version that is affected is 9.2.0.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.0 Base Score   5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-3197</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4781V-9.2.0.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-4781V-9.2.0.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="22" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-3197</Title>
      <Notes>
         <Note Audience="All" Ordinal="22" Title="Details" Type="Details">Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Project manager).  Supported versions that are affected are 8.3, 8.4, 15.1 and  15.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Primavera P6 Enterprise Project Portfolio Management accessible data. CVSS 3.0 Base Score   5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-3197</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5580V-8.3</ProductID>
            <ProductID>P-5580V-8.4</ProductID>
            <ProductID>P-5580V-15.1</ProductID>
            <ProductID>P-5580V-15.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5580V-8.3</ProductID>
            <ProductID>P-5580V-8.4</ProductID>
            <ProductID>P-5580V-15.1</ProductID>
            <ProductID>P-5580V-15.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="23" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-3197</Title>
      <Notes>
         <Note Audience="All" Ordinal="23" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Ops Center component of Oracle Enterprise Manager Grid Control (subcomponent: Networking).  Supported versions that are affected are 12.1.4, 
12.2.2 and 
12.3.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSL/TLS to compromise Enterprise Manager Ops Center.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Enterprise Manager Ops Center accessible data. CVSS 3.0 Base Score   5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-3197</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9835V-12.1.4</ProductID>
            <ProductID>P-9835V-12.2.2</ProductID>
            <ProductID>P-9835V-12.3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9835V-12.1.4</ProductID>
            <ProductID>P-9835V-12.2.2</ProductID>
            <ProductID>P-9835V-12.3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="24" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-3197</Title>
      <Notes>
         <Note Audience="All" Ordinal="24" Title="Details" Type="Details">Vulnerability in the 40G 10G 72/64 Ethernet Switch component of Oracle Sun Systems Products Suite (subcomponent: Firmware).   The supported version that is affected is 2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSL/TLS to compromise 40G 10G 72/64 Ethernet Switch.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all 40G 10G 72/64 Ethernet Switch accessible data. CVSS 3.0 Base Score   5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-3197</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9889V-2.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9889V-2.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="25" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-3197</Title>
      <Notes>
         <Note Audience="All" Ordinal="25" Title="Details" Type="Details">Vulnerability in the Oracle Switch ES1-24 component of Oracle Sun Systems Products Suite (subcomponent: Firmware).   The supported version that is affected is 1.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSL/TLS to compromise Oracle Switch ES1-24.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Switch ES1-24 accessible data. CVSS 3.0 Base Score   5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-3197</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9889V-1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9889V-1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="26" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-3197</Title>
      <Notes>
         <Note Audience="All" Ordinal="26" Title="Details" Type="Details">Vulnerability in the Sun Blade 6000 Ethernet Switched NEM 24P 10GE component of Oracle Sun Systems Products Suite (subcomponent: Firmware).   The supported version that is affected is 1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSL/TLS to compromise Sun Blade 6000 Ethernet Switched NEM 24P 10GE.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Sun Blade 6000 Ethernet Switched NEM 24P 10GE accessible data. CVSS 3.0 Base Score   5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-3197</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9889V-1.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9889V-1.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="27" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-3197</Title>
      <Notes>
         <Note Audience="All" Ordinal="27" Title="Details" Type="Details">Vulnerability in the Sun Network 10GE Switch 72p component of Oracle Sun Systems Products Suite (subcomponent: Firmware).   The supported version that is affected is 1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSL/TLS to compromise Sun Network 10GE Switch 72p.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Sun Network 10GE Switch 72p accessible data. CVSS 3.0 Base Score   5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-3197</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9889V-1.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9889V-1.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="28" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-3237</Title>
      <Notes>
         <Note Audience="All" Ordinal="28" Title="Details" Type="Details">Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Administration).  Supported versions that are affected are 3.0.1 and  3.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GlassFish Server.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle GlassFish Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GlassFish Server. CVSS 3.0 Base Score   6.5 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-3237</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8493V-3.0.1</ProductID>
            <ProductID>P-8493V-3.1.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8493V-3.0.1</ProductID>
            <ProductID>P-8493V-3.1.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="29" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-3237</Title>
      <Notes>
         <Note Audience="All" Ordinal="29" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Ops Center component of Oracle Enterprise Manager Grid Control (subcomponent: Networking).  Supported versions that are affected are 12.1.4, 
12.2.2 and 
12.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Ops Center.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Enterprise Manager Ops Center accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Enterprise Manager Ops Center. CVSS 3.0 Base Score   6.5 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-3237</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9835V-12.1.4</ProductID>
            <ProductID>P-9835V-12.2.2</ProductID>
            <ProductID>P-9835V-12.3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9835V-12.1.4</ProductID>
            <ProductID>P-9835V-12.2.2</ProductID>
            <ProductID>P-9835V-12.3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="30" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-3253</Title>
      <Notes>
         <Note Audience="All" Ordinal="30" Title="Details" Type="Details">Vulnerability in the Oracle Retail Store Inventory Management component of Oracle Retail Applications (subcomponent: SIMINT).  Supported versions that are affected are 13.2, 14.0 and  14.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Store Inventory Management.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Store Inventory Management. CVSS 3.0 Base Score   9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-3253</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1838V-13.2</ProductID>
            <ProductID>P-1838V-14.0</ProductID>
            <ProductID>P-1838V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1838V-13.2</ProductID>
            <ProductID>P-1838V-14.0</ProductID>
            <ProductID>P-1838V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="31" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-3253</Title>
      <Notes>
         <Note Audience="All" Ordinal="31" Title="Details" Type="Details">Vulnerability in the Oracle Health Sciences Clinical Development Center component of Oracle Health Sciences Applications (subcomponent: Installation and configuration).  Supported versions that are affected are 3.1.1.x and  3.1.2.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Health Sciences Clinical Development Center.  Successful attacks of this vulnerability can result in takeover of Oracle Health Sciences Clinical Development Center. CVSS 3.0 Base Score   9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-3253</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9652V-3.1.1.x</ProductID>
            <ProductID>P-9652V-3.1.2.x</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9652V-3.1.1.x</ProductID>
            <ProductID>P-9652V-3.1.2.x</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="32" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-3253</Title>
      <Notes>
         <Note Audience="All" Ordinal="32" Title="Details" Type="Details">Vulnerability in the Oracle Retail Service Backbone component of Oracle Retail Applications (subcomponent: Install).  Supported versions that are affected are 13.0, 13.1, 13.2, 14.0, 14.1 and 15.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Service Backbone. CVSS 3.0 Base Score   9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-3253</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10867V-13.0</ProductID>
            <ProductID>P-10867V-13.1</ProductID>
            <ProductID>P-10867V-13.2</ProductID>
            <ProductID>P-10867V-14.0</ProductID>
            <ProductID>P-10867V-14.1</ProductID>
            <ProductID>P-10867V-15.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-10867V-13.0</ProductID>
            <ProductID>P-10867V-13.1</ProductID>
            <ProductID>P-10867V-13.2</ProductID>
            <ProductID>P-10867V-14.0</ProductID>
            <ProductID>P-10867V-14.1</ProductID>
            <ProductID>P-10867V-15.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="33" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-3253</Title>
      <Notes>
         <Note Audience="All" Ordinal="33" Title="Details" Type="Details">Vulnerability in the Oracle Retail Order Broker component of Oracle Retail Applications (subcomponent: System Administration).  Supported versions that are affected are 4.1, 5.1, 5.2 and  15.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Order Broker.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Order Broker. CVSS 3.0 Base Score   9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-3253</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11520V-4.1</ProductID>
            <ProductID>P-11520V-5.1</ProductID>
            <ProductID>P-11520V-5.2</ProductID>
            <ProductID>P-11520V-15.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-11520V-4.1</ProductID>
            <ProductID>P-11520V-5.1</ProductID>
            <ProductID>P-11520V-5.2</ProductID>
            <ProductID>P-11520V-15.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="34" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-5300</Title>
      <Notes>
         <Note Audience="All" Ordinal="34" Title="Details" Type="Details">Vulnerability in the Oracle Communications Session Border Controller component of Oracle Communications Applications (subcomponent: System).  Supported versions that are affected are 7.2.0 and  7.3.0. Difficult to exploit vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Communications Session Border Controller executes to compromise Oracle Communications Session Border Controller.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Session Border Controller accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Session Border Controller. CVSS 3.0 Base Score   3.7 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-5300</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10750V-7.2.0</ProductID>
            <ProductID>P-10750V-7.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-10750V-7.2.0</ProductID>
            <ProductID>P-10750V-7.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="35" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-5600</Title>
      <Notes>
         <Note Audience="All" Ordinal="35" Title="Details" Type="Details">Vulnerability in the ILOM component of Oracle Sun Systems Products Suite (subcomponent: SSH).  Supported versions that are affected are 3.0, 3.1 and  3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via SSH to compromise ILOM.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of ILOM and  unauthorized read access to a subset of ILOM accessible data. CVSS 3.0 Base Score   8.2 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-5600</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9849V-3.0</ProductID>
            <ProductID>P-9849V-3.1</ProductID>
            <ProductID>P-9849V-3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9849V-3.0</ProductID>
            <ProductID>P-9849V-3.1</ProductID>
            <ProductID>P-9849V-3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="36" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7182</Title>
      <Notes>
         <Note Audience="All" Ordinal="36" Title="Details" Type="Details">Vulnerability in the Oracle Communications Messaging Server component of Oracle Communications Applications (subcomponent: Security).  Supported versions that are affected are Prior to 7.0.5.37.0 and 8.0.1.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Messaging Server.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Messaging Server. CVSS 3.0 Base Score   9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7182</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8496V-Prior to 7.0.5.37.0 and 8.0.1.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8496V-Prior to 7.0.5.37.0 and 8.0.1.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="37" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7182</Title>
      <Notes>
         <Note Audience="All" Ordinal="37" Title="Details" Type="Details">Vulnerability in the Oracle Directory Server Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Admin Server).  Supported versions that are affected are 7.0 and  11.1.1.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Directory Server Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Directory Server Enterprise Edition. CVSS 3.0 Base Score   9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7182</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8512V-7.0</ProductID>
            <ProductID>P-8512V-11.1.1.7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8512V-7.0</ProductID>
            <ProductID>P-8512V-11.1.1.7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="38" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7501</Title>
      <Notes>
         <Note Audience="All" Ordinal="38" Title="Details" Type="Details">Vulnerability in the Oracle Retail Store Inventory Management component of Oracle Retail Applications (subcomponent: SIMINT).  Supported versions that are affected are 12.0, 13.0, 13.1, 13.2, 14.0 and  14.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Store Inventory Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Retail Store Inventory Management accessible data as well as  unauthorized read access to a subset of Oracle Retail Store Inventory Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Store Inventory Management. CVSS 3.0 Base Score   6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1838V-12.0</ProductID>
            <ProductID>P-1838V-13.0</ProductID>
            <ProductID>P-1838V-13.1</ProductID>
            <ProductID>P-1838V-13.2</ProductID>
            <ProductID>P-1838V-14.0</ProductID>
            <ProductID>P-1838V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1838V-12.0</ProductID>
            <ProductID>P-1838V-13.0</ProductID>
            <ProductID>P-1838V-13.1</ProductID>
            <ProductID>P-1838V-13.2</ProductID>
            <ProductID>P-1838V-14.0</ProductID>
            <ProductID>P-1838V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="39" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7501</Title>
      <Notes>
         <Note Audience="All" Ordinal="39" Title="Details" Type="Details">Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suite (subcomponent: Web Container).  Supported versions that are affected are 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.4.0 and  6.4.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management.  Successful attacks of this vulnerability can result in takeover of Oracle Transportation Management. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1991V-6.3.0</ProductID>
            <ProductID>P-1991V-6.3.1</ProductID>
            <ProductID>P-1991V-6.3.2</ProductID>
            <ProductID>P-1991V-6.3.3</ProductID>
            <ProductID>P-1991V-6.3.4</ProductID>
            <ProductID>P-1991V-6.3.5</ProductID>
            <ProductID>P-1991V-6.3.6</ProductID>
            <ProductID>P-1991V-6.3.7</ProductID>
            <ProductID>P-1991V-6.4.0</ProductID>
            <ProductID>P-1991V-6.4.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1991V-6.3.0</ProductID>
            <ProductID>P-1991V-6.3.1</ProductID>
            <ProductID>P-1991V-6.3.2</ProductID>
            <ProductID>P-1991V-6.3.3</ProductID>
            <ProductID>P-1991V-6.3.4</ProductID>
            <ProductID>P-1991V-6.3.5</ProductID>
            <ProductID>P-1991V-6.3.6</ProductID>
            <ProductID>P-1991V-6.3.7</ProductID>
            <ProductID>P-1991V-6.4.0</ProductID>
            <ProductID>P-1991V-6.4.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="40" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7501</Title>
      <Notes>
         <Note Audience="All" Ordinal="40" Title="Details" Type="Details">Vulnerability in the Oracle Retail Central, Back Office, Returns Management component of Oracle Retail Applications (subcomponent: Install).  Supported versions that are affected are 12.0 13.0, 13.1, 13.2, 13.3, 13.4, 14.0 and  14.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Central, Back Office, Returns Management.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Central, Back Office, Returns Management. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2017V-12.0 13.0</ProductID>
            <ProductID>P-2017V-13.1</ProductID>
            <ProductID>P-2017V-13.2</ProductID>
            <ProductID>P-2017V-13.3</ProductID>
            <ProductID>P-2017V-13.4</ProductID>
            <ProductID>P-2017V-14.0</ProductID>
            <ProductID>P-2017V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-2017V-12.0 13.0</ProductID>
            <ProductID>P-2017V-13.1</ProductID>
            <ProductID>P-2017V-13.2</ProductID>
            <ProductID>P-2017V-13.3</ProductID>
            <ProductID>P-2017V-13.4</ProductID>
            <ProductID>P-2017V-14.0</ProductID>
            <ProductID>P-2017V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="41" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7501</Title>
      <Notes>
         <Note Audience="All" Ordinal="41" Title="Details" Type="Details">Vulnerability in the Oracle Utilities Network Management System component of Oracle Utilities Applications (subcomponent: System wide).  Supported versions that are affected are 1.10.0.6.27, 
1.11.0.4.41, 
1.11.0.5.4, 
1.12.0.1.16 and 
1.12.0.2.12.
1.12.0.3.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Utilities Network Management System.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Network Management System. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2241V-1.10.0.6.27</ProductID>
            <ProductID>P-2241V-1.11.0.4.41</ProductID>
            <ProductID>P-2241V-1.11.0.5.4</ProductID>
            <ProductID>P-2241V-1.12.0.1.16</ProductID>
            <ProductID>P-2241V-1.12.0.2.12.1.12.0.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-2241V-1.10.0.6.27</ProductID>
            <ProductID>P-2241V-1.11.0.4.41</ProductID>
            <ProductID>P-2241V-1.11.0.5.4</ProductID>
            <ProductID>P-2241V-1.12.0.1.16</ProductID>
            <ProductID>P-2241V-1.12.0.2.12.1.12.0.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="42" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7501</Title>
      <Notes>
         <Note Audience="All" Ordinal="42" Title="Details" Type="Details">Vulnerability in the Oracle Utilities Work and Asset Management component of Oracle Utilities Applications (subcomponent: Integrations).   The supported version that is affected is 1.9.1.2.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Utilities Work and Asset Management.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Work and Asset Management. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2244V-1.9.1.2.8</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-2244V-1.9.1.2.8</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="43" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7501</Title>
      <Notes>
         <Note Audience="All" Ordinal="43" Title="Details" Type="Details">Vulnerability in the Oracle Utilities Framework component of Oracle Utilities Applications (subcomponent: System wide).  Supported versions that are affected are 2.2.0.0.0, 4.1.0.1.0, 4.1.0.2.0,  4.2.0.1.0, 4.2.0.2.0, 4.2.0.3.0, 4.3.0.1.0 and  
4.3.0.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Utilities Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Framework. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2245V-2.2.0.0.0</ProductID>
            <ProductID>P-2245V-4.1.0.1.0</ProductID>
            <ProductID>P-2245V-4.1.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.1.0</ProductID>
            <ProductID>P-2245V-4.2.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.3.0</ProductID>
            <ProductID>P-2245V-4.3.0.1.0</ProductID>
            <ProductID>P-2245V-4.3.0.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-2245V-2.2.0.0.0</ProductID>
            <ProductID>P-2245V-4.1.0.1.0</ProductID>
            <ProductID>P-2245V-4.1.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.1.0</ProductID>
            <ProductID>P-2245V-4.2.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.3.0</ProductID>
            <ProductID>P-2245V-4.3.0.1.0</ProductID>
            <ProductID>P-2245V-4.3.0.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="44" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7501</Title>
      <Notes>
         <Note Audience="All" Ordinal="44" Title="Details" Type="Details">Vulnerability in the Oracle Communications ASAP component of Oracle Communications Applications (subcomponent: Service request translator).  Supported versions that are affected are 7.0, 7.2 and  7.3. Easily exploitable vulnerability allows low privileged attacker with network access via T3 to compromise Oracle Communications ASAP.  Successful attacks of this vulnerability can result in takeover of Oracle Communications ASAP. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2260V-7.0</ProductID>
            <ProductID>P-2260V-7.2</ProductID>
            <ProductID>P-2260V-7.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-2260V-7.0</ProductID>
            <ProductID>P-2260V-7.2</ProductID>
            <ProductID>P-2260V-7.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="45" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7501</Title>
      <Notes>
         <Note Audience="All" Ordinal="45" Title="Details" Type="Details">Vulnerability in the Oracle Insurance Policy Administration J2EE component of Oracle Insurance Applications (subcomponent: Architecture).  Supported versions that are affected are 9.6.1, 
9.7.1, 
10.0.1, 
10.1.2, 
10.2.0 and 
10.2.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Insurance Policy Administration J2EE.  Successful attacks of this vulnerability can result in takeover of Oracle Insurance Policy Administration J2EE. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5279V-9.6.1</ProductID>
            <ProductID>P-5279V-9.7.1</ProductID>
            <ProductID>P-5279V-10.0.1</ProductID>
            <ProductID>P-5279V-10.1.2</ProductID>
            <ProductID>P-5279V-10.2.0</ProductID>
            <ProductID>P-5279V-10.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5279V-9.6.1</ProductID>
            <ProductID>P-5279V-9.7.1</ProductID>
            <ProductID>P-5279V-10.0.1</ProductID>
            <ProductID>P-5279V-10.1.2</ProductID>
            <ProductID>P-5279V-10.2.0</ProductID>
            <ProductID>P-5279V-10.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="46" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7501</Title>
      <Notes>
         <Note Audience="All" Ordinal="46" Title="Details" Type="Details">Vulnerability in the Oracle Insurance Rules Palette component of Oracle Insurance Applications (subcomponent: Architecture).  Supported versions that are affected are 9.6.1, 
9.7.1, 
10.0.1, 
10.1.2, 
10.2.0 and 
10.2.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Insurance Rules Palette.  Successful attacks of this vulnerability can result in takeover of Oracle Insurance Rules Palette. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5288V-9.6.1</ProductID>
            <ProductID>P-5288V-9.7.1</ProductID>
            <ProductID>P-5288V-10.0.1</ProductID>
            <ProductID>P-5288V-10.1.2</ProductID>
            <ProductID>P-5288V-10.2.0</ProductID>
            <ProductID>P-5288V-10.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5288V-9.6.1</ProductID>
            <ProductID>P-5288V-9.7.1</ProductID>
            <ProductID>P-5288V-10.0.1</ProductID>
            <ProductID>P-5288V-10.1.2</ProductID>
            <ProductID>P-5288V-10.2.0</ProductID>
            <ProductID>P-5288V-10.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="47" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7501</Title>
      <Notes>
         <Note Audience="All" Ordinal="47" Title="Details" Type="Details">Vulnerability in the Oracle Documaker component of Oracle Insurance Applications (subcomponent: Development tools).   The supported version that is affected is Prior to 12.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Documaker.  Successful attacks of this vulnerability can result in takeover of Oracle Documaker. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5477V-Prior to 12.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5477V-Prior to 12.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="48" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7501</Title>
      <Notes>
         <Note Audience="All" Ordinal="48" Title="Details" Type="Details">Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web access).  Supported versions that are affected are 8.2, 8.3, 8.4, 15.1, 15.2 and  16.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management.  Successful attacks of this vulnerability can result in takeover of Primavera P6 Enterprise Project Portfolio Management. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5579V-8.2</ProductID>
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
            <ProductID>P-5579V-15.1</ProductID>
            <ProductID>P-5579V-15.2</ProductID>
            <ProductID>P-5579V-16.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5579V-8.2</ProductID>
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
            <ProductID>P-5579V-15.1</ProductID>
            <ProductID>P-5579V-15.2</ProductID>
            <ProductID>P-5579V-16.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="49" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7501</Title>
      <Notes>
         <Note Audience="All" Ordinal="49" Title="Details" Type="Details">Vulnerability in the Primavera Contract Management component of Oracle Primavera Products Suite (subcomponent: PCM application).   The supported version that is affected is 14.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera Contract Management.  Successful attacks of this vulnerability can result in takeover of Primavera Contract Management. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5581V-14.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5581V-14.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="50" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7501</Title>
      <Notes>
         <Note Audience="All" Ordinal="50" Title="Details" Type="Details">Vulnerability in the Oracle Policy Automation component of Oracle Policy Automation (subcomponent: Determinations Engine).  Supported versions that are affected are 10.3.0, 10.3.1, 10.4.0, 10.4.1, 10.4.2, 10.4.3, 10.4.4, 10.4.5, 10.4.6, 12.1.0 and  12.1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Policy Automation.  Successful attacks of this vulnerability can result in takeover of Oracle Policy Automation. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5624V-10.3.0</ProductID>
            <ProductID>P-5624V-10.3.1</ProductID>
            <ProductID>P-5624V-10.4.0</ProductID>
            <ProductID>P-5624V-10.4.1</ProductID>
            <ProductID>P-5624V-10.4.2</ProductID>
            <ProductID>P-5624V-10.4.3</ProductID>
            <ProductID>P-5624V-10.4.4</ProductID>
            <ProductID>P-5624V-10.4.5</ProductID>
            <ProductID>P-5624V-10.4.6</ProductID>
            <ProductID>P-5624V-12.1.0</ProductID>
            <ProductID>P-5624V-12.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5624V-10.3.0</ProductID>
            <ProductID>P-5624V-10.3.1</ProductID>
            <ProductID>P-5624V-10.4.0</ProductID>
            <ProductID>P-5624V-10.4.1</ProductID>
            <ProductID>P-5624V-10.4.2</ProductID>
            <ProductID>P-5624V-10.4.3</ProductID>
            <ProductID>P-5624V-10.4.4</ProductID>
            <ProductID>P-5624V-10.4.5</ProductID>
            <ProductID>P-5624V-10.4.6</ProductID>
            <ProductID>P-5624V-12.1.0</ProductID>
            <ProductID>P-5624V-12.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="51" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7501</Title>
      <Notes>
         <Note Audience="All" Ordinal="51" Title="Details" Type="Details">Vulnerability in the Oracle Policy Automation for Mobile Devices component of Oracle Policy Automation (subcomponent: Mobile Application).   The supported version that is affected is 12.1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Policy Automation for Mobile Devices.  Successful attacks of this vulnerability can result in takeover of Oracle Policy Automation for Mobile Devices. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5626V-12.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5626V-12.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="52" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7501</Title>
      <Notes>
         <Note Audience="All" Ordinal="52" Title="Details" Type="Details">Vulnerability in the Oracle Policy Automation Connector for Siebel component of Oracle Policy Automation (subcomponent: Determinations Server).  Supported versions that are affected are 10.3.0, 10.4.0, 10.4.1, 10.4.2, 10.4.3, 10.4.4, 10.4.5 and  10.4.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Policy Automation Connector for Siebel.  Successful attacks of this vulnerability can result in takeover of Oracle Policy Automation Connector for Siebel. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5627V-10.3.0</ProductID>
            <ProductID>P-5627V-10.4.0</ProductID>
            <ProductID>P-5627V-10.4.1</ProductID>
            <ProductID>P-5627V-10.4.2</ProductID>
            <ProductID>P-5627V-10.4.3</ProductID>
            <ProductID>P-5627V-10.4.4</ProductID>
            <ProductID>P-5627V-10.4.5</ProductID>
            <ProductID>P-5627V-10.4.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5627V-10.3.0</ProductID>
            <ProductID>P-5627V-10.4.0</ProductID>
            <ProductID>P-5627V-10.4.1</ProductID>
            <ProductID>P-5627V-10.4.2</ProductID>
            <ProductID>P-5627V-10.4.3</ProductID>
            <ProductID>P-5627V-10.4.4</ProductID>
            <ProductID>P-5627V-10.4.5</ProductID>
            <ProductID>P-5627V-10.4.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="53" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7501</Title>
      <Notes>
         <Note Audience="All" Ordinal="53" Title="Details" Type="Details">Vulnerability in the Oracle Banking Platform component of Oracle Financial Services Applications (subcomponent: Rules collections).  Supported versions that are affected are 2.3.0, 2.4.0 and  2.4.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Platform. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9178V-2.3.0</ProductID>
            <ProductID>P-9178V-2.4.0</ProductID>
            <ProductID>P-9178V-2.4.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9178V-2.3.0</ProductID>
            <ProductID>P-9178V-2.4.0</ProductID>
            <ProductID>P-9178V-2.4.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="54" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7501</Title>
      <Notes>
         <Note Audience="All" Ordinal="54" Title="Details" Type="Details">Vulnerability in the Oracle Healthcare Analytics Data Integration component of Oracle Health Sciences Applications (subcomponent: Self Service Analytics).   The supported version that is affected is 3.1.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Healthcare Analytics Data Integration.  Successful attacks of this vulnerability can result in takeover of Oracle Healthcare Analytics Data Integration. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9314V-3.1.0.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9314V-3.1.0.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="55" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7501</Title>
      <Notes>
         <Note Audience="All" Ordinal="55" Title="Details" Type="Details">Vulnerability in the Oracle Health Sciences Clinical Development Center component of Oracle Health Sciences Applications (subcomponent: Installation and configuration).  Supported versions that are affected are 3.1.1.x and  3.1.2.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Health Sciences Clinical Development Center.  Successful attacks of this vulnerability can result in takeover of Oracle Health Sciences Clinical Development Center. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9652V-3.1.1.x</ProductID>
            <ProductID>P-9652V-3.1.2.x</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9652V-3.1.1.x</ProductID>
            <ProductID>P-9652V-3.1.2.x</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="56" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7501</Title>
      <Notes>
         <Note Audience="All" Ordinal="56" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Ops Center component of Oracle Enterprise Manager Grid Control (subcomponent: Enterprise Controller Install).  Supported versions that are affected are 12.1.4, 
12.2.2 and 
12.3.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Enterprise Manager Ops Center.  Successful attacks of this vulnerability can result in takeover of Enterprise Manager Ops Center. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9835V-12.1.4</ProductID>
            <ProductID>P-9835V-12.2.2</ProductID>
            <ProductID>P-9835V-12.3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9835V-12.1.4</ProductID>
            <ProductID>P-9835V-12.2.2</ProductID>
            <ProductID>P-9835V-12.3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="57" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7501</Title>
      <Notes>
         <Note Audience="All" Ordinal="57" Title="Details" Type="Details">Vulnerability in the Oracle Insurance Calculation Engine component of Oracle Insurance Applications (subcomponent: Architecture).  Supported versions that are affected are 9.7.1, 
10.1.2 and 
10.2.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Insurance Calculation Engine.  Successful attacks of this vulnerability can result in takeover of Oracle Insurance Calculation Engine. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10837V-9.7.1</ProductID>
            <ProductID>P-10837V-10.1.2</ProductID>
            <ProductID>P-10837V-10.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-10837V-9.7.1</ProductID>
            <ProductID>P-10837V-10.1.2</ProductID>
            <ProductID>P-10837V-10.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="58" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7501</Title>
      <Notes>
         <Note Audience="All" Ordinal="58" Title="Details" Type="Details">Vulnerability in the Oracle Retail Service Backbone component of Oracle Retail Applications (subcomponent: Install).   The supported version that is affected is 15.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Service Backbone. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10867V-15.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-10867V-15.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="59" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7501</Title>
      <Notes>
         <Note Audience="All" Ordinal="59" Title="Details" Type="Details">Vulnerability in the Oracle In-Memory Policy Analytics component of Oracle Policy Automation (subcomponent: Analysis Server).   The supported version that is affected is 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle In-Memory Policy Analytics.  Successful attacks of this vulnerability can result in takeover of Oracle In-Memory Policy Analytics. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11368V-12.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-11368V-12.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="60" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7501</Title>
      <Notes>
         <Note Audience="All" Ordinal="60" Title="Details" Type="Details">Vulnerability in the MICROS Retail XBRi Loss Prevention component of Oracle Retail Applications (subcomponent: Retail).  Supported versions that are affected are 10.0.1, 10.5.0, 10.6.0, 10.7.0, 10.8.0 and  10.8.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise MICROS Retail XBRi Loss Prevention.  Successful attacks of this vulnerability can result in takeover of MICROS Retail XBRi Loss Prevention. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11506V-10.0.1</ProductID>
            <ProductID>P-11506V-10.5.0</ProductID>
            <ProductID>P-11506V-10.6.0</ProductID>
            <ProductID>P-11506V-10.7.0</ProductID>
            <ProductID>P-11506V-10.8.0</ProductID>
            <ProductID>P-11506V-10.8.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-11506V-10.0.1</ProductID>
            <ProductID>P-11506V-10.5.0</ProductID>
            <ProductID>P-11506V-10.6.0</ProductID>
            <ProductID>P-11506V-10.7.0</ProductID>
            <ProductID>P-11506V-10.8.0</ProductID>
            <ProductID>P-11506V-10.8.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="61" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-8104</Title>
      <Notes>
         <Note Audience="All" Ordinal="61" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Solaris Kernel Zones).   The supported version that is affected is 11.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris.  While the vulnerability is in Solaris, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Solaris. CVSS 3.0 Base Score   6.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-8104</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-10006V-11.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="62" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0635</Title>
      <Notes>
         <Note Audience="All" Ordinal="62" Title="Details" Type="Details">Vulnerability in the Oracle Retail Integration Bus component of Oracle Retail Applications (subcomponent: Install).   The supported version that is affected is 15.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0635</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1807V-15.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1807V-15.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="63" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0635</Title>
      <Notes>
         <Note Audience="All" Ordinal="63" Title="Details" Type="Details">Vulnerability in the Oracle Insurance Policy Administration J2EE component of Oracle Insurance Applications (subcomponent: Architecture).  Supported versions that are affected are 9.6.1, 
9.7.1, 
10.0.1, 
10.1.2, 
10.2.0 and 
10.2.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Insurance Policy Administration J2EE.  Successful attacks of this vulnerability can result in takeover of Oracle Insurance Policy Administration J2EE. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0635</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5279V-9.6.1</ProductID>
            <ProductID>P-5279V-9.7.1</ProductID>
            <ProductID>P-5279V-10.0.1</ProductID>
            <ProductID>P-5279V-10.1.2</ProductID>
            <ProductID>P-5279V-10.2.0</ProductID>
            <ProductID>P-5279V-10.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5279V-9.6.1</ProductID>
            <ProductID>P-5279V-9.7.1</ProductID>
            <ProductID>P-5279V-10.0.1</ProductID>
            <ProductID>P-5279V-10.1.2</ProductID>
            <ProductID>P-5279V-10.2.0</ProductID>
            <ProductID>P-5279V-10.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="64" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0635</Title>
      <Notes>
         <Note Audience="All" Ordinal="64" Title="Details" Type="Details">Vulnerability in the Oracle Insurance Rules Palette component of Oracle Insurance Applications (subcomponent: Architecture).  Supported versions that are affected are 9.6.1, 
9.7.1, 
10.0.1, 
10.1.2, 
10.2.0 and 
10.2.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Insurance Rules Palette.  Successful attacks of this vulnerability can result in takeover of Oracle Insurance Rules Palette. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0635</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5288V-9.6.1</ProductID>
            <ProductID>P-5288V-9.7.1</ProductID>
            <ProductID>P-5288V-10.0.1</ProductID>
            <ProductID>P-5288V-10.1.2</ProductID>
            <ProductID>P-5288V-10.2.0</ProductID>
            <ProductID>P-5288V-10.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5288V-9.6.1</ProductID>
            <ProductID>P-5288V-9.7.1</ProductID>
            <ProductID>P-5288V-10.0.1</ProductID>
            <ProductID>P-5288V-10.1.2</ProductID>
            <ProductID>P-5288V-10.2.0</ProductID>
            <ProductID>P-5288V-10.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="65" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0635</Title>
      <Notes>
         <Note Audience="All" Ordinal="65" Title="Details" Type="Details">Vulnerability in the Oracle Documaker component of Oracle Insurance Applications (subcomponent: Development tools).   The supported version that is affected is Prior to 12.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Documaker.  Successful attacks of this vulnerability can result in takeover of Oracle Documaker. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0635</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5477V-Prior to 12.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5477V-Prior to 12.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="66" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0635</Title>
      <Notes>
         <Note Audience="All" Ordinal="66" Title="Details" Type="Details">Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web access).  Supported versions that are affected are 8.2, 8.3, 8.4, 15.1, 15.2 and  16.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management.  Successful attacks of this vulnerability can result in takeover of Primavera P6 Enterprise Project Portfolio Management. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0635</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5579V-8.2</ProductID>
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
            <ProductID>P-5579V-15.1</ProductID>
            <ProductID>P-5579V-15.2</ProductID>
            <ProductID>P-5579V-16.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5579V-8.2</ProductID>
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
            <ProductID>P-5579V-15.1</ProductID>
            <ProductID>P-5579V-15.2</ProductID>
            <ProductID>P-5579V-16.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="67" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0635</Title>
      <Notes>
         <Note Audience="All" Ordinal="67" Title="Details" Type="Details">Vulnerability in the Primavera Contract Management component of Oracle Primavera Products Suite (subcomponent: PCM web services).   The supported version that is affected is 14.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera Contract Management.  Successful attacks of this vulnerability can result in takeover of Primavera Contract Management. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0635</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5581V-14.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5581V-14.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="68" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0635</Title>
      <Notes>
         <Note Audience="All" Ordinal="68" Title="Details" Type="Details">Vulnerability in the Oracle Healthcare Master Person Index component of Oracle Health Sciences Applications (subcomponent: Internal operations).  Supported versions that are affected are 2.0.12, 3.0.0 and  4.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Healthcare Master Person Index.  Successful attacks of this vulnerability can result in takeover of Oracle Healthcare Master Person Index. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0635</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8575V-2.0.12</ProductID>
            <ProductID>P-8575V-3.0.0</ProductID>
            <ProductID>P-8575V-4.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8575V-2.0.12</ProductID>
            <ProductID>P-8575V-3.0.0</ProductID>
            <ProductID>P-8575V-4.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="69" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0635</Title>
      <Notes>
         <Note Audience="All" Ordinal="69" Title="Details" Type="Details">Vulnerability in the Oracle Health Sciences Information Manager component of Oracle Health Sciences Applications (subcomponent: Health Policy Monitor).  Supported versions that are affected are 1.2.8.3, 2.0.2.3 and  3.0.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via TLS, UDP to compromise Oracle Health Sciences Information Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Health Sciences Information Manager. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0635</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9177V-1.2.8.3</ProductID>
            <ProductID>P-9177V-2.0.2.3</ProductID>
            <ProductID>P-9177V-3.0.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9177V-1.2.8.3</ProductID>
            <ProductID>P-9177V-2.0.2.3</ProductID>
            <ProductID>P-9177V-3.0.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="70" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0635</Title>
      <Notes>
         <Note Audience="All" Ordinal="70" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Ops Center component of Oracle Enterprise Manager Grid Control (subcomponent: Framework).  Supported versions that are affected are 12.1.4, 12.2.2 and  12.3.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Enterprise Manager Ops Center.  Successful attacks of this vulnerability can result in takeover of Enterprise Manager Ops Center. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0635</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9835V-12.1.4</ProductID>
            <ProductID>P-9835V-12.2.2</ProductID>
            <ProductID>P-9835V-12.3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9835V-12.1.4</ProductID>
            <ProductID>P-9835V-12.2.2</ProductID>
            <ProductID>P-9835V-12.3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="71" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0635</Title>
      <Notes>
         <Note Audience="All" Ordinal="71" Title="Details" Type="Details">Vulnerability in the Oracle Insurance Calculation Engine component of Oracle Insurance Applications (subcomponent: Architecture).  Supported versions that are affected are 9.7.1, 
10.1.2 and 
10.2.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Insurance Calculation Engine.  Successful attacks of this vulnerability can result in takeover of Oracle Insurance Calculation Engine. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0635</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10837V-9.7.1</ProductID>
            <ProductID>P-10837V-10.1.2</ProductID>
            <ProductID>P-10837V-10.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-10837V-9.7.1</ProductID>
            <ProductID>P-10837V-10.1.2</ProductID>
            <ProductID>P-10837V-10.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="72" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0635</Title>
      <Notes>
         <Note Audience="All" Ordinal="72" Title="Details" Type="Details">Vulnerability in the Oracle Retail Order Broker component of Oracle Retail Applications (subcomponent: Order Broker Foundation).  Supported versions that are affected are 5.1, 5.2 and  15.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Order Broker.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Order Broker. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0635</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11520V-5.1</ProductID>
            <ProductID>P-11520V-5.2</ProductID>
            <ProductID>P-11520V-15.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-11520V-5.1</ProductID>
            <ProductID>P-11520V-5.2</ProductID>
            <ProductID>P-11520V-15.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="73" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0702</Title>
      <Notes>
         <Note Audience="All" Ordinal="73" Title="Details" Type="Details">Vulnerability in the Oracle Communications Session Border Controller component of Oracle Communications Applications (subcomponent: Encryption).  Supported versions that are affected are 7.2.0 and  7.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Communications Session Border Controller.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Session Border Controller accessible data as well as  unauthorized read access to a subset of Oracle Communications Session Border Controller accessible data. CVSS 3.0 Base Score   4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0702</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10750V-7.2.0</ProductID>
            <ProductID>P-10750V-7.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-10750V-7.2.0</ProductID>
            <ProductID>P-10750V-7.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="74" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0800</Title>
      <Notes>
         <Note Audience="All" Ordinal="74" Title="Details" Type="Details">Vulnerability in the Fujitsu M10-1, M10-4, M10-4S Servers component of Oracle Sun Systems Products Suite (subcomponent: XCP Firmware).   The supported version that is affected is XCP prior to XCP2320. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSL/TLS to compromise Fujitsu M10-1, M10-4, M10-4S Servers.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Fujitsu M10-1, M10-4, M10-4S Servers accessible data. CVSS 3.0 Base Score   5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0800</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10656V-XCP prior to XCP2320</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-10656V-XCP prior to XCP2320</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="75" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-1181</Title>
      <Notes>
         <Note Audience="All" Ordinal="75" Title="Details" Type="Details">Vulnerability in the Oracle Portal component of Oracle Fusion Middleware (subcomponent: User and Group Security).   The supported version that is affected is 11.1.1.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Portal.  Successful attacks of this vulnerability can result in takeover of Oracle Portal.  Note: Please refer to &lt;a href="https://support.oracle.com/CSP/main/article?cmd=show&amp;type=NOT&amp;id=2155256.1"&gt;My Oracle Support Note 2155256.1&lt;/a&gt; for instructions on how to address this issue. CVSS 3.0 Base Score   8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-1181</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-96V-11.1.1.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-96V-11.1.1.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="76" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-1181</Title>
      <Notes>
         <Note Audience="All" Ordinal="76" Title="Details" Type="Details">Vulnerability in the Oracle Banking Platform component of Oracle Financial Services Applications (subcomponent: OPS).  Supported versions that are affected are 2.3.0, 2.4.0, 2.4.1 and  2.5.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Platform.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Banking Platform accessible data. CVSS 3.0 Base Score   3.1 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-1181</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9178V-2.3.0</ProductID>
            <ProductID>P-9178V-2.4.0</ProductID>
            <ProductID>P-9178V-2.4.1</ProductID>
            <ProductID>P-9178V-2.5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9178V-2.3.0</ProductID>
            <ProductID>P-9178V-2.4.0</ProductID>
            <ProductID>P-9178V-2.4.1</ProductID>
            <ProductID>P-9178V-2.5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="77" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-1548</Title>
      <Notes>
         <Note Audience="All" Ordinal="77" Title="Details" Type="Details">Vulnerability in the Oracle Exalogic Infrastructure component of Oracle Fusion Middleware (subcomponent: Base Image).  Supported versions that are affected are 1.x and  2.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Exalogic Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Exalogic Infrastructure accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Exalogic Infrastructure. CVSS 3.0 Base Score   6.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-1548</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9415V-1.x</ProductID>
            <ProductID>P-9415V-2.x</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9415V-1.x</ProductID>
            <ProductID>P-9415V-2.x</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="78" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-2105</Title>
      <Notes>
         <Note Audience="All" Ordinal="78" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encryption).  Supported versions that are affected are 5.6.30 and earlier and 
5.7.12 and earlier. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score   7.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-2105</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.30 and earlier</ProductID>
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8478V-5.6.30 and earlier</ProductID>
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="79" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-2107</Title>
      <Notes>
         <Note Audience="All" Ordinal="79" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Discovery Framework).  Supported versions that are affected are 12.1.0.5 and 
13.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Enterprise Manager Base Platform accessible data. CVSS 3.0 Base Score   5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-2107</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-12.1.0.5</ProductID>
            <ProductID>P-1370V-13.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1370V-12.1.0.5</ProductID>
            <ProductID>P-1370V-13.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="80" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-2107</Title>
      <Notes>
         <Note Audience="All" Ordinal="80" Title="Details" Type="Details">Vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware (subcomponent: Web Server Plugin).  Supported versions that are affected are 10.1.4.x and  11.1.1.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Access Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.0 Base Score   5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-2107</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1773V-10.1.4.x</ProductID>
            <ProductID>P-1773V-11.1.1.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1773V-10.1.4.x</ProductID>
            <ProductID>P-1773V-11.1.1.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="81" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-2107</Title>
      <Notes>
         <Note Audience="All" Ordinal="81" Title="Details" Type="Details">Vulnerability in the Oracle Agile Engineering Data Management component of Oracle Supply Chain Products Suite (subcomponent: Install).  Supported versions that are affected are 6.1.3.0 and  6.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile Engineering Data Management accessible data. CVSS 3.0 Base Score   5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-2107</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4436V-6.1.3.0</ProductID>
            <ProductID>P-4436V-6.2.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-4436V-6.1.3.0</ProductID>
            <ProductID>P-4436V-6.2.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="82" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-2107</Title>
      <Notes>
         <Note Audience="All" Ordinal="82" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Security).  Supported versions that are affected are 8.53, 8.54 and  8.55. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score   5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-2107</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.53</ProductID>
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5085V-8.53</ProductID>
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="83" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-2107</Title>
      <Notes>
         <Note Audience="All" Ordinal="83" Title="Details" Type="Details">Vulnerability in the Oracle Exalogic Infrastructure component of Oracle Fusion Middleware (subcomponent: Base Image).  Supported versions that are affected are 1.x and  2.x. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Exalogic Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Exalogic Infrastructure accessible data. CVSS 3.0 Base Score   5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-2107</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9415V-1.x</ProductID>
            <ProductID>P-9415V-2.x</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9415V-1.x</ProductID>
            <ProductID>P-9415V-2.x</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="84" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-2107</Title>
      <Notes>
         <Note Audience="All" Ordinal="84" Title="Details" Type="Details">Vulnerability in the Oracle Communications Unified Session Manager component of Oracle Communications Applications (subcomponent: Routing).  Supported versions that are affected are 7.2.5 and  7.3.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Communications Unified Session Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Session Manager accessible data. CVSS 3.0 Base Score   5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-2107</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10753V-7.2.5</ProductID>
            <ProductID>P-10753V-7.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-10753V-7.2.5</ProductID>
            <ProductID>P-10753V-7.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="85" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3081</Title>
      <Notes>
         <Note Audience="All" Ordinal="85" Title="Details" Type="Details">Vulnerability in the MICROS Retail XBRi Loss Prevention component of Oracle Retail Applications (subcomponent: Retail).  Supported versions that are affected are 10.0.1, 10.5.0, 10.6.0, 10.7.0, 10.8.0 and  10.8.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise MICROS Retail XBRi Loss Prevention.  Successful attacks of this vulnerability can result in takeover of MICROS Retail XBRi Loss Prevention. CVSS 3.0 Base Score   8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3081</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11506V-10.0.1</ProductID>
            <ProductID>P-11506V-10.5.0</ProductID>
            <ProductID>P-11506V-10.6.0</ProductID>
            <ProductID>P-11506V-10.7.0</ProductID>
            <ProductID>P-11506V-10.8.0</ProductID>
            <ProductID>P-11506V-10.8.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-11506V-10.0.1</ProductID>
            <ProductID>P-11506V-10.5.0</ProductID>
            <ProductID>P-11506V-10.6.0</ProductID>
            <ProductID>P-11506V-10.7.0</ProductID>
            <ProductID>P-11506V-10.8.0</ProductID>
            <ProductID>P-11506V-10.8.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="86" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3424</Title>
      <Notes>
         <Note Audience="All" Ordinal="86" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer).  Supported versions that are affected are 5.7.12 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score   4.9 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3424</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="87" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3432</Title>
      <Notes>
         <Note Audience="All" Ordinal="87" Title="Details" Type="Details">Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: Web Server).  Supported versions that are affected are 11.1.1.7.0 and  11.1.1.9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher).  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in BI Publisher (formerly XML Publisher), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of BI Publisher (formerly XML Publisher) accessible data as well as  unauthorized read access to a subset of BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score   5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3432</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1479V-11.1.1.7.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1479V-11.1.1.7.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="88" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3433</Title>
      <Notes>
         <Note Audience="All" Ordinal="88" Title="Details" Type="Details">Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Analytics Web Administration).  Supported versions that are affected are 11.1.1.7.0 and  11.1.1.9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data as well as  unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.0 Base Score   5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3433</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2025V-11.1.1.7.0</ProductID>
            <ProductID>P-2025V-11.1.1.9.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-2025V-11.1.1.7.0</ProductID>
            <ProductID>P-2025V-11.1.1.9.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="89" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3440</Title>
      <Notes>
         <Note Audience="All" Ordinal="89" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer).  Supported versions that are affected are 5.7.11 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  While the vulnerability is in MySQL Server, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score   7.7 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3440</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.11 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.7</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8478V-5.7.11 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="90" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3444</Title>
      <Notes>
         <Note Audience="All" Ordinal="90" Title="Details" Type="Details">Vulnerability in the Oracle Retail Integration Bus component of Oracle Retail Applications (subcomponent: Install).  Supported versions that are affected are 13.0, 13.1, 13.2, 14.0, 14.1 and  15.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus. CVSS 3.0 Base Score   9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3444</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1807V-13.0</ProductID>
            <ProductID>P-1807V-13.1</ProductID>
            <ProductID>P-1807V-13.2</ProductID>
            <ProductID>P-1807V-14.0</ProductID>
            <ProductID>P-1807V-14.1</ProductID>
            <ProductID>P-1807V-15.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1807V-13.0</ProductID>
            <ProductID>P-1807V-13.1</ProductID>
            <ProductID>P-1807V-13.2</ProductID>
            <ProductID>P-1807V-14.0</ProductID>
            <ProductID>P-1807V-14.1</ProductID>
            <ProductID>P-1807V-15.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="91" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3445</Title>
      <Notes>
         <Note Audience="All" Ordinal="91" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Container).  Supported versions that are affected are 10.3.6.0 and  12.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebLogic Server. CVSS 3.0 Base Score   5.3 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3445</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.3.6.0</ProductID>
            <ProductID>P-5242V-12.1.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5242V-10.3.6.0</ProductID>
            <ProductID>P-5242V-12.1.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="92" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3446</Title>
      <Notes>
         <Note Audience="All" Ordinal="92" Title="Details" Type="Details">Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Analytics Web Administration).  Supported versions that are affected are 11.1.1.7.0 and  11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data as well as  unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.0 Base Score   8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3446</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2025V-11.1.1.7.0</ProductID>
            <ProductID>P-2025V-11.1.1.9.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-2025V-11.1.1.7.0</ProductID>
            <ProductID>P-2025V-11.1.1.9.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="93" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3448</Title>
      <Notes>
         <Note Audience="All" Ordinal="93" Title="Details" Type="Details">Vulnerability in the Application Express component of Oracle Database Server.   The supported version that is affected is Prior to 5.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Application Express.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Application Express, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Application Express accessible data as well as  unauthorized read access to a subset of Application Express accessible data. CVSS 3.0 Base Score   6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3448</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1348V-Prior to 5.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1348V-Prior to 5.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="94" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3450</Title>
      <Notes>
         <Note Audience="All" Ordinal="94" Title="Details" Type="Details">Vulnerability in the Siebel Core - Server Framework component of Oracle Siebel CRM (subcomponent: Services).  Supported versions that are affected are 8.1.1, 8.2.2, IP2014, IP2015 and  IP2016. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Core - Server Framework.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Siebel Core - Server Framework accessible data. CVSS 3.0 Base Score   3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3450</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9001V-8.1.1</ProductID>
            <ProductID>P-9001V-8.2.2</ProductID>
            <ProductID>P-9001V-IP2014</ProductID>
            <ProductID>P-9001V-IP2015</ProductID>
            <ProductID>P-9001V-IP2016</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9001V-8.1.1</ProductID>
            <ProductID>P-9001V-8.2.2</ProductID>
            <ProductID>P-9001V-IP2014</ProductID>
            <ProductID>P-9001V-IP2015</ProductID>
            <ProductID>P-9001V-IP2016</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="95" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3451</Title>
      <Notes>
         <Note Audience="All" Ordinal="95" Title="Details" Type="Details">Vulnerability in the ILOM component of Oracle Sun Systems Products Suite (subcomponent: Web).  Supported versions that are affected are 3.0, 3.1 and  3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise ILOM.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in ILOM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of ILOM accessible data. CVSS 3.0 Base Score   4.7 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3451</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9849V-3.0</ProductID>
            <ProductID>P-9849V-3.1</ProductID>
            <ProductID>P-9849V-3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.7</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9849V-3.0</ProductID>
            <ProductID>P-9849V-3.1</ProductID>
            <ProductID>P-9849V-3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="96" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3452</Title>
      <Notes>
         <Note Audience="All" Ordinal="96" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encryption).  Supported versions that are affected are 5.5.48 and earlier, 
5.6.29 and earlier and 
5.7.10 and earlier. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.0 Base Score   3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3452</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.48 and earlier</ProductID>
            <ProductID>P-8478V-5.6.29 and earlier</ProductID>
            <ProductID>P-8478V-5.7.10 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8478V-5.5.48 and earlier</ProductID>
            <ProductID>P-8478V-5.6.29 and earlier</ProductID>
            <ProductID>P-8478V-5.7.10 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="97" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3453</Title>
      <Notes>
         <Note Audience="All" Ordinal="97" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel).   The supported version that is affected is 10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Solaris. CVSS 3.0 Base Score   5.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3453</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-10006V-10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="98" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3458</Title>
      <Notes>
         <Note Audience="All" Ordinal="98" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: CORBA).  Supported versions that are affected are Java SE: 6u115, 7u101 and  8u92; Java SE Embedded: 8u91. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score   4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3458</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 6u115</ProductID>
            <ProductID>P-856V-7u101</ProductID>
            <ProductID>P-856V-8u92; Java SE Embedded: 8u91</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-856V-Java SE: 6u115</ProductID>
            <ProductID>P-856V-7u101</ProductID>
            <ProductID>P-856V-8u92; Java SE Embedded: 8u91</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="99" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3459</Title>
      <Notes>
         <Note Audience="All" Ordinal="99" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB).  Supported versions that are affected are 5.6.30 and earlier and 
5.7.12 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score   4.9 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3459</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.30 and earlier</ProductID>
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8478V-5.6.30 and earlier</ProductID>
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="100" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3467</Title>
      <Notes>
         <Note Audience="All" Ordinal="100" Title="Details" Type="Details">Vulnerability in the Application Express component of Oracle Database Server.   The supported version that is affected is Prior to 5.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Application Express.  While the vulnerability is in Application Express, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Application Express. CVSS 3.0 Base Score   5.8 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3467</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1348V-Prior to 5.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1348V-Prior to 5.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="101" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3468</Title>
      <Notes>
         <Note Audience="All" Ordinal="101" Title="Details" Type="Details">Vulnerability in the Oracle Agile Engineering Data Management component of Oracle Supply Chain Products Suite (subcomponent: Install).  Supported versions that are affected are 6.1.3.0 and  6.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTPP to compromise Oracle Agile Engineering Data Management.  Successful attacks of this vulnerability can result in takeover of Oracle Agile Engineering Data Management. CVSS 3.0 Base Score   9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3468</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4436V-6.1.3.0</ProductID>
            <ProductID>P-4436V-6.2.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-4436V-6.1.3.0</ProductID>
            <ProductID>P-4436V-6.2.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="102" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3469</Title>
      <Notes>
         <Note Audience="All" Ordinal="102" Title="Details" Type="Details">Vulnerability in the Siebel Core - Server Framework component of Oracle Siebel CRM (subcomponent: Services).  Supported versions that are affected are 8.1.1, 8.2.2, IP2014, IP2015 and  IP2016. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel Core - Server Framework executes to compromise Siebel Core - Server Framework.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Siebel Core - Server Framework accessible data. CVSS 3.0 Base Score   3.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3469</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9001V-8.1.1</ProductID>
            <ProductID>P-9001V-8.2.2</ProductID>
            <ProductID>P-9001V-IP2014</ProductID>
            <ProductID>P-9001V-IP2015</ProductID>
            <ProductID>P-9001V-IP2016</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.3</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9001V-8.1.1</ProductID>
            <ProductID>P-9001V-8.2.2</ProductID>
            <ProductID>P-9001V-IP2014</ProductID>
            <ProductID>P-9001V-IP2015</ProductID>
            <ProductID>P-9001V-IP2016</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="103" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3470</Title>
      <Notes>
         <Note Audience="All" Ordinal="103" Title="Details" Type="Details">Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suite (subcomponent: Install).   The supported version that is affected is 6.4.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Transportation Management accessible data as well as  unauthorized update, insert or delete access to some of Oracle Transportation Management accessible data. CVSS 3.0 Base Score   7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3470</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1991V-6.4.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1991V-6.4.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="104" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3471</Title>
      <Notes>
         <Note Audience="All" Ordinal="104" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Option).  Supported versions that are affected are 5.5.45 and earlier and 
5.6.26 and earlier. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server.  While the vulnerability is in MySQL Server, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of MySQL Server. CVSS 3.0 Base Score   7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3471</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.45 and earlier</ProductID>
            <ProductID>P-8478V-5.6.26 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8478V-5.5.45 and earlier</ProductID>
            <ProductID>P-8478V-5.6.26 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="105" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3472</Title>
      <Notes>
         <Note Audience="All" Ordinal="105" Title="Details" Type="Details">Vulnerability in the Siebel Engineering - Installer and Deployment component of Oracle Siebel CRM (subcomponent: Web Server).  Supported versions that are affected are 8.1.1, 8.2.2, IP2014, IP2015 and  IP2016. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Engineering - Installer and Deployment.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel Engineering - Installer and Deployment accessible data. CVSS 3.0 Base Score   5.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3472</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9023V-8.1.1</ProductID>
            <ProductID>P-9023V-8.2.2</ProductID>
            <ProductID>P-9023V-IP2014</ProductID>
            <ProductID>P-9023V-IP2015</ProductID>
            <ProductID>P-9023V-IP2016</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.7</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9023V-8.1.1</ProductID>
            <ProductID>P-9023V-8.2.2</ProductID>
            <ProductID>P-9023V-IP2014</ProductID>
            <ProductID>P-9023V-IP2015</ProductID>
            <ProductID>P-9023V-IP2016</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="106" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3474</Title>
      <Notes>
         <Note Audience="All" Ordinal="106" Title="Details" Type="Details">Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: Security).  Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0 and  12.2.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher).  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score   3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3474</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1479V-11.1.1.7.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
            <ProductID>P-1479V-12.2.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1479V-11.1.1.7.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
            <ProductID>P-1479V-12.2.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="107" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3475</Title>
      <Notes>
         <Note Audience="All" Ordinal="107" Title="Details" Type="Details">Vulnerability in the Oracle Knowledge component of Oracle Siebel CRM (subcomponent: Information Manager Console).   The supported version that is affected is 8.5.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Knowledge.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Knowledge accessible data. CVSS 3.0 Base Score   4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3475</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9571V-8.5.x</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9571V-8.5.x</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="108" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3476</Title>
      <Notes>
         <Note Audience="All" Ordinal="108" Title="Details" Type="Details">Vulnerability in the Oracle Knowledge component of Oracle Siebel CRM (subcomponent: Information Manager Console).   The supported version that is affected is 8.5.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Knowledge accessible data as well as  unauthorized read access to a subset of Oracle Knowledge accessible data. CVSS 3.0 Base Score   6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3476</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9571V-8.5.x</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9571V-8.5.x</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="109" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3477</Title>
      <Notes>
         <Note Audience="All" Ordinal="109" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser).  Supported versions that are affected are 5.5.49 and earlier, 
5.6.30 and earlier and 
5.7.12 and earlier. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server.  While the vulnerability is in MySQL Server, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of MySQL Server. CVSS 3.0 Base Score   8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3477</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.49 and earlier</ProductID>
            <ProductID>P-8478V-5.6.30 and earlier</ProductID>
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8478V-5.5.49 and earlier</ProductID>
            <ProductID>P-8478V-5.6.30 and earlier</ProductID>
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="110" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3478</Title>
      <Notes>
         <Note Audience="All" Ordinal="110" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: File Processing).  Supported versions that are affected are 8.53, 8.54 and  8.55. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score   6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3478</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.53</ProductID>
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5085V-8.53</ProductID>
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="111" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3479</Title>
      <Notes>
         <Note Audience="All" Ordinal="111" Title="Details" Type="Details">Vulnerability in the Portable Clusterware component of Oracle Database Server.  Supported versions that are affected are 11.2.0.4 and 12.1.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Portable Clusterware.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Portable Clusterware. CVSS 3.0 Base Score   7.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3479</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="112" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3480</Title>
      <Notes>
         <Note Audience="All" Ordinal="112" Title="Details" Type="Details">Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: HA for Postgresql).  Supported versions that are affected are 3.3 and  4.3. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Solaris Cluster executes to compromise Solaris Cluster.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Solaris Cluster accessible data. CVSS 3.0 Base Score   4.4 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3480</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10005V-3.3</ProductID>
            <ProductID>P-10005V-4.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.4</BaseScore>
            <Vector>AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-10005V-3.3</ProductID>
            <ProductID>P-10005V-4.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="113" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3481</Title>
      <Notes>
         <Note Audience="All" Ordinal="113" Title="Details" Type="Details">Vulnerability in the ILOM component of Oracle Sun Systems Products Suite (subcomponent: Web).  Supported versions that are affected are 3.0, 3.1 and  3.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise ILOM.  While the vulnerability is in ILOM, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of ILOM. CVSS 3.0 Base Score   7.7 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3481</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9849V-3.0</ProductID>
            <ProductID>P-9849V-3.1</ProductID>
            <ProductID>P-9849V-3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.7</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9849V-3.0</ProductID>
            <ProductID>P-9849V-3.1</ProductID>
            <ProductID>P-9849V-3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="114" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3482</Title>
      <Notes>
         <Note Audience="All" Ordinal="114" Title="Details" Type="Details">Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: SSL/TLS Module).  Supported versions that are affected are 11.1.1.9 and  12.1.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle HTTP Server accessible data. CVSS 3.0 Base Score   3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3482</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1042V-11.1.1.9</ProductID>
            <ProductID>P-1042V-12.1.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1042V-11.1.1.9</ProductID>
            <ProductID>P-1042V-12.1.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="115" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3483</Title>
      <Notes>
         <Note Audience="All" Ordinal="115" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: File Processing).  Supported versions that are affected are 8.53, 8.54 and  8.55. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  While the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.0 Base Score   7.2 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3483</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.53</ProductID>
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5085V-8.53</ProductID>
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="116" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3484</Title>
      <Notes>
         <Note Audience="All" Ordinal="116" Title="Details" Type="Details">Vulnerability in the Database Vault component of Oracle Database Server.  Supported versions that are affected are 11.2.0.4, 12.1.0.1 and 12.1.0.2. Easily exploitable vulnerability allows high privileged attacker having Create Public Synonym privilege with logon to the infrastructure where Database Vault executes to compromise Database Vault.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Database Vault accessible data as well as  unauthorized read access to a subset of Database Vault accessible data. CVSS 3.0 Base Score   3.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3484</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.1</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.4</BaseScore>
            <Vector>AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.1</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="117" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3485</Title>
      <Notes>
         <Note Audience="All" Ordinal="117" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking).  Supported versions that are affected are Java SE: 6u115, 7u101 and  8u92; Java SE Embedded: 8u91; JRockit: R28.3.10. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE, Java SE Embedded, JRockit executes to compromise Java SE, Java SE Embedded, JRockit.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Java SE, Java SE Embedded, JRockit accessible data.  Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score   2.9 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3485</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 6u115</ProductID>
            <ProductID>P-856V-7u101</ProductID>
            <ProductID>P-856V-8u92; Java SE Embedded: 8u91; JRockit: R28.3.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.9</BaseScore>
            <Vector>AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-856V-Java SE: 6u115</ProductID>
            <ProductID>P-856V-7u101</ProductID>
            <ProductID>P-856V-8u92; Java SE Embedded: 8u91; JRockit: R28.3.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="118" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3486</Title>
      <Notes>
         <Note Audience="All" Ordinal="118" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: FTS).  Supported versions that are affected are 5.6.30 and earlier and 
5.7.12 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score   6.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3486</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.30 and earlier</ProductID>
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8478V-5.6.30 and earlier</ProductID>
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="119" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3487</Title>
      <Notes>
         <Note Audience="All" Ordinal="119" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: WebCenter Sites).  Supported versions that are affected are 11.1.1.8 and  12.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.0 Base Score   8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3487</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9617V-11.1.1.8</ProductID>
            <ProductID>P-9617V-12.2.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9617V-11.1.1.8</ProductID>
            <ProductID>P-9617V-12.2.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="120" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3488</Title>
      <Notes>
         <Note Audience="All" Ordinal="120" Title="Details" Type="Details">Vulnerability in the DB Sharding component of Oracle Database Server.   The supported version that is affected is 12.1.0.2. Easily exploitable vulnerability allows high privileged attacker having Execute on gsmadmin_internal privilege with logon to the infrastructure where DB Sharding executes to compromise DB Sharding.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all DB Sharding accessible data. CVSS 3.0 Base Score   4.4 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-12.1.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.4</BaseScore>
            <Vector>AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5V-12.1.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="121" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3489</Title>
      <Notes>
         <Note Audience="All" Ordinal="121" Title="Details" Type="Details">Vulnerability in the Data Pump Import component of Oracle Database Server.  Supported versions that are affected are 11.2.0.4, 12.1.0.1 and 12.1.0.2. Easily exploitable vulnerability allows high privileged attacker having Index on SYS.INCVID privilege with logon to the infrastructure where Data Pump Import executes to compromise Data Pump Import.  Successful attacks of this vulnerability can result in takeover of Data Pump Import. CVSS 3.0 Base Score   6.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3489</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.1</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.7</BaseScore>
            <Vector>AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.1</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="122" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3490</Title>
      <Notes>
         <Note Audience="All" Ordinal="122" Title="Details" Type="Details">Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suite (subcomponent: Database).  Supported versions that are affected are 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.4.0 and  6.4.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Transportation Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Transportation Management accessible data. CVSS 3.0 Base Score   3.0 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3490</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1991V-6.3.0</ProductID>
            <ProductID>P-1991V-6.3.1</ProductID>
            <ProductID>P-1991V-6.3.2</ProductID>
            <ProductID>P-1991V-6.3.3</ProductID>
            <ProductID>P-1991V-6.3.4</ProductID>
            <ProductID>P-1991V-6.3.5</ProductID>
            <ProductID>P-1991V-6.3.6</ProductID>
            <ProductID>P-1991V-6.3.7</ProductID>
            <ProductID>P-1991V-6.4.0</ProductID>
            <ProductID>P-1991V-6.4.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.0</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1991V-6.3.0</ProductID>
            <ProductID>P-1991V-6.3.1</ProductID>
            <ProductID>P-1991V-6.3.2</ProductID>
            <ProductID>P-1991V-6.3.3</ProductID>
            <ProductID>P-1991V-6.3.4</ProductID>
            <ProductID>P-1991V-6.3.5</ProductID>
            <ProductID>P-1991V-6.3.6</ProductID>
            <ProductID>P-1991V-6.3.7</ProductID>
            <ProductID>P-1991V-6.4.0</ProductID>
            <ProductID>P-1991V-6.4.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="123" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3491</Title>
      <Notes>
         <Note Audience="All" Ordinal="123" Title="Details" Type="Details">Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Wireless Framework).   The supported version that is affected is 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle CRM Technical Foundation accessible data as well as  unauthorized update, insert or delete access to some of Oracle CRM Technical Foundation accessible data. CVSS 3.0 Base Score   8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3491</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1199V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1199V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="124" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3493</Title>
      <Notes>
         <Note Audience="All" Ordinal="124" Title="Details" Type="Details">Vulnerability in the Hyperion Financial Reporting component of Oracle Hyperion (subcomponent: Security Models).   The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Financial Reporting.  Successful attacks of this vulnerability can result in takeover of Hyperion Financial Reporting. CVSS 3.0 Base Score   9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3493</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8776V-11.1.2.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8776V-11.1.2.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="125" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3494</Title>
      <Notes>
         <Note Audience="All" Ordinal="125" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Ops Center component of Oracle Enterprise Manager Grid Control (subcomponent: OS Provisioning).  Supported versions that are affected are 12.1.4, 
12.2.2 and 
12.3.2. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Enterprise Manager Ops Center executes to compromise Enterprise Manager Ops Center.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Enterprise Manager Ops Center. CVSS 3.0 Base Score   6.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3494</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9835V-12.1.4</ProductID>
            <ProductID>P-9835V-12.2.2</ProductID>
            <ProductID>P-9835V-12.3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9835V-12.1.4</ProductID>
            <ProductID>P-9835V-12.2.2</ProductID>
            <ProductID>P-9835V-12.3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="126" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3496</Title>
      <Notes>
         <Note Audience="All" Ordinal="126" Title="Details" Type="Details">Vulnerability in the Enterprise Manager for Fusion Middleware component of Oracle Enterprise Manager Grid Control (subcomponent: SOA Topology Viewer).  Supported versions that are affected are 11.1.1.7 and 
11.1.1.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager for Fusion Middleware.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Enterprise Manager for Fusion Middleware, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Enterprise Manager for Fusion Middleware accessible data. CVSS 3.0 Base Score   4.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3496</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1369V-11.1.1.7</ProductID>
            <ProductID>P-1369V-11.1.1.9</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.7</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1369V-11.1.1.7</ProductID>
            <ProductID>P-1369V-11.1.1.9</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="127" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3497</Title>
      <Notes>
         <Note Audience="All" Ordinal="127" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel).   The supported version that is affected is 11.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Solaris. CVSS 3.0 Base Score   5.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3497</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-10006V-11.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="128" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3498</Title>
      <Notes>
         <Note Audience="All" Ordinal="128" Title="Details" Type="Details">Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX).  Supported versions that are affected are Java SE: 7u101 and  8u92. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score   5.3 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3498</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 7u101</ProductID>
            <ProductID>P-856V-8u92</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-856V-Java SE: 7u101</ProductID>
            <ProductID>P-856V-8u92</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="129" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3499</Title>
      <Notes>
         <Note Audience="All" Ordinal="129" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Container).  Supported versions that are affected are 12.1.3.0 and  12.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score   9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3499</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-12.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5242V-12.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="130" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3500</Title>
      <Notes>
         <Note Audience="All" Ordinal="130" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAXP).  Supported versions that are affected are Java SE: 6u115, 7u101 and  8u92; Java SE Embedded: 8u91; JRockit: R28.3.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit.  Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score   5.3 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3500</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 6u115</ProductID>
            <ProductID>P-856V-7u101</ProductID>
            <ProductID>P-856V-8u92; Java SE Embedded: 8u91; JRockit: R28.3.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-856V-Java SE: 6u115</ProductID>
            <ProductID>P-856V-7u101</ProductID>
            <ProductID>P-856V-8u92; Java SE Embedded: 8u91; JRockit: R28.3.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="131" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3501</Title>
      <Notes>
         <Note Audience="All" Ordinal="131" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer).  Supported versions that are affected are 5.6.30 and earlier and 
5.7.12 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score   6.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.30 and earlier</ProductID>
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8478V-5.6.30 and earlier</ProductID>
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="132" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3502</Title>
      <Notes>
         <Note Audience="All" Ordinal="132" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: WebCenter Sites).  Supported versions that are affected are 11.1.1.8 and  12.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data as well as  unauthorized read access to a subset of Oracle WebCenter Sites accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Sites. CVSS 3.0 Base Score   6.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3502</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9617V-11.1.1.8</ProductID>
            <ProductID>P-9617V-12.2.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9617V-11.1.1.8</ProductID>
            <ProductID>P-9617V-12.2.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="133" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3503</Title>
      <Notes>
         <Note Audience="All" Ordinal="133" Title="Details" Type="Details">Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Install).  Supported versions that are affected are Java SE: 6u115, 7u101 and  8u92. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE executes to compromise Java SE.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE.  Note: Applies to installation process on client deployment of Java. CVSS 3.0 Base Score   7.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3503</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 6u115</ProductID>
            <ProductID>P-856V-7u101</ProductID>
            <ProductID>P-856V-8u92</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.7</BaseScore>
            <Vector>AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-856V-Java SE: 6u115</ProductID>
            <ProductID>P-856V-7u101</ProductID>
            <ProductID>P-856V-8u92</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="134" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3504</Title>
      <Notes>
         <Note Audience="All" Ordinal="134" Title="Details" Type="Details">Vulnerability in the Oracle JDeveloper component of Oracle Fusion Middleware (subcomponent: ADF Faces).  Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0, 11.1.2.4.0, 12.1.3.0.0 and  12.2.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper.  Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper. CVSS 3.0 Base Score   9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3504</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-807V-11.1.1.7.0</ProductID>
            <ProductID>P-807V-11.1.1.9.0</ProductID>
            <ProductID>P-807V-11.1.2.4.0</ProductID>
            <ProductID>P-807V-12.1.3.0.0</ProductID>
            <ProductID>P-807V-12.2.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-807V-11.1.1.7.0</ProductID>
            <ProductID>P-807V-11.1.1.9.0</ProductID>
            <ProductID>P-807V-11.1.2.4.0</ProductID>
            <ProductID>P-807V-12.1.3.0.0</ProductID>
            <ProductID>P-807V-12.2.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="135" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3506</Title>
      <Notes>
         <Note Audience="All" Ordinal="135" Title="Details" Type="Details">Vulnerability in the JDBC component of Oracle Database Server.  Supported versions that are affected are 11.2.0.4, 12.1.0.1 and 12.1.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise JDBC.  Successful attacks of this vulnerability can result in takeover of JDBC. CVSS 3.0 Base Score   8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3506</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-972V-11.2.0.4</ProductID>
            <ProductID>P-972V-12.1.0.1</ProductID>
            <ProductID>P-972V-12.1.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-972V-11.2.0.4</ProductID>
            <ProductID>P-972V-12.1.0.1</ProductID>
            <ProductID>P-972V-12.1.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="136" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3507</Title>
      <Notes>
         <Note Audience="All" Ordinal="136" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: WebClient / Admin).  Supported versions that are affected are 9.3.4 and  9.3.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data. CVSS 3.0 Base Score   4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3507</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="137" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3508</Title>
      <Notes>
         <Note Audience="All" Ordinal="137" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAXP).  Supported versions that are affected are Java SE: 6u115, 7u101 and  8u92; Java SE Embedded: 8u91; JRockit: R28.3.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit.  Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score   5.3 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3508</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 6u115</ProductID>
            <ProductID>P-856V-7u101</ProductID>
            <ProductID>P-856V-8u92; Java SE Embedded: 8u91; JRockit: R28.3.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-856V-Java SE: 6u115</ProductID>
            <ProductID>P-856V-7u101</ProductID>
            <ProductID>P-856V-8u92; Java SE Embedded: 8u91; JRockit: R28.3.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="138" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3509</Title>
      <Notes>
         <Note Audience="All" Ordinal="138" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: File Folders / URL Attachment).  Supported versions that are affected are 9.3.4 and  9.3.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data as well as  unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.0 Base Score   5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3509</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="139" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3510</Title>
      <Notes>
         <Note Audience="All" Ordinal="139" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components).  Supported versions that are affected are 10.3.6.0, 12.1.3.0 and  12.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score   9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3510</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.3.6.0</ProductID>
            <ProductID>P-5242V-12.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5242V-10.3.6.0</ProductID>
            <ProductID>P-5242V-12.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="140" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3511</Title>
      <Notes>
         <Note Audience="All" Ordinal="140" Title="Details" Type="Details">Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment).  Supported versions that are affected are Java SE: 7u101 and  8u92. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE executes to compromise Java SE.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score   7.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3511</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 7u101</ProductID>
            <ProductID>P-856V-8u92</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.7</BaseScore>
            <Vector>AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-856V-Java SE: 7u101</ProductID>
            <ProductID>P-856V-8u92</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="141" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3512</Title>
      <Notes>
         <Note Audience="All" Ordinal="141" Title="Details" Type="Details">Vulnerability in the Oracle Customer Interaction History component of Oracle E-Business Suite (subcomponent: Function Security).  Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Customer Interaction History.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Customer Interaction History, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Customer Interaction History accessible data as well as  unauthorized update, insert or delete access to some of Oracle Customer Interaction History accessible data. CVSS 3.0 Base Score   8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3512</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1374V-12.1.1</ProductID>
            <ProductID>P-1374V-12.1.2</ProductID>
            <ProductID>P-1374V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1374V-12.1.1</ProductID>
            <ProductID>P-1374V-12.1.2</ProductID>
            <ProductID>P-1374V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="142" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3513</Title>
      <Notes>
         <Note Audience="All" Ordinal="142" Title="Details" Type="Details">Vulnerability in the Oracle Communications Operations Monitor component of Oracle Communications Applications (subcomponent: Infrastructure).   The supported version that is affected is Prior to 3.3.92.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Operations Monitor.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Operations Monitor accessible data. CVSS 3.0 Base Score   6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3513</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10761V-Prior to 3.3.92.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-10761V-Prior to 3.3.92.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="143" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3514</Title>
      <Notes>
         <Note Audience="All" Ordinal="143" Title="Details" Type="Details">Vulnerability in the Oracle Enterprise Communications Broker component of Oracle Communications Applications (subcomponent: GUI).   The supported version that is affected is Prior to PCz 2.0.0m4p1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Communications Broker.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Enterprise Communications Broker accessible data. CVSS 3.0 Base Score   6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3514</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10758V-Prior to PCz 2.0.0m4p1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-10758V-Prior to PCz 2.0.0m4p1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="144" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3515</Title>
      <Notes>
         <Note Audience="All" Ordinal="144" Title="Details" Type="Details">Vulnerability in the Oracle Enterprise Communications Broker component of Oracle Communications Applications (subcomponent: Crash, network, system, admin).   The supported version that is affected is Prior to PCz 2.0.0m4p1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Communications Broker.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Enterprise Communications Broker accessible data. CVSS 3.0 Base Score   7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3515</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10758V-Prior to PCz 2.0.0m4p1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-10758V-Prior to PCz 2.0.0m4p1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="145" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3516</Title>
      <Notes>
         <Note Audience="All" Ordinal="145" Title="Details" Type="Details">Vulnerability in the Oracle Enterprise Communications Broker component of Oracle Communications Applications (subcomponent: GUI).   The supported version that is affected is Prior to PCz 2.0.0m4p1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Communications Broker.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Enterprise Communications Broker accessible data. CVSS 3.0 Base Score   3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3516</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10758V-Prior to PCz 2.0.0m4p1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.1</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-10758V-Prior to PCz 2.0.0m4p1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="146" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3517</Title>
      <Notes>
         <Note Audience="All" Ordinal="146" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: PC / Get Shortcut).  Supported versions that are affected are 9.3.4 and  9.3.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data. CVSS 3.0 Base Score   4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3517</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="147" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3518</Title>
      <Notes>
         <Note Audience="All" Ordinal="147" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer).  Supported versions that are affected are 5.7.12 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score   6.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3518</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="148" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3519</Title>
      <Notes>
         <Note Audience="All" Ordinal="148" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: PC / Get Shortcut).  Supported versions that are affected are 9.3.4 and  9.3.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data as well as  unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.0 Base Score   6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3519</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="149" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3520</Title>
      <Notes>
         <Note Audience="All" Ordinal="149" Title="Details" Type="Details">Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: AOL Diagnostic tests).  Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Application Object Library.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.0 Base Score   4.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3520</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-510V-12.1.3</ProductID>
            <ProductID>P-510V-12.2.3</ProductID>
            <ProductID>P-510V-12.2.4</ProductID>
            <ProductID>P-510V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-510V-12.1.3</ProductID>
            <ProductID>P-510V-12.2.3</ProductID>
            <ProductID>P-510V-12.2.4</ProductID>
            <ProductID>P-510V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="150" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3521</Title>
      <Notes>
         <Note Audience="All" Ordinal="150" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Types).  Supported versions that are affected are 5.5.49 and earlier, 
5.6.30 and earlier and 
5.7.12 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score   6.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3521</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.49 and earlier</ProductID>
            <ProductID>P-8478V-5.6.30 and earlier</ProductID>
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8478V-5.5.49 and earlier</ProductID>
            <ProductID>P-8478V-5.6.30 and earlier</ProductID>
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="151" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3522</Title>
      <Notes>
         <Note Audience="All" Ordinal="151" Title="Details" Type="Details">Vulnerability in the Oracle Web Applications Desktop Integrator component of Oracle E-Business Suite (subcomponent: Application Service).  Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Web Applications Desktop Integrator, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Web Applications Desktop Integrator accessible data as well as  unauthorized update, insert or delete access to some of Oracle Web Applications Desktop Integrator accessible data. CVSS 3.0 Base Score   8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3522</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1171V-12.1.3</ProductID>
            <ProductID>P-1171V-12.2.3</ProductID>
            <ProductID>P-1171V-12.2.4</ProductID>
            <ProductID>P-1171V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1171V-12.1.3</ProductID>
            <ProductID>P-1171V-12.2.3</ProductID>
            <ProductID>P-1171V-12.2.4</ProductID>
            <ProductID>P-1171V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="152" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3523</Title>
      <Notes>
         <Note Audience="All" Ordinal="152" Title="Details" Type="Details">Vulnerability in the Oracle Web Applications Desktop Integrator component of Oracle E-Business Suite (subcomponent: Application Service).  Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Web Applications Desktop Integrator, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Web Applications Desktop Integrator accessible data. CVSS 3.0 Base Score   4.7 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3523</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1171V-12.1.3</ProductID>
            <ProductID>P-1171V-12.2.3</ProductID>
            <ProductID>P-1171V-12.2.4</ProductID>
            <ProductID>P-1171V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.7</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1171V-12.1.3</ProductID>
            <ProductID>P-1171V-12.2.3</ProductID>
            <ProductID>P-1171V-12.2.4</ProductID>
            <ProductID>P-1171V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="153" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3524</Title>
      <Notes>
         <Note Audience="All" Ordinal="153" Title="Details" Type="Details">Vulnerability in the Oracle Applications Technology Stack component of Oracle E-Business Suite (subcomponent: Configuration).  Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Technology Stack.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Applications Technology Stack accessible data as well as  unauthorized read access to a subset of Oracle Applications Technology Stack accessible data. CVSS 3.0 Base Score   6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3524</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1745V-12.1.3</ProductID>
            <ProductID>P-1745V-12.2.3</ProductID>
            <ProductID>P-1745V-12.2.4</ProductID>
            <ProductID>P-1745V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1745V-12.1.3</ProductID>
            <ProductID>P-1745V-12.2.3</ProductID>
            <ProductID>P-1745V-12.2.4</ProductID>
            <ProductID>P-1745V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="154" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3525</Title>
      <Notes>
         <Note Audience="All" Ordinal="154" Title="Details" Type="Details">Vulnerability in the Oracle Applications Manager component of Oracle E-Business Suite (subcomponent: Cookie Management).   The supported version that is affected is 12.1.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Applications Manager accessible data. CVSS 3.0 Base Score   5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3525</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-99V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-99V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="155" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3526</Title>
      <Notes>
         <Note Audience="All" Ordinal="155" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: SDK).  Supported versions that are affected are 9.3.4 and  9.3.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.0 Base Score   7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3526</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="156" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3527</Title>
      <Notes>
         <Note Audience="All" Ordinal="156" Title="Details" Type="Details">Vulnerability in the Oracle Demand Planning component of Oracle Supply Chain Products Suite (subcomponent: ODPDA Servlet).  Supported versions that are affected are 12.1 and  12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Demand Planning.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Demand Planning accessible data as well as  unauthorized access to critical data or complete access to all Oracle Demand Planning accessible data. CVSS 3.0 Base Score   9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3527</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-723V-12.1</ProductID>
            <ProductID>P-723V-12.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-723V-12.1</ProductID>
            <ProductID>P-723V-12.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="157" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3528</Title>
      <Notes>
         <Note Audience="All" Ordinal="157" Title="Details" Type="Details">Vulnerability in the Oracle Internet Expenses component of Oracle E-Business Suite (subcomponent: Expenses Admin Utilities).  Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Internet Expenses.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Internet Expenses. CVSS 3.0 Base Score   7.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3528</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-397V-12.1.1</ProductID>
            <ProductID>P-397V-12.1.2</ProductID>
            <ProductID>P-397V-12.1.3</ProductID>
            <ProductID>P-397V-12.2.3</ProductID>
            <ProductID>P-397V-12.2.4</ProductID>
            <ProductID>P-397V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-397V-12.1.1</ProductID>
            <ProductID>P-397V-12.1.2</ProductID>
            <ProductID>P-397V-12.1.3</ProductID>
            <ProductID>P-397V-12.2.3</ProductID>
            <ProductID>P-397V-12.2.4</ProductID>
            <ProductID>P-397V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="158" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3529</Title>
      <Notes>
         <Note Audience="All" Ordinal="158" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: SDK).  Supported versions that are affected are 9.3.4 and  9.3.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  While the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.0 Base Score   5.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3529</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="159" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3530</Title>
      <Notes>
         <Note Audience="All" Ordinal="159" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: PGC / Import).  Supported versions that are affected are 9.3.4 and  9.3.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile PLM. CVSS 3.0 Base Score   7.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3530</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="160" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3531</Title>
      <Notes>
         <Note Audience="All" Ordinal="160" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: PC / Notification).  Supported versions that are affected are 9.3.4 and  9.3.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.0 Base Score   3.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3531</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="161" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3532</Title>
      <Notes>
         <Note Audience="All" Ordinal="161" Title="Details" Type="Details">Vulnerability in the Oracle Advanced Inbound Telephony component of Oracle E-Business Suite (subcomponent: SDK client integration).  Supported versions that are affected are 12.1.1, 12.1.2 and  12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Inbound Telephony.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Advanced Inbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Advanced Inbound Telephony accessible data as well as  unauthorized update, insert or delete access to some of Oracle Advanced Inbound Telephony accessible data. CVSS 3.0 Base Score   8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3532</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-265V-12.1.1</ProductID>
            <ProductID>P-265V-12.1.2</ProductID>
            <ProductID>P-265V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-265V-12.1.1</ProductID>
            <ProductID>P-265V-12.1.2</ProductID>
            <ProductID>P-265V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="162" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3533</Title>
      <Notes>
         <Note Audience="All" Ordinal="162" Title="Details" Type="Details">Vulnerability in the Oracle Knowledge Management component of Oracle E-Business Suite (subcomponent: Search).  Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Knowledge Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Knowledge Management accessible data. CVSS 3.0 Base Score   4.7 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3533</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1351V-12.1.1</ProductID>
            <ProductID>P-1351V-12.1.2</ProductID>
            <ProductID>P-1351V-12.1.3</ProductID>
            <ProductID>P-1351V-12.2.3</ProductID>
            <ProductID>P-1351V-12.2.4</ProductID>
            <ProductID>P-1351V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.7</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1351V-12.1.1</ProductID>
            <ProductID>P-1351V-12.1.2</ProductID>
            <ProductID>P-1351V-12.1.3</ProductID>
            <ProductID>P-1351V-12.2.3</ProductID>
            <ProductID>P-1351V-12.2.4</ProductID>
            <ProductID>P-1351V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="163" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3534</Title>
      <Notes>
         <Note Audience="All" Ordinal="163" Title="Details" Type="Details">Vulnerability in the Oracle Installed Base component of Oracle E-Business Suite (subcomponent: Engineering Change Order).  Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Installed Base.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Installed Base, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Installed Base accessible data. CVSS 3.0 Base Score   4.7 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3534</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1118V-12.1.1</ProductID>
            <ProductID>P-1118V-12.1.2</ProductID>
            <ProductID>P-1118V-12.1.3</ProductID>
            <ProductID>P-1118V-12.2.3</ProductID>
            <ProductID>P-1118V-12.2.4</ProductID>
            <ProductID>P-1118V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.7</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1118V-12.1.1</ProductID>
            <ProductID>P-1118V-12.1.2</ProductID>
            <ProductID>P-1118V-12.1.3</ProductID>
            <ProductID>P-1118V-12.2.3</ProductID>
            <ProductID>P-1118V-12.2.4</ProductID>
            <ProductID>P-1118V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="164" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3535</Title>
      <Notes>
         <Note Audience="All" Ordinal="164" Title="Details" Type="Details">Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Remote Launch).   The supported version that is affected is 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle CRM Technical Foundation accessible data as well as  unauthorized update, insert or delete access to some of Oracle CRM Technical Foundation accessible data. CVSS 3.0 Base Score   8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3535</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1199V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1199V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="165" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3536</Title>
      <Notes>
         <Note Audience="All" Ordinal="165" Title="Details" Type="Details">Vulnerability in the Oracle Marketing component of Oracle E-Business Suite (subcomponent: Deliverables).  Supported versions that are affected are 12.1.1, 12.1.2 and  12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Marketing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Marketing accessible data as well as  unauthorized update, insert or delete access to some of Oracle Marketing accessible data. CVSS 3.0 Base Score   8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3536</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-229V-12.1.1</ProductID>
            <ProductID>P-229V-12.1.2</ProductID>
            <ProductID>P-229V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-229V-12.1.1</ProductID>
            <ProductID>P-229V-12.1.2</ProductID>
            <ProductID>P-229V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="166" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3537</Title>
      <Notes>
         <Note Audience="All" Ordinal="166" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: File Folders / Attachment).  Supported versions that are affected are 9.3.4 and  9.3.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.0 Base Score   6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3537</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="167" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3538</Title>
      <Notes>
         <Note Audience="All" Ordinal="167" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: File Folders / Attachment).  Supported versions that are affected are 9.3.4 and  9.3.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile PLM. CVSS 3.0 Base Score   7.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3538</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="168" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3539</Title>
      <Notes>
         <Note Audience="All" Ordinal="168" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: File Folders / Attachment).  Supported versions that are affected are 9.3.4 and  9.3.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile PLM. CVSS 3.0 Base Score   7.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3539</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="169" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3540</Title>
      <Notes>
         <Note Audience="All" Ordinal="169" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: UI Framework).  Supported versions that are affected are 12.1.0.5 and 
13.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Enterprise Manager Base Platform accessible data. CVSS 3.0 Base Score   4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3540</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-12.1.0.5</ProductID>
            <ProductID>P-1370V-13.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1370V-12.1.0.5</ProductID>
            <ProductID>P-1370V-13.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="170" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3541</Title>
      <Notes>
         <Note Audience="All" Ordinal="170" Title="Details" Type="Details">Vulnerability in the Oracle Common Applications Calendar component of Oracle E-Business Suite (subcomponent: Notes).  Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications Calendar.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Common Applications Calendar accessible data as well as  unauthorized access to critical data or complete access to all Oracle Common Applications Calendar accessible data. CVSS 3.0 Base Score   9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3541</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1528V-12.1.1</ProductID>
            <ProductID>P-1528V-12.1.2</ProductID>
            <ProductID>P-1528V-12.1.3</ProductID>
            <ProductID>P-1528V-12.2.3</ProductID>
            <ProductID>P-1528V-12.2.4</ProductID>
            <ProductID>P-1528V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1528V-12.1.1</ProductID>
            <ProductID>P-1528V-12.1.2</ProductID>
            <ProductID>P-1528V-12.1.3</ProductID>
            <ProductID>P-1528V-12.2.3</ProductID>
            <ProductID>P-1528V-12.2.4</ProductID>
            <ProductID>P-1528V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="171" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3542</Title>
      <Notes>
         <Note Audience="All" Ordinal="171" Title="Details" Type="Details">Vulnerability in the Oracle Knowledge Management component of Oracle E-Business Suite (subcomponent: Search, Browse).  Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Knowledge Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Knowledge Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Knowledge Management accessible data. CVSS 3.0 Base Score   6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3542</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1351V-12.1.1</ProductID>
            <ProductID>P-1351V-12.1.2</ProductID>
            <ProductID>P-1351V-12.1.3</ProductID>
            <ProductID>P-1351V-12.2.3</ProductID>
            <ProductID>P-1351V-12.2.4</ProductID>
            <ProductID>P-1351V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1351V-12.1.1</ProductID>
            <ProductID>P-1351V-12.1.2</ProductID>
            <ProductID>P-1351V-12.1.3</ProductID>
            <ProductID>P-1351V-12.2.3</ProductID>
            <ProductID>P-1351V-12.2.4</ProductID>
            <ProductID>P-1351V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="172" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3543</Title>
      <Notes>
         <Note Audience="All" Ordinal="172" Title="Details" Type="Details">Vulnerability in the Oracle Common Applications Calendar component of Oracle E-Business Suite (subcomponent: Tasks).  Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications Calendar.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Common Applications Calendar accessible data as well as  unauthorized access to critical data or complete access to all Oracle Common Applications Calendar accessible data. CVSS 3.0 Base Score   9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3543</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1528V-12.1.1</ProductID>
            <ProductID>P-1528V-12.1.2</ProductID>
            <ProductID>P-1528V-12.1.3</ProductID>
            <ProductID>P-1528V-12.2.3</ProductID>
            <ProductID>P-1528V-12.2.4</ProductID>
            <ProductID>P-1528V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1528V-12.1.1</ProductID>
            <ProductID>P-1528V-12.1.2</ProductID>
            <ProductID>P-1528V-12.1.3</ProductID>
            <ProductID>P-1528V-12.2.3</ProductID>
            <ProductID>P-1528V-12.2.4</ProductID>
            <ProductID>P-1528V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="173" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3544</Title>
      <Notes>
         <Note Audience="All" Ordinal="173" Title="Details" Type="Details">Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Analytics Web General).  Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0 and  11.2.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data as well as  unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.0 Base Score   7.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3544</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2025V-11.1.1.7.0</ProductID>
            <ProductID>P-2025V-11.1.1.9.0</ProductID>
            <ProductID>P-2025V-11.2.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.6</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-2025V-11.1.1.7.0</ProductID>
            <ProductID>P-2025V-11.1.1.9.0</ProductID>
            <ProductID>P-2025V-11.2.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="174" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3545</Title>
      <Notes>
         <Note Audience="All" Ordinal="174" Title="Details" Type="Details">Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Web based help screens).  Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Application Object Library accessible data. CVSS 3.0 Base Score   5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3545</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-510V-12.1.3</ProductID>
            <ProductID>P-510V-12.2.3</ProductID>
            <ProductID>P-510V-12.2.4</ProductID>
            <ProductID>P-510V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-510V-12.1.3</ProductID>
            <ProductID>P-510V-12.2.3</ProductID>
            <ProductID>P-510V-12.2.4</ProductID>
            <ProductID>P-510V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="175" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3546</Title>
      <Notes>
         <Note Audience="All" Ordinal="175" Title="Details" Type="Details">Vulnerability in the Oracle Advanced Collections component of Oracle E-Business Suite (subcomponent: Report JSPs).  Supported versions that are affected are 12.1.1, 12.1.2 and  12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Collections.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Advanced Collections accessible data as well as  unauthorized access to critical data or complete access to all Oracle Advanced Collections accessible data. CVSS 3.0 Base Score   9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3546</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-782V-12.1.1</ProductID>
            <ProductID>P-782V-12.1.2</ProductID>
            <ProductID>P-782V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-782V-12.1.1</ProductID>
            <ProductID>P-782V-12.1.2</ProductID>
            <ProductID>P-782V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="176" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3547</Title>
      <Notes>
         <Note Audience="All" Ordinal="176" Title="Details" Type="Details">Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponent: Content Manager).  Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle One-to-One Fulfillment accessible data. CVSS 3.0 Base Score   5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3547</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1379V-12.1.1</ProductID>
            <ProductID>P-1379V-12.1.2</ProductID>
            <ProductID>P-1379V-12.1.3</ProductID>
            <ProductID>P-1379V-12.2.3</ProductID>
            <ProductID>P-1379V-12.2.4</ProductID>
            <ProductID>P-1379V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1379V-12.1.1</ProductID>
            <ProductID>P-1379V-12.1.2</ProductID>
            <ProductID>P-1379V-12.1.3</ProductID>
            <ProductID>P-1379V-12.2.3</ProductID>
            <ProductID>P-1379V-12.2.4</ProductID>
            <ProductID>P-1379V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="177" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3548</Title>
      <Notes>
         <Note Audience="All" Ordinal="177" Title="Details" Type="Details">Vulnerability in the Oracle Marketing component of Oracle E-Business Suite (subcomponent: Marketing activity collateral).  Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Marketing accessible data. CVSS 3.0 Base Score   5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3548</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-229V-12.1.1</ProductID>
            <ProductID>P-229V-12.1.2</ProductID>
            <ProductID>P-229V-12.1.3</ProductID>
            <ProductID>P-229V-12.2.3</ProductID>
            <ProductID>P-229V-12.2.4</ProductID>
            <ProductID>P-229V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-229V-12.1.1</ProductID>
            <ProductID>P-229V-12.1.2</ProductID>
            <ProductID>P-229V-12.1.3</ProductID>
            <ProductID>P-229V-12.2.3</ProductID>
            <ProductID>P-229V-12.2.4</ProductID>
            <ProductID>P-229V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="178" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3549</Title>
      <Notes>
         <Note Audience="All" Ordinal="178" Title="Details" Type="Details">Vulnerability in the Oracle E-Business Suite Secure Enterprise Search component of Oracle E-Business Suite (subcomponent: Search Integration Engine).  Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle E-Business Suite Secure Enterprise Search.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle E-Business Suite Secure Enterprise Search accessible data. CVSS 3.0 Base Score   5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3549</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4574V-12.1.3</ProductID>
            <ProductID>P-4574V-12.2.3</ProductID>
            <ProductID>P-4574V-12.2.4</ProductID>
            <ProductID>P-4574V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-4574V-12.1.3</ProductID>
            <ProductID>P-4574V-12.2.3</ProductID>
            <ProductID>P-4574V-12.2.4</ProductID>
            <ProductID>P-4574V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="179" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3550</Title>
      <Notes>
         <Note Audience="All" Ordinal="179" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot).  Supported versions that are affected are Java SE: 6u115, 7u101 and  8u92; Java SE Embedded: 8u91. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Java SE, Java SE Embedded accessible data.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score   4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3550</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 6u115</ProductID>
            <ProductID>P-856V-7u101</ProductID>
            <ProductID>P-856V-8u92; Java SE Embedded: 8u91</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-856V-Java SE: 6u115</ProductID>
            <ProductID>P-856V-7u101</ProductID>
            <ProductID>P-856V-8u92; Java SE Embedded: 8u91</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="180" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3552</Title>
      <Notes>
         <Note Audience="All" Ordinal="180" Title="Details" Type="Details">Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Install).   The supported version that is affected is Java SE: 8u92. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE executes to compromise Java SE.  While the vulnerability is in Java SE, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Java SE.  Note: Applies to installation process on client deployment of Java. CVSS 3.0 Base Score   8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3552</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 8u92</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-856V-Java SE: 8u92</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="181" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3553</Title>
      <Notes>
         <Note Audience="All" Ordinal="181" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: PC Core).  Supported versions that are affected are 9.3.4 and  9.3.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data as well as  unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.0 Base Score   5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3553</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="182" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3554</Title>
      <Notes>
         <Note Audience="All" Ordinal="182" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: PC / BOM, MCAD, Design).  Supported versions that are affected are 9.3.4 and  9.3.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3554</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="183" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3555</Title>
      <Notes>
         <Note Audience="All" Ordinal="183" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: PGC / Excel Plugin).  Supported versions that are affected are 9.3.4 and  9.3.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data as well as  unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.0 Base Score   6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3555</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="184" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3556</Title>
      <Notes>
         <Note Audience="All" Ordinal="184" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: EM Integration).  Supported versions that are affected are 9.3.4 and  9.3.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.0 Base Score   9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3556</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="185" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3557</Title>
      <Notes>
         <Note Audience="All" Ordinal="185" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: File Load).  Supported versions that are affected are 9.3.4 and  9.3.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data as well as  unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.0 Base Score   6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3557</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="186" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3558</Title>
      <Notes>
         <Note Audience="All" Ordinal="186" Title="Details" Type="Details">Vulnerability in the Oracle Email Center component of Oracle E-Business Suite (subcomponent: Email Center Agent Console).  Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Email Center.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Email Center, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Email Center accessible data. CVSS 3.0 Base Score   4.7 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3558</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-950V-12.1.1</ProductID>
            <ProductID>P-950V-12.1.2</ProductID>
            <ProductID>P-950V-12.1.3</ProductID>
            <ProductID>P-950V-12.2.3</ProductID>
            <ProductID>P-950V-12.2.4</ProductID>
            <ProductID>P-950V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.7</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-950V-12.1.1</ProductID>
            <ProductID>P-950V-12.1.2</ProductID>
            <ProductID>P-950V-12.1.3</ProductID>
            <ProductID>P-950V-12.2.3</ProductID>
            <ProductID>P-950V-12.2.4</ProductID>
            <ProductID>P-950V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="187" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3559</Title>
      <Notes>
         <Note Audience="All" Ordinal="187" Title="Details" Type="Details">Vulnerability in the Oracle Email Center component of Oracle E-Business Suite (subcomponent: Email Center Agent Console).  Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Email Center.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Email Center, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Email Center accessible data. CVSS 3.0 Base Score   4.7 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3559</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-950V-12.1.1</ProductID>
            <ProductID>P-950V-12.1.2</ProductID>
            <ProductID>P-950V-12.1.3</ProductID>
            <ProductID>P-950V-12.2.3</ProductID>
            <ProductID>P-950V-12.2.4</ProductID>
            <ProductID>P-950V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.7</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-950V-12.1.1</ProductID>
            <ProductID>P-950V-12.1.2</ProductID>
            <ProductID>P-950V-12.1.3</ProductID>
            <ProductID>P-950V-12.2.3</ProductID>
            <ProductID>P-950V-12.2.4</ProductID>
            <ProductID>P-950V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="188" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3560</Title>
      <Notes>
         <Note Audience="All" Ordinal="188" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: SDK).  Supported versions that are affected are 9.3.4 and  9.3.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.0 Base Score   5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3560</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="189" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3561</Title>
      <Notes>
         <Note Audience="All" Ordinal="189" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: SDK).  Supported versions that are affected are 9.3.4 and  9.3.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data as well as  unauthorized read access to a subset of Oracle Agile PLM accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile PLM. CVSS 3.0 Base Score   7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3561</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="190" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3563</Title>
      <Notes>
         <Note Audience="All" Ordinal="190" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Security Framework).   The supported version that is affected is 12.1.0.5. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Enterprise Manager Base Platform executes to compromise Enterprise Manager Base Platform.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Enterprise Manager Base Platform, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Enterprise Manager Base Platform accessible data as well as  unauthorized read access to a subset of Enterprise Manager Base Platform accessible data. CVSS 3.0 Base Score   6.3 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3563</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-12.1.0.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1370V-12.1.0.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="191" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3564</Title>
      <Notes>
         <Note Audience="All" Ordinal="191" Title="Details" Type="Details">Vulnerability in the Oracle TopLink component of Oracle Fusion Middleware (subcomponent: JPA-RS).  Supported versions that are affected are 12.1.3.0, 12.2.1.0 and  12.2.1.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle TopLink.  Successful attacks of this vulnerability can result in takeover of Oracle TopLink. CVSS 3.0 Base Score   8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3564</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1339V-12.1.3.0</ProductID>
            <ProductID>P-1339V-12.2.1.0</ProductID>
            <ProductID>P-1339V-12.2.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1339V-12.1.3.0</ProductID>
            <ProductID>P-1339V-12.2.1.0</ProductID>
            <ProductID>P-1339V-12.2.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="192" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3565</Title>
      <Notes>
         <Note Audience="All" Ordinal="192" Title="Details" Type="Details">Vulnerability in the Oracle Retail Order Broker component of Oracle Retail Applications (subcomponent: System Administration).  Supported versions that are affected are 5.1 and  5.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Order Broker.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Order Broker accessible data as well as  unauthorized read access to a subset of Oracle Retail Order Broker accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Order Broker. CVSS 3.0 Base Score   7.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3565</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11520V-5.1</ProductID>
            <ProductID>P-11520V-5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.6</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-11520V-5.1</ProductID>
            <ProductID>P-11520V-5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="193" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3566</Title>
      <Notes>
         <Note Audience="All" Ordinal="193" Title="Details" Type="Details">Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web access).  Supported versions that are affected are 8.3, 8.4, 15.1, 15.2 and  16.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera P6 Enterprise Project Portfolio Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera P6 Enterprise Project Portfolio Management accessible data as well as  unauthorized read access to a subset of Primavera P6 Enterprise Project Portfolio Management accessible data. CVSS 3.0 Base Score   6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3566</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
            <ProductID>P-5579V-15.1</ProductID>
            <ProductID>P-5579V-15.2</ProductID>
            <ProductID>P-5579V-16.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
            <ProductID>P-5579V-15.1</ProductID>
            <ProductID>P-5579V-15.2</ProductID>
            <ProductID>P-5579V-16.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="194" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3567</Title>
      <Notes>
         <Note Audience="All" Ordinal="194" Title="Details" Type="Details">Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web access).  Supported versions that are affected are 8.3, 8.4, 15.1, 15.2 and  16.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera P6 Enterprise Project Portfolio Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera P6 Enterprise Project Portfolio Management accessible data as well as  unauthorized read access to a subset of Primavera P6 Enterprise Project Portfolio Management accessible data. CVSS 3.0 Base Score   5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3567</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
            <ProductID>P-5579V-15.1</ProductID>
            <ProductID>P-5579V-15.2</ProductID>
            <ProductID>P-5579V-16.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
            <ProductID>P-5579V-15.1</ProductID>
            <ProductID>P-5579V-15.2</ProductID>
            <ProductID>P-5579V-16.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="195" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3568</Title>
      <Notes>
         <Note Audience="All" Ordinal="195" Title="Details" Type="Details">Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web access).  Supported versions that are affected are 8.3, 8.4, 15.1, 15.2 and  16.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera P6 Enterprise Project Portfolio Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera P6 Enterprise Project Portfolio Management accessible data as well as  unauthorized read access to a subset of Primavera P6 Enterprise Project Portfolio Management accessible data. CVSS 3.0 Base Score   6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3568</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
            <ProductID>P-5579V-15.1</ProductID>
            <ProductID>P-5579V-15.2</ProductID>
            <ProductID>P-5579V-16.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
            <ProductID>P-5579V-15.1</ProductID>
            <ProductID>P-5579V-15.2</ProductID>
            <ProductID>P-5579V-16.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="196" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3569</Title>
      <Notes>
         <Note Audience="All" Ordinal="196" Title="Details" Type="Details">Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web access).  Supported versions that are affected are 8.3, 8.4, 15.1, 15.2 and  16.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera P6 Enterprise Project Portfolio Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera P6 Enterprise Project Portfolio Management accessible data as well as  unauthorized read access to a subset of Primavera P6 Enterprise Project Portfolio Management accessible data. CVSS 3.0 Base Score   6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3569</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
            <ProductID>P-5579V-15.1</ProductID>
            <ProductID>P-5579V-15.2</ProductID>
            <ProductID>P-5579V-16.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
            <ProductID>P-5579V-15.1</ProductID>
            <ProductID>P-5579V-15.2</ProductID>
            <ProductID>P-5579V-16.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="197" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3570</Title>
      <Notes>
         <Note Audience="All" Ordinal="197" Title="Details" Type="Details">Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web access).  Supported versions that are affected are 8.3, 8.4, 15.1, 15.2 and  16.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera P6 Enterprise Project Portfolio Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera P6 Enterprise Project Portfolio Management accessible data as well as  unauthorized read access to a subset of Primavera P6 Enterprise Project Portfolio Management accessible data. CVSS 3.0 Base Score   6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3570</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
            <ProductID>P-5579V-15.1</ProductID>
            <ProductID>P-5579V-15.2</ProductID>
            <ProductID>P-5579V-16.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
            <ProductID>P-5579V-15.1</ProductID>
            <ProductID>P-5579V-15.2</ProductID>
            <ProductID>P-5579V-16.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="198" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3571</Title>
      <Notes>
         <Note Audience="All" Ordinal="198" Title="Details" Type="Details">Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web access).  Supported versions that are affected are 8.3, 8.4, 15.1, 15.2 and  16.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera P6 Enterprise Project Portfolio Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera P6 Enterprise Project Portfolio Management accessible data as well as  unauthorized read access to a subset of Primavera P6 Enterprise Project Portfolio Management accessible data. CVSS 3.0 Base Score   6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3571</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
            <ProductID>P-5579V-15.1</ProductID>
            <ProductID>P-5579V-15.2</ProductID>
            <ProductID>P-5579V-16.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
            <ProductID>P-5579V-15.1</ProductID>
            <ProductID>P-5579V-15.2</ProductID>
            <ProductID>P-5579V-16.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="199" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3572</Title>
      <Notes>
         <Note Audience="All" Ordinal="199" Title="Details" Type="Details">Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access).  Supported versions that are affected are 8.3, 8.4, 15.1, 15.2 and  16.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management.  While the vulnerability is in Primavera P6 Enterprise Project Portfolio Management, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera P6 Enterprise Project Portfolio Management accessible data as well as  unauthorized read access to a subset of Primavera P6 Enterprise Project Portfolio Management accessible data. CVSS 3.0 Base Score   6.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3572</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
            <ProductID>P-5579V-15.1</ProductID>
            <ProductID>P-5579V-15.2</ProductID>
            <ProductID>P-5579V-16.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
            <ProductID>P-5579V-15.1</ProductID>
            <ProductID>P-5579V-15.2</ProductID>
            <ProductID>P-5579V-16.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="200" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3573</Title>
      <Notes>
         <Note Audience="All" Ordinal="200" Title="Details" Type="Details">Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web access).  Supported versions that are affected are 8.3, 8.4, 15.1, 15.2 and  16.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera P6 Enterprise Project Portfolio Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera P6 Enterprise Project Portfolio Management accessible data as well as  unauthorized read access to a subset of Primavera P6 Enterprise Project Portfolio Management accessible data. CVSS 3.0 Base Score   6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3573</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
            <ProductID>P-5579V-15.1</ProductID>
            <ProductID>P-5579V-15.2</ProductID>
            <ProductID>P-5579V-16.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
            <ProductID>P-5579V-15.1</ProductID>
            <ProductID>P-5579V-15.2</ProductID>
            <ProductID>P-5579V-16.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="201" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3574</Title>
      <Notes>
         <Note Audience="All" Ordinal="201" Title="Details" Type="Details">Vulnerability in the Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.5.0, 8.5.1 and  8.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Outside In Technology.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Outside In Technology accessible data as well as  unauthorized update, insert or delete access to some of Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Outside In Technology.  Note: Outside In Technology is a suite of software development kits (SDKs).
The protocol and CVSS score depend on the software that uses the Outside In
Technology code. The CVSS score assumes that the software passes data
received over a network directly to Outside In Technology code, but if data
is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score   8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3574</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="202" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3575</Title>
      <Notes>
         <Note Audience="All" Ordinal="202" Title="Details" Type="Details">Vulnerability in the Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.5.0, 8.5.1 and  8.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Outside In Technology.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Outside In Technology accessible data as well as  unauthorized update, insert or delete access to some of Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Outside In Technology.  Note: Outside In Technology is a suite of software development kits (SDKs).
The protocol and CVSS score depend on the software that uses the Outside In
Technology code. The CVSS score assumes that the software passes data
received over a network directly to Outside In Technology code, but if data
is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score   8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3575</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="203" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3576</Title>
      <Notes>
         <Note Audience="All" Ordinal="203" Title="Details" Type="Details">Vulnerability in the Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.5.0, 8.5.1 and  8.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Outside In Technology.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Outside In Technology accessible data as well as  unauthorized update, insert or delete access to some of Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Outside In Technology.  Note: Outside In Technology is a suite of software development kits (SDKs).
The protocol and CVSS score depend on the software that uses the Outside In
Technology code. The CVSS score assumes that the software passes data
received over a network directly to Outside In Technology code, but if data
is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score   8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3576</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="204" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3577</Title>
      <Notes>
         <Note Audience="All" Ordinal="204" Title="Details" Type="Details">Vulnerability in the Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.5.0, 8.5.1 and  8.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Outside In Technology.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Outside In Technology accessible data as well as  unauthorized update, insert or delete access to some of Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Outside In Technology.  Note: Outside In Technology is a suite of software development kits (SDKs).
The protocol and CVSS score depend on the software that uses the Outside In
Technology code. The CVSS score assumes that the software passes data
received over a network directly to Outside In Technology code, but if data
is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score   8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3577</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="205" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3578</Title>
      <Notes>
         <Note Audience="All" Ordinal="205" Title="Details" Type="Details">Vulnerability in the Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.5.0, 8.5.1 and  8.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Outside In Technology.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Outside In Technology accessible data as well as  unauthorized update, insert or delete access to some of Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Outside In Technology.  Note: Outside In Technology is a suite of software development kits (SDKs).
The protocol and CVSS score depend on the software that uses the Outside In
Technology code. The CVSS score assumes that the software passes data
received over a network directly to Outside In Technology code, but if data
is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score   8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3578</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="206" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3579</Title>
      <Notes>
         <Note Audience="All" Ordinal="206" Title="Details" Type="Details">Vulnerability in the Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.5.0, 8.5.1 and  8.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Outside In Technology.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Outside In Technology accessible data as well as  unauthorized update, insert or delete access to some of Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Outside In Technology.  Note: Outside In Technology is a suite of software development kits (SDKs).
The protocol and CVSS score depend on the software that uses the Outside In
Technology code. The CVSS score assumes that the software passes data
received over a network directly to Outside In Technology code, but if data
is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score   8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3579</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="207" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3580</Title>
      <Notes>
         <Note Audience="All" Ordinal="207" Title="Details" Type="Details">Vulnerability in the Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.5.0, 8.5.1 and  8.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Outside In Technology.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Outside In Technology accessible data as well as  unauthorized update, insert or delete access to some of Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Outside In Technology.  Note: Outside In Technology is a suite of software development kits (SDKs).
The protocol and CVSS score depend on the software that uses the Outside In
Technology code. The CVSS score assumes that the software passes data
received over a network directly to Outside In Technology code, but if data
is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score   8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3580</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="208" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3581</Title>
      <Notes>
         <Note Audience="All" Ordinal="208" Title="Details" Type="Details">Vulnerability in the Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.5.0, 8.5.1 and  8.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Outside In Technology.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Outside In Technology accessible data as well as  unauthorized update, insert or delete access to some of Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Outside In Technology.  Note: Outside In Technology is a suite of software development kits (SDKs).
The protocol and CVSS score depend on the software that uses the Outside In
Technology code. The CVSS score assumes that the software passes data
received over a network directly to Outside In Technology code, but if data
is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score   8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3581</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="209" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3582</Title>
      <Notes>
         <Note Audience="All" Ordinal="209" Title="Details" Type="Details">Vulnerability in the Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.5.0, 8.5.1 and  8.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Outside In Technology.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Outside In Technology accessible data as well as  unauthorized update, insert or delete access to some of Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Outside In Technology.  Note: Outside In Technology is a suite of software development kits (SDKs).
The protocol and CVSS score depend on the software that uses the Outside In
Technology code. The CVSS score assumes that the software passes data
received over a network directly to Outside In Technology code, but if data
is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score   8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3582</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="210" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3583</Title>
      <Notes>
         <Note Audience="All" Ordinal="210" Title="Details" Type="Details">Vulnerability in the Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.5.0, 8.5.1 and  8.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Outside In Technology.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Outside In Technology accessible data as well as  unauthorized update, insert or delete access to some of Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Outside In Technology.  Note: Outside In Technology is a suite of software development kits (SDKs).
The protocol and CVSS score depend on the software that uses the Outside In
Technology code. The CVSS score assumes that the software passes data
received over a network directly to Outside In Technology code, but if data
is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score   8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3583</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="211" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3584</Title>
      <Notes>
         <Note Audience="All" Ordinal="211" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Libadimalloc).   The supported version that is affected is 11.3. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris.  Successful attacks of this vulnerability can result in takeover of Solaris. CVSS 3.0 Base Score   7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3584</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.0</BaseScore>
            <Vector>AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-10006V-11.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="212" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3585</Title>
      <Notes>
         <Note Audience="All" Ordinal="212" Title="Details" Type="Details">Vulnerability in the ILOM component of Oracle Sun Systems Products Suite (subcomponent: Emulex).  Supported versions that are affected are 3.0, 3.1 and  3.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise ILOM.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all ILOM accessible data as well as  unauthorized access to critical data or complete access to all ILOM accessible data. CVSS 3.0 Base Score   7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3585</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9849V-3.0</ProductID>
            <ProductID>P-9849V-3.1</ProductID>
            <ProductID>P-9849V-3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.4</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9849V-3.0</ProductID>
            <ProductID>P-9849V-3.1</ProductID>
            <ProductID>P-9849V-3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="213" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3586</Title>
      <Notes>
         <Note Audience="All" Ordinal="213" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components).  Supported versions that are affected are 10.3.6.0, 12.1.3.0 and  12.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score   9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3586</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.3.6.0</ProductID>
            <ProductID>P-5242V-12.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5242V-10.3.6.0</ProductID>
            <ProductID>P-5242V-12.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="214" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3587</Title>
      <Notes>
         <Note Audience="All" Ordinal="214" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot).   The supported version that is affected is Java SE: 8u92; Java SE Embedded: 8u91. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score   9.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3587</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 8u92; Java SE Embedded: 8u91</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-856V-Java SE: 8u92; Java SE Embedded: 8u91</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="215" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3588</Title>
      <Notes>
         <Note Audience="All" Ordinal="215" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB
).  Supported versions that are affected are 5.7.12 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score   5.9 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3588</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="216" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3589</Title>
      <Notes>
         <Note Audience="All" Ordinal="216" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Applications (subcomponent: Base).  Supported versions that are affected are 12.0.1, 12.0.2 and  12.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Direct Banking.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle FLEXCUBE Direct Banking, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle FLEXCUBE Direct Banking accessible data as well as  unauthorized read access to a subset of Oracle FLEXCUBE Direct Banking accessible data. CVSS 3.0 Base Score   6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3589</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9111V-12.0.1</ProductID>
            <ProductID>P-9111V-12.0.2</ProductID>
            <ProductID>P-9111V-12.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9111V-12.0.1</ProductID>
            <ProductID>P-9111V-12.0.2</ProductID>
            <ProductID>P-9111V-12.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="217" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3590</Title>
      <Notes>
         <Note Audience="All" Ordinal="217" Title="Details" Type="Details">Vulnerability in the Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.5.0, 8.5.1 and  8.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Outside In Technology.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Outside In Technology accessible data as well as  unauthorized update, insert or delete access to some of Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Outside In Technology.  Note: Outside In Technology is a suite of software development kits (SDKs).
The protocol and CVSS score depend on the software that uses the Outside In
Technology code. The CVSS score assumes that the software passes data
received over a network directly to Outside In Technology code, but if data
is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score   8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3590</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="218" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3591</Title>
      <Notes>
         <Note Audience="All" Ordinal="218" Title="Details" Type="Details">Vulnerability in the Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.5.0, 8.5.1 and  8.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Outside In Technology.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Outside In Technology accessible data as well as  unauthorized update, insert or delete access to some of Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Outside In Technology.  Note: Outside In Technology is a suite of software development kits (SDKs).
The protocol and CVSS score depend on the software that uses the Outside In
Technology code. The CVSS score assumes that the software passes data
received over a network directly to Outside In Technology code, but if data
is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score   8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3591</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="219" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3592</Title>
      <Notes>
         <Note Audience="All" Ordinal="219" Title="Details" Type="Details">Vulnerability in the Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.5.0, 8.5.1 and  8.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Outside In Technology.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Outside In Technology accessible data as well as  unauthorized update, insert or delete access to some of Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Outside In Technology.  Note: Outside In Technology is a suite of software development kits (SDKs).
The protocol and CVSS score depend on the software that uses the Outside In
Technology code. The CVSS score assumes that the software passes data
received over a network directly to Outside In Technology code, but if data
is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score   8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3592</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="220" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3593</Title>
      <Notes>
         <Note Audience="All" Ordinal="220" Title="Details" Type="Details">Vulnerability in the Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.5.0, 8.5.1 and  8.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Outside In Technology.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Outside In Technology accessible data as well as  unauthorized update, insert or delete access to some of Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Outside In Technology.  Note: Outside In Technology is a suite of software development kits (SDKs).
The protocol and CVSS score depend on the software that uses the Outside In
Technology code. The CVSS score assumes that the software passes data
received over a network directly to Outside In Technology code, but if data
is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score   8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3593</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="221" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3594</Title>
      <Notes>
         <Note Audience="All" Ordinal="221" Title="Details" Type="Details">Vulnerability in the Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.5.0, 8.5.1 and  8.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Outside In Technology.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Outside In Technology accessible data as well as  unauthorized update, insert or delete access to some of Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Outside In Technology.  Note: Outside In Technology is a suite of software development kits (SDKs).
The protocol and CVSS score depend on the software that uses the Outside In
Technology code. The CVSS score assumes that the software passes data
received over a network directly to Outside In Technology code, but if data
is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score   8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3594</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="222" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3595</Title>
      <Notes>
         <Note Audience="All" Ordinal="222" Title="Details" Type="Details">Vulnerability in the Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.5.0, 8.5.1 and  8.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Outside In Technology.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Outside In Technology accessible data as well as  unauthorized update, insert or delete access to some of Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Outside In Technology.  Note: Outside In Technology is a suite of software development kits (SDKs).
The protocol and CVSS score depend on the software that uses the Outside In
Technology code. The CVSS score assumes that the software passes data
received over a network directly to Outside In Technology code, but if data
is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score   8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3595</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="223" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3596</Title>
      <Notes>
         <Note Audience="All" Ordinal="223" Title="Details" Type="Details">Vulnerability in the Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.5.0, 8.5.1 and  8.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Outside In Technology.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Outside In Technology accessible data as well as  unauthorized update, insert or delete access to some of Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Outside In Technology.  Note: Outside In Technology is a suite of software development kits (SDKs).
The protocol and CVSS score depend on the software that uses the Outside In
Technology code. The CVSS score assumes that the software passes data
received over a network directly to Outside In Technology code, but if data
is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score   8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3596</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="224" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3597</Title>
      <Notes>
         <Note Audience="All" Ordinal="224" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core).   The supported version that is affected is VirtualBox prior to 5.0.26. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score   5.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3597</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-VirtualBox prior to 5.0.26</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8370V-VirtualBox prior to 5.0.26</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="225" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3598</Title>
      <Notes>
         <Note Audience="All" Ordinal="225" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries).   The supported version that is affected is Java SE: 8u92; Java SE Embedded: 8u91. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score   9.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3598</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 8u92; Java SE Embedded: 8u91</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-856V-Java SE: 8u92; Java SE Embedded: 8u91</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="226" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3606</Title>
      <Notes>
         <Note Audience="All" Ordinal="226" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot).  Supported versions that are affected are Java SE: 7u101 and  8u92; Java SE Embedded: 8u91. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score   9.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3606</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 7u101</ProductID>
            <ProductID>P-856V-8u92; Java SE Embedded: 8u91</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-856V-Java SE: 7u101</ProductID>
            <ProductID>P-856V-8u92; Java SE Embedded: 8u91</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="227" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3607</Title>
      <Notes>
         <Note Audience="All" Ordinal="227" Title="Details" Type="Details">Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Web Container).  Supported versions that are affected are 3.0.1 and  3.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GlassFish Server.  Successful attacks of this vulnerability can result in takeover of Oracle GlassFish Server. CVSS 3.0 Base Score   9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3607</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8493V-3.0.1</ProductID>
            <ProductID>P-8493V-3.1.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8493V-3.0.1</ProductID>
            <ProductID>P-8493V-3.1.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="228" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3608</Title>
      <Notes>
         <Note Audience="All" Ordinal="228" Title="Details" Type="Details">Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Administration).   The supported version that is affected is 3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GlassFish Server.  While the vulnerability is in Oracle GlassFish Server, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle GlassFish Server accessible data. CVSS 3.0 Base Score   5.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3608</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8493V-3.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8493V-3.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="229" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3609</Title>
      <Notes>
         <Note Audience="All" Ordinal="229" Title="Details" Type="Details">Vulnerability in the OJVM component of Oracle Database Server.  Supported versions that are affected are 11.2.0.4, 12.1.0.1 and 12.1.0.2. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via multiple protocols to compromise OJVM.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in OJVM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of OJVM.  Note: The score 9.0 is for Windows platform. On Linux platform the score is 8.0. CVSS 3.0 Base Score   9.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3609</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.1</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.0</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.1</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="230" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3610</Title>
      <Notes>
         <Note Audience="All" Ordinal="230" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries).   The supported version that is affected is Java SE: 8u92; Java SE Embedded: 8u91. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score   9.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3610</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 8u92; Java SE Embedded: 8u91</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-856V-Java SE: 8u92; Java SE Embedded: 8u91</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="231" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3611</Title>
      <Notes>
         <Note Audience="All" Ordinal="231" Title="Details" Type="Details">Vulnerability in the Oracle Retail Order Broker component of Oracle Retail Applications (subcomponent: System Administration).   The supported version that is affected is 15.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Order Broker.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Retail Order Broker accessible data as well as  unauthorized read access to a subset of Oracle Retail Order Broker accessible data. CVSS 3.0 Base Score   5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3611</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11520V-15.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-11520V-15.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="232" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3612</Title>
      <Notes>
         <Note Audience="All" Ordinal="232" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core).   The supported version that is affected is VirtualBox prior to 5.0.22. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSL/TLS to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score   5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3612</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-VirtualBox prior to 5.0.22</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8370V-VirtualBox prior to 5.0.22</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="233" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3613</Title>
      <Notes>
         <Note Audience="All" Ordinal="233" Title="Details" Type="Details">Vulnerability in the Oracle Secure Global Desktop component of Oracle Virtualization (subcomponent: OpenSSL).  Supported versions that are affected are 4.63, 4.71 and  5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via SSL/TLS to compromise Oracle Secure Global Desktop.  Successful attacks of this vulnerability can result in takeover of Oracle Secure Global Desktop. CVSS 3.0 Base Score   9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3613</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8539V-4.63</ProductID>
            <ProductID>P-8539V-4.71</ProductID>
            <ProductID>P-8539V-5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8539V-4.63</ProductID>
            <ProductID>P-8539V-4.71</ProductID>
            <ProductID>P-8539V-5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="234" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3614</Title>
      <Notes>
         <Note Audience="All" Ordinal="234" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encryption).  Supported versions that are affected are 5.6.30 and earlier and 
5.7.12 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score   5.3 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3614</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.30 and earlier</ProductID>
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8478V-5.6.30 and earlier</ProductID>
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="235" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3615</Title>
      <Notes>
         <Note Audience="All" Ordinal="235" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML).  Supported versions that are affected are 5.5.49 and earlier, 
5.6.30 and earlier and 
5.7.12 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score   5.3 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3615</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.49 and earlier</ProductID>
            <ProductID>P-8478V-5.6.30 and earlier</ProductID>
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8478V-5.5.49 and earlier</ProductID>
            <ProductID>P-8478V-5.6.30 and earlier</ProductID>
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="236" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5436</Title>
      <Notes>
         <Note Audience="All" Ordinal="236" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB).  Supported versions that are affected are 5.7.12 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score   4.9 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5436</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="237" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5437</Title>
      <Notes>
         <Note Audience="All" Ordinal="237" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Log).  Supported versions that are affected are 5.7.12 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score   4.9 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5437</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="238" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5439</Title>
      <Notes>
         <Note Audience="All" Ordinal="238" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Privileges).  Supported versions that are affected are 5.6.30 and earlier and 
5.7.12 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score   4.9 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5439</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.30 and earlier</ProductID>
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8478V-5.6.30 and earlier</ProductID>
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="239" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5440</Title>
      <Notes>
         <Note Audience="All" Ordinal="239" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: RBR).  Supported versions that are affected are 5.5.49 and earlier, 
5.6.30 and earlier and 
5.7.12 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score   4.9 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5440</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.49 and earlier</ProductID>
            <ProductID>P-8478V-5.6.30 and earlier</ProductID>
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8478V-5.5.49 and earlier</ProductID>
            <ProductID>P-8478V-5.6.30 and earlier</ProductID>
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="240" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5441</Title>
      <Notes>
         <Note Audience="All" Ordinal="240" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication).  Supported versions that are affected are 5.7.12 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score   4.9 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5441</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="241" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5442</Title>
      <Notes>
         <Note Audience="All" Ordinal="241" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encryption
).  Supported versions that are affected are 5.7.12 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score   4.9 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5442</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="242" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5443</Title>
      <Notes>
         <Note Audience="All" Ordinal="242" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Connection).  Supported versions that are affected are 5.7.12 and earlier. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score   4.7 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5443</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.7</BaseScore>
            <Vector>AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8478V-5.7.12 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="243" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5444</Title>
      <Notes>
         <Note Audience="All" Ordinal="243" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Connection).  Supported versions that are affected are 5.5.48 and earlier, 
5.6.29 and earlier and 
5.7.11 and earlier. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.0 Base Score   3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5444</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.48 and earlier</ProductID>
            <ProductID>P-8478V-5.6.29 and earlier</ProductID>
            <ProductID>P-8478V-5.7.11 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8478V-5.5.48 and earlier</ProductID>
            <ProductID>P-8478V-5.6.29 and earlier</ProductID>
            <ProductID>P-8478V-5.7.11 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="244" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5445</Title>
      <Notes>
         <Note Audience="All" Ordinal="244" Title="Details" Type="Details">Vulnerability in the ILOM component of Oracle Sun Systems Products Suite (subcomponent: Authentication).  Supported versions that are affected are 3.0, 3.1 and  3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise ILOM.  While the vulnerability is in ILOM, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of ILOM accessible data as well as  unauthorized read access to a subset of ILOM accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of ILOM. CVSS 3.0 Base Score   8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5445</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9849V-3.0</ProductID>
            <ProductID>P-9849V-3.1</ProductID>
            <ProductID>P-9849V-3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9849V-3.0</ProductID>
            <ProductID>P-9849V-3.1</ProductID>
            <ProductID>P-9849V-3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="245" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5446</Title>
      <Notes>
         <Note Audience="All" Ordinal="245" Title="Details" Type="Details">Vulnerability in the ILOM component of Oracle Sun Systems Products Suite (subcomponent: Infrastructure).  Supported versions that are affected are 3.0, 3.1 and  3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise ILOM.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of ILOM accessible data as well as  unauthorized read access to a subset of ILOM accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of ILOM. CVSS 3.0 Base Score   7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5446</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9849V-3.0</ProductID>
            <ProductID>P-9849V-3.1</ProductID>
            <ProductID>P-9849V-3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9849V-3.0</ProductID>
            <ProductID>P-9849V-3.1</ProductID>
            <ProductID>P-9849V-3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="246" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5447</Title>
      <Notes>
         <Note Audience="All" Ordinal="246" Title="Details" Type="Details">Vulnerability in the ILOM component of Oracle Sun Systems Products Suite (subcomponent: Backup-Restore).  Supported versions that are affected are 3.0, 3.1 and  3.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise ILOM.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all ILOM accessible data as well as  unauthorized update, insert or delete access to some of ILOM accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of ILOM. CVSS 3.0 Base Score   7.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5447</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9849V-3.0</ProductID>
            <ProductID>P-9849V-3.1</ProductID>
            <ProductID>P-9849V-3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.6</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9849V-3.0</ProductID>
            <ProductID>P-9849V-3.1</ProductID>
            <ProductID>P-9849V-3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="247" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5448</Title>
      <Notes>
         <Note Audience="All" Ordinal="247" Title="Details" Type="Details">Vulnerability in the ILOM component of Oracle Sun Systems Products Suite (subcomponent: SNMP).  Supported versions that are affected are 3.0, 3.1 and  3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via SNMP to compromise ILOM.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of ILOM accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of ILOM. CVSS 3.0 Base Score   6.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5448</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9849V-3.0</ProductID>
            <ProductID>P-9849V-3.1</ProductID>
            <ProductID>P-9849V-3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9849V-3.0</ProductID>
            <ProductID>P-9849V-3.1</ProductID>
            <ProductID>P-9849V-3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="248" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5449</Title>
      <Notes>
         <Note Audience="All" Ordinal="248" Title="Details" Type="Details">Vulnerability in the ILOM component of Oracle Sun Systems Products Suite (subcomponent: Console Redirection).  Supported versions that are affected are 3.0, 3.1 and  3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise ILOM.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of ILOM. CVSS 3.0 Base Score   7.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5449</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9849V-3.0</ProductID>
            <ProductID>P-9849V-3.1</ProductID>
            <ProductID>P-9849V-3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9849V-3.0</ProductID>
            <ProductID>P-9849V-3.1</ProductID>
            <ProductID>P-9849V-3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="249" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5450</Title>
      <Notes>
         <Note Audience="All" Ordinal="249" Title="Details" Type="Details">Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: UIF Open UI).  Supported versions that are affected are 8.1.1, 8.2.2, IP2014, IP2015 and  IP2016. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel UI Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel UI Framework accessible data. CVSS 3.0 Base Score   4.7 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5450</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
            <ProductID>P-9011V-IP2014</ProductID>
            <ProductID>P-9011V-IP2015</ProductID>
            <ProductID>P-9011V-IP2016</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.7</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
            <ProductID>P-9011V-IP2014</ProductID>
            <ProductID>P-9011V-IP2015</ProductID>
            <ProductID>P-9011V-IP2016</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="250" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5451</Title>
      <Notes>
         <Note Audience="All" Ordinal="250" Title="Details" Type="Details">Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: EAI).  Supported versions that are affected are 8.1.1, 8.2.2, IP2014, IP2015 and  IP2016. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel UI Framework.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel UI Framework accessible data as well as  unauthorized access to critical data or complete access to all Siebel UI Framework accessible data. CVSS 3.0 Base Score   8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5451</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
            <ProductID>P-9011V-IP2014</ProductID>
            <ProductID>P-9011V-IP2015</ProductID>
            <ProductID>P-9011V-IP2016</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
            <ProductID>P-9011V-IP2014</ProductID>
            <ProductID>P-9011V-IP2015</ProductID>
            <ProductID>P-9011V-IP2016</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="251" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5452</Title>
      <Notes>
         <Note Audience="All" Ordinal="251" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Verified Boot).   The supported version that is affected is 11.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Solaris accessible data. CVSS 3.0 Base Score   5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5452</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-10006V-11.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="252" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5453</Title>
      <Notes>
         <Note Audience="All" Ordinal="252" Title="Details" Type="Details">Vulnerability in the ILOM component of Oracle Sun Systems Products Suite (subcomponent: IPMI).  Supported versions that are affected are 3.0, 3.1 and  3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via IPMI to compromise ILOM.  Successful attacks of this vulnerability can result in takeover of ILOM. CVSS 3.0 Base Score   9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5453</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9849V-3.0</ProductID>
            <ProductID>P-9849V-3.1</ProductID>
            <ProductID>P-9849V-3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9849V-3.0</ProductID>
            <ProductID>P-9849V-3.1</ProductID>
            <ProductID>P-9849V-3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="253" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5454</Title>
      <Notes>
         <Note Audience="All" Ordinal="253" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Verified Boot).   The supported version that is affected is 11.3. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris.  While the vulnerability is in Solaris, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Solaris as well as  unauthorized update, insert or delete access to some of Solaris accessible data. CVSS 3.0 Base Score   6.4 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5454</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.4</BaseScore>
            <Vector>AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-10006V-11.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="254" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5455</Title>
      <Notes>
         <Note Audience="All" Ordinal="254" Title="Details" Type="Details">Vulnerability in the Oracle Communications Messaging Server component of Oracle Communications Applications (subcomponent: Multiplexor).  Supported versions that are affected are 6.3, 7.0 and  8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Messaging Server.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Messaging Server accessible data. CVSS 3.0 Base Score   5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5455</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8496V-6.3</ProductID>
            <ProductID>P-8496V-7.0</ProductID>
            <ProductID>P-8496V-8.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8496V-6.3</ProductID>
            <ProductID>P-8496V-7.0</ProductID>
            <ProductID>P-8496V-8.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="255" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5456</Title>
      <Notes>
         <Note Audience="All" Ordinal="255" Title="Details" Type="Details">Vulnerability in the Siebel Core - Server Framework component of Oracle Siebel CRM (subcomponent: Services).  Supported versions that are affected are 8.1.1, 8.2.2, IP2014, IP2015 and  IP2016. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Core - Server Framework.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel Core - Server Framework accessible data. CVSS 3.0 Base Score   5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5456</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9001V-8.1.1</ProductID>
            <ProductID>P-9001V-8.2.2</ProductID>
            <ProductID>P-9001V-IP2014</ProductID>
            <ProductID>P-9001V-IP2015</ProductID>
            <ProductID>P-9001V-IP2016</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9001V-8.1.1</ProductID>
            <ProductID>P-9001V-8.2.2</ProductID>
            <ProductID>P-9001V-IP2014</ProductID>
            <ProductID>P-9001V-IP2015</ProductID>
            <ProductID>P-9001V-IP2016</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="256" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5457</Title>
      <Notes>
         <Note Audience="All" Ordinal="256" Title="Details" Type="Details">Vulnerability in the ILOM component of Oracle Sun Systems Products Suite (subcomponent: LUMAIN).  Supported versions that are affected are 3.0, 3.1 and  3.2. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise ILOM.  Successful attacks of this vulnerability can result in takeover of ILOM. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5457</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9849V-3.0</ProductID>
            <ProductID>P-9849V-3.1</ProductID>
            <ProductID>P-9849V-3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9849V-3.0</ProductID>
            <ProductID>P-9849V-3.1</ProductID>
            <ProductID>P-9849V-3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="257" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5458</Title>
      <Notes>
         <Note Audience="All" Ordinal="257" Title="Details" Type="Details">Vulnerability in the Oracle Communications EAGLE Application Processor component of Oracle Communications Applications (subcomponent: APPL).   The supported version that is affected is 16.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications EAGLE Application Processor.  While the vulnerability is in Oracle Communications EAGLE Application Processor, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications EAGLE Application Processor accessible data as well as  unauthorized read access to a subset of Oracle Communications EAGLE Application Processor accessible data. CVSS 3.0 Base Score   6.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5458</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11122V-16.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-11122V-16.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="258" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5459</Title>
      <Notes>
         <Note Audience="All" Ordinal="258" Title="Details" Type="Details">Vulnerability in the Siebel Core - Common Components component of Oracle Siebel CRM (subcomponent: iHelp).  Supported versions that are affected are 8.1.1, 8.2.2, IP2014, IP2015 and  IP2016. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Core - Common Components.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel Core - Common Components, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel Core - Common Components accessible data. CVSS 3.0 Base Score   4.7 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5459</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9747V-8.1.1</ProductID>
            <ProductID>P-9747V-8.2.2</ProductID>
            <ProductID>P-9747V-IP2014</ProductID>
            <ProductID>P-9747V-IP2015</ProductID>
            <ProductID>P-9747V-IP2016</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.7</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9747V-8.1.1</ProductID>
            <ProductID>P-9747V-8.2.2</ProductID>
            <ProductID>P-9747V-IP2014</ProductID>
            <ProductID>P-9747V-IP2015</ProductID>
            <ProductID>P-9747V-IP2016</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="259" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5460</Title>
      <Notes>
         <Note Audience="All" Ordinal="259" Title="Details" Type="Details">Vulnerability in the Siebel Core - Server Framework component of Oracle Siebel CRM (subcomponent: Services).  Supported versions that are affected are 8.1.1, 8.2.2, IP2014, IP2015 and  IP2016. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Core - Server Framework.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Siebel Core - Server Framework accessible data. CVSS 3.0 Base Score   3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5460</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9001V-8.1.1</ProductID>
            <ProductID>P-9001V-8.2.2</ProductID>
            <ProductID>P-9001V-IP2014</ProductID>
            <ProductID>P-9001V-IP2015</ProductID>
            <ProductID>P-9001V-IP2016</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9001V-8.1.1</ProductID>
            <ProductID>P-9001V-8.2.2</ProductID>
            <ProductID>P-9001V-IP2014</ProductID>
            <ProductID>P-9001V-IP2015</ProductID>
            <ProductID>P-9001V-IP2016</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="260" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5461</Title>
      <Notes>
         <Note Audience="All" Ordinal="260" Title="Details" Type="Details">Vulnerability in the Siebel Core - Server Framework component of Oracle Siebel CRM (subcomponent: Object Manager).  Supported versions that are affected are 8.1.1, 8.2.2, IP2014, IP2015 and  IP2016. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Core - Server Framework.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel Core - Server Framework accessible data. CVSS 3.0 Base Score   6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5461</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9001V-8.1.1</ProductID>
            <ProductID>P-9001V-8.2.2</ProductID>
            <ProductID>P-9001V-IP2014</ProductID>
            <ProductID>P-9001V-IP2015</ProductID>
            <ProductID>P-9001V-IP2016</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9001V-8.1.1</ProductID>
            <ProductID>P-9001V-8.2.2</ProductID>
            <ProductID>P-9001V-IP2014</ProductID>
            <ProductID>P-9001V-IP2015</ProductID>
            <ProductID>P-9001V-IP2016</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="261" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5462</Title>
      <Notes>
         <Note Audience="All" Ordinal="261" Title="Details" Type="Details">Vulnerability in the Siebel Core - Server Framework component of Oracle Siebel CRM (subcomponent: Workspaces).  Supported versions that are affected are 8.1.1, 8.2.2, IP2014, IP2015 and  IP2016. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel Core - Server Framework.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Siebel Core - Server Framework accessible data. CVSS 3.0 Base Score   2.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5462</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9001V-8.1.1</ProductID>
            <ProductID>P-9001V-8.2.2</ProductID>
            <ProductID>P-9001V-IP2014</ProductID>
            <ProductID>P-9001V-IP2015</ProductID>
            <ProductID>P-9001V-IP2016</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.7</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9001V-8.1.1</ProductID>
            <ProductID>P-9001V-8.2.2</ProductID>
            <ProductID>P-9001V-IP2014</ProductID>
            <ProductID>P-9001V-IP2015</ProductID>
            <ProductID>P-9001V-IP2016</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="262" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5463</Title>
      <Notes>
         <Note Audience="All" Ordinal="262" Title="Details" Type="Details">Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: SWSE Server).  Supported versions that are affected are 8.1.1, 8.2.2, IP2014, IP2015 and  IP2016. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel UI Framework.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel UI Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel UI Framework accessible data. CVSS 3.0 Base Score   4.1 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5463</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
            <ProductID>P-9011V-IP2014</ProductID>
            <ProductID>P-9011V-IP2015</ProductID>
            <ProductID>P-9011V-IP2016</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
            <ProductID>P-9011V-IP2014</ProductID>
            <ProductID>P-9011V-IP2015</ProductID>
            <ProductID>P-9011V-IP2016</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="263" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5464</Title>
      <Notes>
         <Note Audience="All" Ordinal="263" Title="Details" Type="Details">Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: SWSE Server).  Supported versions that are affected are 8.1.1, 8.2.2, IP2014, IP2015 and  IP2016. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel UI Framework.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel UI Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel UI Framework accessible data. CVSS 3.0 Base Score   4.1 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5464</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
            <ProductID>P-9011V-IP2014</ProductID>
            <ProductID>P-9011V-IP2015</ProductID>
            <ProductID>P-9011V-IP2016</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
            <ProductID>P-9011V-IP2014</ProductID>
            <ProductID>P-9011V-IP2015</ProductID>
            <ProductID>P-9011V-IP2016</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="264" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5465</Title>
      <Notes>
         <Note Audience="All" Ordinal="264" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Panel Processor).  Supported versions that are affected are 8.53, 8.54 and  8.55. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score   8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5465</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.53</ProductID>
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5085V-8.53</ProductID>
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="265" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5466</Title>
      <Notes>
         <Note Audience="All" Ordinal="265" Title="Details" Type="Details">Vulnerability in the Siebel Core - Server Framework component of Oracle Siebel CRM (subcomponent: Services).  Supported versions that are affected are 8.1.1, 8.2.2, IP2014, IP2015 and  IP2016. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Core - Server Framework.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Siebel Core - Server Framework accessible data. CVSS 3.0 Base Score   3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5466</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9001V-8.1.1</ProductID>
            <ProductID>P-9001V-8.2.2</ProductID>
            <ProductID>P-9001V-IP2014</ProductID>
            <ProductID>P-9001V-IP2015</ProductID>
            <ProductID>P-9001V-IP2016</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9001V-8.1.1</ProductID>
            <ProductID>P-9001V-8.2.2</ProductID>
            <ProductID>P-9001V-IP2014</ProductID>
            <ProductID>P-9001V-IP2015</ProductID>
            <ProductID>P-9001V-IP2016</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="266" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5467</Title>
      <Notes>
         <Note Audience="All" Ordinal="266" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise FSCM component of Oracle PeopleSoft Products (subcomponent: eProcurement).  Supported versions that are affected are 9.1 and  9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FSCM.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise FSCM accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise FSCM accessible data. CVSS 3.0 Base Score   5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5467</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5118V-9.1</ProductID>
            <ProductID>P-5118V-9.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5118V-9.1</ProductID>
            <ProductID>P-5118V-9.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="267" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5468</Title>
      <Notes>
         <Note Audience="All" Ordinal="267" Title="Details" Type="Details">Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: EAI).  Supported versions that are affected are 8.1.1, 8.2.2, IP2014, IP2015 and  IP2016. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel UI Framework.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel UI Framework accessible data as well as  unauthorized read access to a subset of Siebel UI Framework accessible data. CVSS 3.0 Base Score   5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5468</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
            <ProductID>P-9011V-IP2014</ProductID>
            <ProductID>P-9011V-IP2015</ProductID>
            <ProductID>P-9011V-IP2016</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
            <ProductID>P-9011V-IP2014</ProductID>
            <ProductID>P-9011V-IP2015</ProductID>
            <ProductID>P-9011V-IP2016</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="268" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5469</Title>
      <Notes>
         <Note Audience="All" Ordinal="268" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel).   The supported version that is affected is 11.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Solaris. CVSS 3.0 Base Score   5.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5469</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-10006V-11.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="269" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5470</Title>
      <Notes>
         <Note Audience="All" Ordinal="269" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Application Designer).  Supported versions that are affected are 8.54 and  8.55. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score   6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5470</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="270" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5471</Title>
      <Notes>
         <Note Audience="All" Ordinal="270" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel).   The supported version that is affected is 11.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Solaris. CVSS 3.0 Base Score   5.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5471</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-10006V-11.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="271" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5472</Title>
      <Notes>
         <Note Audience="All" Ordinal="271" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Install and Packaging).  Supported versions that are affected are 8.54 and  8.55. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.0 Base Score   7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5472</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="272" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5473</Title>
      <Notes>
         <Note Audience="All" Ordinal="272" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: File Folders / Attachment).  Supported versions that are affected are 9.3.4 and  9.3.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.0 Base Score   3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5473</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.1</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-4461V-9.3.4</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="273" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5474</Title>
      <Notes>
         <Note Audience="All" Ordinal="273" Title="Details" Type="Details">Vulnerability in the Oracle Retail Service Backbone component of Oracle Retail Applications (subcomponent: RSB Kernel).  Supported versions that are affected are 14.0, 14.1 and 15.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Service Backbone. CVSS 3.0 Base Score   8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5474</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10867V-14.0</ProductID>
            <ProductID>P-10867V-14.1</ProductID>
            <ProductID>P-10867V-15.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-10867V-14.0</ProductID>
            <ProductID>P-10867V-14.1</ProductID>
            <ProductID>P-10867V-15.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="274" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5475</Title>
      <Notes>
         <Note Audience="All" Ordinal="274" Title="Details" Type="Details">Vulnerability in the Oracle Retail Service Backbone component of Oracle Retail Applications (subcomponent: Install).  Supported versions that are affected are 14.0, 14.1 and 15.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Service Backbone accessible data as well as  unauthorized update, insert or delete access to some of Oracle Retail Service Backbone accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Service Backbone. CVSS 3.0 Base Score   7.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5475</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10867V-14.0</ProductID>
            <ProductID>P-10867V-14.1</ProductID>
            <ProductID>P-10867V-15.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.6</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-10867V-14.0</ProductID>
            <ProductID>P-10867V-14.1</ProductID>
            <ProductID>P-10867V-15.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="275" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5476</Title>
      <Notes>
         <Note Audience="All" Ordinal="275" Title="Details" Type="Details">Vulnerability in the Oracle Retail Integration Bus component of Oracle Retail Applications (subcomponent: Install).  Supported versions that are affected are 13.0, 13.1, 13.2, 14.0, 14.1 and 15.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Integration Bus accessible data as well as  unauthorized update, insert or delete access to some of Oracle Retail Integration Bus accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Integration Bus. CVSS 3.0 Base Score   7.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5476</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1807V-13.0</ProductID>
            <ProductID>P-1807V-13.1</ProductID>
            <ProductID>P-1807V-13.2</ProductID>
            <ProductID>P-1807V-14.0</ProductID>
            <ProductID>P-1807V-14.1</ProductID>
            <ProductID>P-1807V-15.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.6</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-1807V-13.0</ProductID>
            <ProductID>P-1807V-13.1</ProductID>
            <ProductID>P-1807V-13.2</ProductID>
            <ProductID>P-1807V-14.0</ProductID>
            <ProductID>P-1807V-14.1</ProductID>
            <ProductID>P-1807V-15.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="276" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5477</Title>
      <Notes>
         <Note Audience="All" Ordinal="276" Title="Details" Type="Details">Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Administration).  Supported versions that are affected are 2.1.1 and  3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GlassFish Server.  While the vulnerability is in Oracle GlassFish Server, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle GlassFish Server accessible data. CVSS 3.0 Base Score   5.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5477</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8493V-2.1.1</ProductID>
            <ProductID>P-8493V-3.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2016.html</URL>
            <ProductID>P-8493V-2.1.1</ProductID>
            <ProductID>P-8493V-3.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
</cvrf:cvrfdoc>
