<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet type="text/xsl" href="2967710.xsl"?>
<?xml-stylesheet type="text/css" href="2967708.css"?>
<cvrf:cvrfdoc xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1">
   <DocumentTitle xml:lang="en">Oracle Critical Patch Update Advisory - July 2012 - BETA ORACLE CVRF</DocumentTitle>
   <DocumentType xml:lang="en">Oracle Critical Patch Update Advisory</DocumentType>
   <DocumentPublisher Type="Vendor"/>
   <DocumentTracking>
      <Identification>
         <ID>CPUJul2012</ID>
      </Identification>
      <Status>Final</Status>
      <Version>1.0</Version>
      <RevisionHistory>
         <Revision>
            <Number>1.0</Number>
            <Date>2012-07-17T13:00:00-07:00</Date>
            <Description>Initial Distribution</Description>
         </Revision>
      </RevisionHistory>
      <InitialReleaseDate>2012-07-17T13:00:00-07:00</InitialReleaseDate>
      <CurrentReleaseDate>2012-07-17T13:00:00-07:00</CurrentReleaseDate>
   </DocumentTracking>
   <DocumentNotes>
      <Note Type="Summary" Ordinal="1" Title="Summary" Audience="All" xml:lang="en">This document contains descriptions of Oracle product security vulnerabilities which have had fixes released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including fix distribution information can be found at the Oracle sites referenced in this document.</Note>
   </DocumentNotes>
   <DocumentDistribution>This document is published at: http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/1695912.xml</DocumentDistribution>
   <DocumentReferences>
      <Reference Type="External">
         <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
         <Description>URL to html version of Advisory</Description>
      </Reference>
   </DocumentReferences>
   <Acknowledgments>
      <Acknowledgment>
         <Name>Alexander Kornbrust</Name>
         <Organization>Red Database Security</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Christian Schneider</Name>
         <Organization>Christian Schneider</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Daniel Bradley</Name>
         <Organization>Postal Options Limited</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Deniz Cevik</Name>
         <Organization>Biznet</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Dennis Yurichev</Name>
         <Organization>Dennis Yurichev</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Enrico Milanese</Name>
         <Organization>Emaze Networks S.p.A</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Esteban Martinez Fayo</Name>
         <Organization>Application Security, Inc.</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Francis Provencher</Name>
         <Organization>Secunia Research</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jens Elkner</Name>
         <Organization>Otto-von-Guericke University</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Joe Moore</Name>
         <Organization>Pentest Limited</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Martin Carpenter</Name>
         <Organization>Citco</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Microsoft Vulnerability Research</Name>
         <Organization>Microsoft Corp</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Mike Gerdts</Name>
         <Organization>Mike Gerdts</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ofer Maor</Name>
         <Organization>Hacktics</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Paul Harrington</Name>
         <Organization>NGS Secure</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Paul Ritchie</Name>
         <Organization>NGS Secure</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Sami Piiroinen</Name>
         <Organization>Louhi Security Oy</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Stephen Kost</Name>
         <Organization>Integrigy</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Steven Seeley</Name>
         <Organization>Corelan Team</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Will Dormann</Name>
         <Organization>CERT/CC</Organization>
      </Acknowledgment>
   </Acknowledgments>
   <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
      <Branch Type="Vendor" Name="Oracle">
         <Branch Type="Product Family" Name="Oracle Application Express Listener">
            <Branch Type="Product Name" Name="Application Express Listener">
               <Branch Type="Product Version" Name="1.1-ea">
                  <FullProductName ProductID="P-9456V-1.1-ea">Application Express Listener Version 1.1-ea</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="1.1.1">
                  <FullProductName ProductID="P-9456V-1.1.1">Application Express Listener Version 1.1.1</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="1.1.2">
                  <FullProductName ProductID="P-9456V-1.1.2">Application Express Listener Version 1.1.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="1.1.3">
                  <FullProductName ProductID="P-9456V-1.1.3">Application Express Listener Version 1.1.3</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle Database Server">
            <Branch Type="Product Name" Name="Oracle Database">
               <Branch Type="Product Version" Name="11.1.0.7">
                  <FullProductName ProductID="P-5V-11.1.0.7">Oracle Database Version 11.1.0.7</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.2.0.2">
                  <FullProductName ProductID="P-5V-11.2.0.2">Oracle Database Version 11.2.0.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.2.0.3">
                  <FullProductName ProductID="P-5V-11.2.0.3">Oracle Database Version 11.2.0.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Advanced Networking Option">
               <Branch Type="Product Version" Name="10.2.0.3">
                  <FullProductName ProductID="P-219V-10.2.0.3">Advanced Networking Option Version 10.2.0.3</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="10.2.0.4">
                  <FullProductName ProductID="P-219V-10.2.0.4">Advanced Networking Option Version 10.2.0.4</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="10.2.0.5">
                  <FullProductName ProductID="P-219V-10.2.0.5">Advanced Networking Option Version 10.2.0.5</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.1.0.7">
                  <FullProductName ProductID="P-219V-11.1.0.7">Advanced Networking Option Version 11.1.0.7</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.2.0.2">
                  <FullProductName ProductID="P-219V-11.2.0.2">Advanced Networking Option Version 11.2.0.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.2.0.3">
                  <FullProductName ProductID="P-219V-11.2.0.3">Advanced Networking Option Version 11.2.0.3</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle E-Business Suite">
            <Branch Type="Product Name" Name="Oracle E-Business Intelligence">
               <Branch Type="Product Version" Name="11.5.10.2">
                  <FullProductName ProductID="P-163V-11.5.10.2">Oracle E-Business Intelligence Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.0.4">
                  <FullProductName ProductID="P-163V-12.0.4">Oracle E-Business Intelligence Version 12.0.4</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.0.6">
                  <FullProductName ProductID="P-163V-12.0.6">Oracle E-Business Intelligence Version 12.0.6</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.1.1">
                  <FullProductName ProductID="P-163V-12.1.1">Oracle E-Business Intelligence Version 12.1.1</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.1.2">
                  <FullProductName ProductID="P-163V-12.1.2">Oracle E-Business Intelligence Version 12.1.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.1.3">
                  <FullProductName ProductID="P-163V-12.1.3">Oracle E-Business Intelligence Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle Application Object Library">
               <Branch Type="Product Version" Name="11.5.10.2">
                  <FullProductName ProductID="P-510V-11.5.10.2">Oracle Application Object Library Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.0.4">
                  <FullProductName ProductID="P-510V-12.0.4">Oracle Application Object Library Version 12.0.4</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.0.6">
                  <FullProductName ProductID="P-510V-12.0.6">Oracle Application Object Library Version 12.0.6</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.1.1">
                  <FullProductName ProductID="P-510V-12.1.1">Oracle Application Object Library Version 12.1.1</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.1.2">
                  <FullProductName ProductID="P-510V-12.1.2">Oracle Application Object Library Version 12.1.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="12.1.3">
                  <FullProductName ProductID="P-510V-12.1.3">Oracle Application Object Library Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle Enterprise Manager Grid Control">
            <Branch Type="Product Name" Name="Enterprise Manager for Oracle Database">
               <Branch Type="Product Version" Name="EM Base Platform 10.2.0.5">
                  <FullProductName ProductID="P-1366V-EM Base Platform 10.2.0.5">Enterprise Manager for Oracle Database Version EM Base Platform 10.2.0.5</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="EM Base Platform 11.1.0.1">
                  <FullProductName ProductID="P-1366V-EM Base Platform 11.1.0.1">Enterprise Manager for Oracle Database Version EM Base Platform 11.1.0.1</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="EM Plugin for DB 12.1.0.1">
                  <FullProductName ProductID="P-1366V-EM Plugin for DB 12.1.0.1">Enterprise Manager for Oracle Database Version EM Plugin for DB 12.1.0.1</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="EM Plugin for DB 12.1.0.2">
                  <FullProductName ProductID="P-1366V-EM Plugin for DB 12.1.0.2">Enterprise Manager for Oracle Database Version EM Plugin for DB 12.1.0.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle Fusion Middleware">
            <Branch Type="Product Name" Name="Portal">
               <Branch Type="Product Version" Name="-">
                  <FullProductName ProductID="P-96V--">Portal Version -</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle HTTP Server">
               <Branch Type="Product Version" Name="10.1.3.5">
                  <FullProductName ProductID="P-1042V-10.1.3.5">Oracle HTTP Server Version 10.1.3.5</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.1.1.5">
                  <FullProductName ProductID="P-1042V-11.1.1.5">Oracle HTTP Server Version 11.1.1.5</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.1.1.6">
                  <FullProductName ProductID="P-1042V-11.1.1.6">Oracle HTTP Server Version 11.1.1.6</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.1.2.0">
                  <FullProductName ProductID="P-1042V-11.1.2.0">Oracle HTTP Server Version 11.1.2.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle 9iAS MapViewer">
               <Branch Type="Product Version" Name="10.1.3.1">
                  <FullProductName ProductID="P-1215V-10.1.3.1">Oracle 9iAS MapViewer Version 10.1.3.1</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.1.1.5">
                  <FullProductName ProductID="P-1215V-11.1.1.5">Oracle 9iAS MapViewer Version 11.1.1.5</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11.1.1.6">
                  <FullProductName ProductID="P-1215V-11.1.1.6">Oracle 9iAS MapViewer Version 11.1.1.6</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Enterprise Manager for iAS">
               <Branch Type="Product Version" Name="10.1.3.5">
                  <FullProductName ProductID="P-1369V-10.1.3.5">Enterprise Manager for iAS Version 10.1.3.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle Outside In Technology">
               <Branch Type="Product Version" Name="8.3.5">
                  <FullProductName ProductID="P-2276V-8.3.5">Oracle Outside In Technology Version 8.3.5</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="8.3.7">
                  <FullProductName ProductID="P-2276V-8.3.7">Oracle Outside In Technology Version 8.3.7</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle JRockit">
               <Branch Type="Product Version" Name="27.7.2 and before: JKD/JRE 5 and 6">
                  <FullProductName ProductID="P-5260V-27.7.2 and before: JKD/JRE 5 and 6">Oracle JRockit Version 27.7.2 and before: JKD/JRE 5 and 6</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="28.2.3 and before: JDK/JRE 5 and 6">
                  <FullProductName ProductID="P-5260V-28.2.3 and before: JDK/JRE 5 and 6">Oracle JRockit Version 28.2.3 and before: JDK/JRE 5 and 6</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle Hyperion">
            <Branch Type="Product Name" Name="Hyperion BI+">
               <Branch Type="Product Version" Name="11.1.1.3 and earlier">
                  <FullProductName ProductID="P-4361V-11.1.1.3 and earlier">Hyperion BI+ Version 11.1.1.3 and earlier</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle Industry Applications">
            <Branch Type="Product Name" Name="Oracle Clinical RDC Option">
               <Branch Type="Product Version" Name="4.6.0.x">
                  <FullProductName ProductID="P-1041V-4.6.0.x">Oracle Clinical RDC Option Version 4.6.0.x</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="4.6.2">
                  <FullProductName ProductID="P-1041V-4.6.2">Oracle Clinical RDC Option Version 4.6.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="4.6.3">
                  <FullProductName ProductID="P-1041V-4.6.3">Oracle Clinical RDC Option Version 4.6.3</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle MySQL">
            <Branch Type="Product Name" Name="MySQL Server">
               <Branch Type="Product Version" Name="5.1.62 and earlier">
                  <FullProductName ProductID="P-8478V-5.1.62 and earlier">MySQL Server Version 5.1.62 and earlier</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="5.5.22 and earlier">
                  <FullProductName ProductID="P-8478V-5.5.22 and earlier">MySQL Server Version 5.5.22 and earlier</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="5.5.23 and earlier">
                  <FullProductName ProductID="P-8478V-5.5.23 and earlier">MySQL Server Version 5.5.23 and earlier</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle PeopleSoft Products">
            <Branch Type="Product Name" Name="PeopleSoft Enterprise HRMS Candidate Gateway">
               <Branch Type="Product Version" Name="9.0.20">
                  <FullProductName ProductID="P-5043V-9.0.20">PeopleSoft Enterprise HRMS Candidate Gateway Version 9.0.20</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="9.1">
                  <FullProductName ProductID="P-5043V-9.1">PeopleSoft Enterprise HRMS Candidate Gateway Version 9.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="PeopleSoft Enterprise HRMS ePerformance">
               <Branch Type="Product Version" Name="9.0.20">
                  <FullProductName ProductID="P-5050V-9.0.20">PeopleSoft Enterprise HRMS ePerformance Version 9.0.20</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="PeopleSoft Enterprise PT PeopleTools">
               <Branch Type="Product Version" Name="8.50">
                  <FullProductName ProductID="P-5085V-8.50">PeopleSoft Enterprise PT PeopleTools Version 8.50</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="8.51">
                  <FullProductName ProductID="P-5085V-8.51">PeopleSoft Enterprise PT PeopleTools Version 8.51</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="8.52">
                  <FullProductName ProductID="P-5085V-8.52">PeopleSoft Enterprise PT PeopleTools Version 8.52</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle Secure Backup">
            <Branch Type="Product Name" Name="Oracle Secure Backup">
               <Branch Type="Product Version" Name="10.3.0.3">
                  <FullProductName ProductID="P-1522V-10.3.0.3">Oracle Secure Backup Version 10.3.0.3</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="10.4.0.1">
                  <FullProductName ProductID="P-1522V-10.4.0.1">Oracle Secure Backup Version 10.4.0.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle Siebel CRM">
            <Branch Type="Product Name" Name="Siebel UI Framework">
               <Branch Type="Product Version" Name="8.1.1">
                  <FullProductName ProductID="P-9011V-8.1.1">Siebel UI Framework Version 8.1.1</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="8.2.2">
                  <FullProductName ProductID="P-9011V-8.2.2">Siebel UI Framework Version 8.2.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle Sun Products Suite">
            <Branch Type="Product Name" Name="Oracle GlassFish Server">
               <Branch Type="Product Version" Name="3.0.1">
                  <FullProductName ProductID="P-8493V-3.0.1">Oracle GlassFish Server Version 3.0.1</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="3.1.1">
                  <FullProductName ProductID="P-8493V-3.1.1">Oracle GlassFish Server Version 3.1.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle iPlanet Web Server">
               <Branch Type="Product Version" Name="Java System Web Server 6.1">
                  <FullProductName ProductID="P-8543V-Java System Web Server 6.1">Oracle iPlanet Web Server Version Java System Web Server 6.1</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="Oracle iPlanet Web Server 7.0">
                  <FullProductName ProductID="P-8543V-Oracle iPlanet Web Server 7.0">Oracle iPlanet Web Server Version Oracle iPlanet Web Server 7.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Solaris Products">
               <Branch Type="Product Version" Name="10">
                  <FullProductName ProductID="P-8752V-10">Solaris Products Version 10</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="11">
                  <FullProductName ProductID="P-8752V-11">Solaris Products Version 11</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="3.3">
                  <FullProductName ProductID="P-8752V-3.3">Solaris Products Version 3.3</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="8">
                  <FullProductName ProductID="P-8752V-8">Solaris Products Version 8</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="9">
                  <FullProductName ProductID="P-8752V-9">Solaris Products Version 9</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="System Firmware 8.1.4.e or earlier">
                  <FullProductName ProductID="P-8752V-System Firmware 8.1.4.e or earlier">Solaris Products Version System Firmware 8.1.4.e or earlier</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="System Firmware 8.2.0">
                  <FullProductName ProductID="P-8752V-System Firmware 8.2.0">Solaris Products Version System Firmware 8.2.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Type="Product Family" Name="Oracle Supply Chain Products Suite">
            <Branch Type="Product Name" Name="Transportation Management">
               <Branch Type="Product Version" Name="5.5.06">
                  <FullProductName ProductID="P-1991V-5.5.06">Transportation Management Version 5.5.06</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="6.0">
                  <FullProductName ProductID="P-1991V-6.0">Transportation Management Version 6.0</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="6.1">
                  <FullProductName ProductID="P-1991V-6.1">Transportation Management Version 6.1</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="6.2">
                  <FullProductName ProductID="P-1991V-6.2">Transportation Management Version 6.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Type="Product Name" Name="Oracle AutoVue Electro-Mechanical Professional">
               <Branch Type="Product Version" Name="20.0.2">
                  <FullProductName ProductID="P-4453V-20.0.2">Oracle AutoVue Electro-Mechanical Professional Version 20.0.2</FullProductName>
               </Branch>
               <Branch Type="Product Version" Name="20.1">
                  <FullProductName ProductID="P-4453V-20.1">Oracle AutoVue Electro-Mechanical Professional Version 20.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
      </Branch>
   </ProductTree>
   <Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2001-0323</Title>
      <Notes>
         <Note Type="Details" Ordinal="1" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: TCP/IP).  Supported versions that are affected are 8, 9 and  10. Easily exploitable vulnerability allows successful unauthenticated network attacks via TCP/IP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Solaris accessible data and ability to cause a partial denial of service (partial DOS) of Solaris.  CVSS Base Score 6.4 (Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2001-0323</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-8</ProductID>
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8752V-8</ProductID>
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2008-4609</Title>
      <Notes>
         <Note Type="Details" Ordinal="2" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: TCP/IP).  Supported versions that are affected are 8, 9 and  10. Difficult to exploit vulnerability allows successful unauthenticated network attacks via TCP.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 7.1 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2008-4609</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-8</ProductID>
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.1</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8752V-8</ProductID>
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="3" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2011-0419</Title>
      <Notes>
         <Note Type="Details" Ordinal="3" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: Library/libc).  Supported versions that are affected are 9 and  10. Difficult to exploit vulnerability allows successful unauthenticated network attacks via TCP/IP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Solaris.  CVSS Base Score 4.3 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2011-0419</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="4" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2011-2699</Title>
      <Notes>
         <Note Type="Details" Ordinal="4" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: TCP/IP).  Supported versions that are affected are 8, 9 and  10. Easily exploitable vulnerability allows successful unauthenticated network attacks via IPv6.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Solaris accessible data.  CVSS Base Score 5.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2011-2699</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-8</ProductID>
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8752V-8</ProductID>
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="5" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2011-3192</Title>
      <Notes>
         <Note Type="Details" Ordinal="5" Title="Details" Audience="All">Vulnerability in the Apache component of Oracle Secure Backup.  Supported versions that are affected are 10.3.0.3 and  10.4.0.1. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 7.8 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2011-3192</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1522V-10.3.0.3</ProductID>
            <ProductID>P-1522V-10.4.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.8</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-1522V-10.3.0.3</ProductID>
            <ProductID>P-1522V-10.4.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="6" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2011-3368</Title>
      <Notes>
         <Note Type="Details" Ordinal="6" Title="Details" Audience="All">Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: Web Listener).  Supported versions that are affected are 10.1.3.5, 11.1.1.5 and  11.1.2.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle HTTP Server accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2011-3368</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1042V-10.1.3.5</ProductID>
            <ProductID>P-1042V-11.1.1.5</ProductID>
            <ProductID>P-1042V-11.1.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-1042V-10.1.3.5</ProductID>
            <ProductID>P-1042V-11.1.1.5</ProductID>
            <ProductID>P-1042V-11.1.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="7" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2011-3562</Title>
      <Notes>
         <Note Type="Details" Ordinal="7" Title="Details" Audience="All">Vulnerability in the Portal component of Oracle Fusion Middleware. For supported versions that are affected see note. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Portal accessible data.   Note: Fixed in all supported releases and patchsets. CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2011-3562</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-96V--</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-96V--</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="8" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2011-4317</Title>
      <Notes>
         <Note Type="Details" Ordinal="8" Title="Details" Audience="All">Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: Web Listener).  Supported versions that are affected are 10.1.3.5, 11.1.1.5, 11.1.1.6 and  11.1.2.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle HTTP Server accessible data.   Note: This also addresses the vulnerabilities of CVE-2011-3607, CVE-2012-0021, CVE-2012-0031 and CVE-2012-0053. CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2011-4317</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1042V-10.1.3.5</ProductID>
            <ProductID>P-1042V-11.1.1.5</ProductID>
            <ProductID>P-1042V-11.1.1.6</ProductID>
            <ProductID>P-1042V-11.1.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-1042V-10.1.3.5</ProductID>
            <ProductID>P-1042V-11.1.1.5</ProductID>
            <ProductID>P-1042V-11.1.1.6</ProductID>
            <ProductID>P-1042V-11.1.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="9" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2011-4358</Title>
      <Notes>
         <Note Type="Details" Ordinal="9" Title="Details" Audience="All">Vulnerability in the GlassFish Enterprise Server component of Oracle Sun Products Suite (subcomponent: JSF).  Supported versions that are affected are 3.0.1 and  3.1.1. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some GlassFish Enterprise Server accessible data as well as  read access to a subset of GlassFish Enterprise Server accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2011-4358</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8493V-3.0.1</ProductID>
            <ProductID>P-8493V-3.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8493V-3.0.1</ProductID>
            <ProductID>P-8493V-3.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="10" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2011-4885</Title>
      <Notes>
         <Note Type="Details" Ordinal="10" Title="Details" Audience="All">Vulnerability in the PHP component of Oracle Secure Backup.  Supported versions that are affected are 10.3.0.3 and  10.4.0.1. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PHP.  CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2011-4885</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1522V-10.3.0.3</ProductID>
            <ProductID>P-1522V-10.4.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-1522V-10.3.0.3</ProductID>
            <ProductID>P-1522V-10.4.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="11" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0540</Title>
      <Notes>
         <Note Type="Details" Ordinal="11" Title="Details" Audience="All">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: GIS Extension).  Supported versions that are affected are 5.1.62 and earlier and  5.5.23 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0540</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.1.62 and earlier</ProductID>
            <ProductID>P-8478V-5.5.23 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8478V-5.1.62 and earlier</ProductID>
            <ProductID>P-8478V-5.5.23 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="12" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0563</Title>
      <Notes>
         <Note Type="Details" Ordinal="12" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: Kerberos/klist).  Supported versions that are affected are 9, 10 and  11. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Solaris.  CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0563</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="13" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1687</Title>
      <Notes>
         <Note Type="Details" Ordinal="13" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: Logical Domains (LDOM)).  Supported versions that are affected are 10 and  11. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS) as well as  update, insert or delete access to some Solaris accessible data.  CVSS Base Score 5.6 (Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:P/A:C).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:P/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1687</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.6</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:P/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="14" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1689</Title>
      <Notes>
         <Note Type="Details" Ordinal="14" Title="Details" Audience="All">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server Optimizer).  Supported versions that are affected are 5.1.62 and earlier and  5.5.22 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1689</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.1.62 and earlier</ProductID>
            <ProductID>P-8478V-5.5.22 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8478V-5.1.62 and earlier</ProductID>
            <ProductID>P-8478V-5.5.22 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="15" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1715</Title>
      <Notes>
         <Note Type="Details" Ordinal="15" Title="Details" Audience="All">Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: HTML Pages).  Supported versions that are affected are 11.5.10.2, 12.0.6 and  12.1.3. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Application Object Library accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1715</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-510V-11.5.10.2</ProductID>
            <ProductID>P-510V-12.0.6</ProductID>
            <ProductID>P-510V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-510V-11.5.10.2</ProductID>
            <ProductID>P-510V-12.0.6</ProductID>
            <ProductID>P-510V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="16" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1727</Title>
      <Notes>
         <Note Type="Details" Ordinal="16" Title="Details" Audience="All">Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Document Repository).  Supported versions that are affected are 11.5.10.2, 12.0.4, 12.0.6, 12.1.1, 12.1.2 and 12.1.3. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Application Object Library accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1727</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-510V-11.5.10.2</ProductID>
            <ProductID>P-510V-12.0.4</ProductID>
            <ProductID>P-510V-12.0.6</ProductID>
            <ProductID>P-510V-12.1.1</ProductID>
            <ProductID>P-510V-12.1.2</ProductID>
            <ProductID>P-510V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-510V-11.5.10.2</ProductID>
            <ProductID>P-510V-12.0.4</ProductID>
            <ProductID>P-510V-12.0.6</ProductID>
            <ProductID>P-510V-12.1.1</ProductID>
            <ProductID>P-510V-12.1.2</ProductID>
            <ProductID>P-510V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="17" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1728</Title>
      <Notes>
         <Note Type="Details" Ordinal="17" Title="Details" Audience="All">Vulnerability in the Siebel CRM component of Oracle Siebel CRM (subcomponent: Portal Framework).  Supported versions that are affected are 8.1.1 and  8.2.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Siebel CRM accessible data as well as  read access to a subset of Siebel CRM accessible data.  CVSS Base Score 5.8 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1728</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="18" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1729</Title>
      <Notes>
         <Note Type="Details" Ordinal="18" Title="Details" Audience="All">Vulnerability in the Hyperion BI+ component of Oracle Hyperion (subcomponent: UI and Visualization).  Supported versions that are affected are 11.1.1.3 and earlier. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Hyperion BI+ accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1729</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4361V-11.1.1.3 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-4361V-11.1.1.3 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="19" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1730</Title>
      <Notes>
         <Note Type="Details" Ordinal="19" Title="Details" Audience="All">Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Password Management).  Supported versions that are affected are 11.5.10.2, 12.0.6 and  12.1.3. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Application Object Library accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1730</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-510V-11.5.10.2</ProductID>
            <ProductID>P-510V-12.0.6</ProductID>
            <ProductID>P-510V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-510V-11.5.10.2</ProductID>
            <ProductID>P-510V-12.0.6</ProductID>
            <ProductID>P-510V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="20" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1731</Title>
      <Notes>
         <Note Type="Details" Ordinal="20" Title="Details" Audience="All">Vulnerability in the Siebel CRM component of Oracle Siebel CRM (subcomponent: Web UI).  Supported versions that are affected are 8.1.1 and  8.2.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Siebel CRM accessible data as well as  read access to a subset of Siebel CRM accessible data and ability to cause a partial denial of service (partial DOS) of Siebel CRM.  CVSS Base Score 6.8 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1731</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="21" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1732</Title>
      <Notes>
         <Note Type="Details" Ordinal="21" Title="Details" Audience="All">Vulnerability in the Siebel CRM  component of Oracle Siebel CRM (subcomponent: UI Framework).  Supported versions that are affected are 8.1.1 and  8.2.2. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Siebel CRM  accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1732</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="22" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1733</Title>
      <Notes>
         <Note Type="Details" Ordinal="22" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: CM).  Supported versions that are affected are 8.50, 8.51 and  8.52. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 3.5 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1733</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="23" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1734</Title>
      <Notes>
         <Note Type="Details" Ordinal="23" Title="Details" Audience="All">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server Optimizer).  Supported versions that are affected are 5.1.62 and earlier and  5.5.23 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1734</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.1.62 and earlier</ProductID>
            <ProductID>P-8478V-5.5.23 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8478V-5.1.62 and earlier</ProductID>
            <ProductID>P-8478V-5.5.23 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="24" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1735</Title>
      <Notes>
         <Note Type="Details" Ordinal="24" Title="Details" Audience="All">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server Optimizer).  Supported versions that are affected are 5.5.23 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 6.8 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:C).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1735</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.23 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.8</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8478V-5.5.23 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="25" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1736</Title>
      <Notes>
         <Note Type="Details" Ordinal="25" Title="Details" Audience="All">Vulnerability in the Oracle MapViewer component of Oracle Fusion Middleware (subcomponent: Oracle Maps).   The supported version that is affected is 10.1.3.1. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to all Oracle MapViewer accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1736</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1215V-10.1.3.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-1215V-10.1.3.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="26" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1737</Title>
      <Notes>
         <Note Type="Details" Ordinal="26" Title="Details" Audience="All">Vulnerability in the Enterprise Manager for Oracle Database component of Oracle Enterprise Manager Grid Control (subcomponent: DB Performance Advisories/UIs).  Supported versions that are affected are EM Base Platform 10.2.0.5, EM Base Platform 11.1.0.1, EM Plugin for DB 12.1.0.1 and  EM Plugin for DB 12.1.0.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Enterprise Manager for Oracle Database accessible data as well as  read access to a subset of Enterprise Manager for Oracle Database accessible data and ability to cause a partial denial of service (partial DOS) of Enterprise Manager for Oracle Database.  CVSS Base Score 6.8 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1737</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1366V-EM Base Platform 10.2.0.5</ProductID>
            <ProductID>P-1366V-EM Base Platform 11.1.0.1</ProductID>
            <ProductID>P-1366V-EM Plugin for DB 12.1.0.1</ProductID>
            <ProductID>P-1366V-EM Plugin for DB 12.1.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-1366V-EM Base Platform 10.2.0.5</ProductID>
            <ProductID>P-1366V-EM Base Platform 11.1.0.1</ProductID>
            <ProductID>P-1366V-EM Plugin for DB 12.1.0.1</ProductID>
            <ProductID>P-1366V-EM Plugin for DB 12.1.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="27" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1738</Title>
      <Notes>
         <Note Type="Details" Ordinal="27" Title="Details" Audience="All">Vulnerability in the Oracle iPlanet Web Server component of Oracle Sun Products Suite (subcomponent: Web Server).  Supported versions that are affected are Java System Web Server 6.1 and  Oracle iPlanet Web Server 7.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle iPlanet Web Server.  CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1738</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8543V-Java System Web Server 6.1</ProductID>
            <ProductID>P-8543V-Oracle iPlanet Web Server 7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8543V-Java System Web Server 6.1</ProductID>
            <ProductID>P-8543V-Oracle iPlanet Web Server 7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="28" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1739</Title>
      <Notes>
         <Note Type="Details" Ordinal="28" Title="Details" Audience="All">Vulnerability in the Oracle E-Business Intelligence component of Oracle E-Business Suite (subcomponent: Financials Business Intelligence).  Supported versions that are affected are 11.5.10.2, 12.0.4, 12.0.6, 12.1.1, 12.1.2 and 12.1.3. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle E-Business Intelligence accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1739</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-163V-11.5.10.2</ProductID>
            <ProductID>P-163V-12.0.4</ProductID>
            <ProductID>P-163V-12.0.6</ProductID>
            <ProductID>P-163V-12.1.1</ProductID>
            <ProductID>P-163V-12.1.2</ProductID>
            <ProductID>P-163V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-163V-11.5.10.2</ProductID>
            <ProductID>P-163V-12.0.4</ProductID>
            <ProductID>P-163V-12.0.6</ProductID>
            <ProductID>P-163V-12.1.1</ProductID>
            <ProductID>P-163V-12.1.2</ProductID>
            <ProductID>P-163V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="29" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1740</Title>
      <Notes>
         <Note Type="Details" Ordinal="29" Title="Details" Audience="All">Vulnerability in the Oracle Application Express Listener component of Oracle Application Express Listener.  Supported versions that are affected are 1.1-ea, 1.1.1, 1.1.2 and  1.1.3. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to any arbitrary Operating System location.   Note: The CVSS Base Score is 7.8 only for Windows. For Linux, Unix and other platforms, the CVSS Base Score is 5.0, and the impact for Confidentiality is Partial+.  Application Express Listener is an Oracle product that is independent of Application Express, is not part of the Application Express distribution and can only be obtained via OTN downloads.   It is used as an alternative method of providing TLS protected communication between Application Express and clients. Only those customers that have chosen to download and install this separate application need to apply this patch. CVSS Base Score 7.8 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1740</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9456V-1.1-ea</ProductID>
            <ProductID>P-9456V-1.1.1</ProductID>
            <ProductID>P-9456V-1.1.2</ProductID>
            <ProductID>P-9456V-1.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.8</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-9456V-1.1-ea</ProductID>
            <ProductID>P-9456V-1.1.1</ProductID>
            <ProductID>P-9456V-1.1.2</ProductID>
            <ProductID>P-9456V-1.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="30" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1741</Title>
      <Notes>
         <Note Type="Details" Ordinal="30" Title="Details" Audience="All">Vulnerability in the Enterprise Manager for Fusion Middleware component of Oracle Fusion Middleware (subcomponent: User Administration Pages).   The supported version that is affected is 10.1.3.5. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Enterprise Manager for Fusion Middleware accessible data as well as  read access to a subset of Enterprise Manager for Fusion Middleware accessible data.  CVSS Base Score 5.8 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1741</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1369V-10.1.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-1369V-10.1.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="31" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1742</Title>
      <Notes>
         <Note Type="Details" Ordinal="31" Title="Details" Audience="All">Vulnerability in the Siebel CRM component of Oracle Siebel CRM (subcomponent: UI Framework).  Supported versions that are affected are 8.1.1 and  8.2.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM.  CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1742</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="32" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1743</Title>
      <Notes>
         <Note Type="Details" Ordinal="32" Title="Details" Audience="All">Vulnerability in the Oracle Clinical Remote Data Capture Option component of Oracle Industry Applications (subcomponent: HTML Surround).  Supported versions that are affected are 4.6.0.x, 4.6.2 and  4.6.3. Difficult to exploit vulnerability allows successful network attacks via HTTP, requiring multiple authentications.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Clinical Remote Data Capture Option accessible data.  CVSS Base Score 2.8 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:M/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:M/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1743</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1041V-4.6.0.x</ProductID>
            <ProductID>P-1041V-4.6.2</ProductID>
            <ProductID>P-1041V-4.6.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.8</BaseScore>
            <Vector>AV:N/AC:M/Au:M/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-1041V-4.6.0.x</ProductID>
            <ProductID>P-1041V-4.6.2</ProductID>
            <ProductID>P-1041V-4.6.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="33" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1744</Title>
      <Notes>
         <Note Type="Details" Ordinal="33" Title="Details" Audience="All">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.3.5 and  8.3.7. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology.   Note: Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. If the hosting software passes data received over the network to Outside In Technology code, the CVSS score would increase to 6.8. CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1744</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="34" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1745</Title>
      <Notes>
         <Note Type="Details" Ordinal="34" Title="Details" Audience="All">Vulnerability in the Network Layer component of Oracle Database Server.  Supported versions that are affected are 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2 and  11.2.0.3. Easily exploitable vulnerability allows successful unauthenticated network attacks via Oracle NET.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Network Layer.  CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1745</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-219V-10.2.0.3</ProductID>
            <ProductID>P-219V-10.2.0.4</ProductID>
            <ProductID>P-219V-10.2.0.5</ProductID>
            <ProductID>P-219V-11.1.0.7</ProductID>
            <ProductID>P-219V-11.2.0.2</ProductID>
            <ProductID>P-219V-11.2.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-219V-10.2.0.3</ProductID>
            <ProductID>P-219V-10.2.0.4</ProductID>
            <ProductID>P-219V-10.2.0.5</ProductID>
            <ProductID>P-219V-11.1.0.7</ProductID>
            <ProductID>P-219V-11.2.0.2</ProductID>
            <ProductID>P-219V-11.2.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="35" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1746</Title>
      <Notes>
         <Note Type="Details" Ordinal="35" Title="Details" Audience="All">Vulnerability in the Network Layer component of Oracle Database Server.  Supported versions that are affected are 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2 and  11.2.0.3. Easily exploitable vulnerability allows successful unauthenticated network attacks via Oracle NET.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Network Layer.   Note: The vulnerability affects Microsoft Windows platforms only. CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1746</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-219V-10.2.0.3</ProductID>
            <ProductID>P-219V-10.2.0.4</ProductID>
            <ProductID>P-219V-10.2.0.5</ProductID>
            <ProductID>P-219V-11.1.0.7</ProductID>
            <ProductID>P-219V-11.2.0.2</ProductID>
            <ProductID>P-219V-11.2.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-219V-10.2.0.3</ProductID>
            <ProductID>P-219V-10.2.0.4</ProductID>
            <ProductID>P-219V-10.2.0.5</ProductID>
            <ProductID>P-219V-11.1.0.7</ProductID>
            <ProductID>P-219V-11.2.0.2</ProductID>
            <ProductID>P-219V-11.2.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="36" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1747</Title>
      <Notes>
         <Note Type="Details" Ordinal="36" Title="Details" Audience="All">Vulnerability in the Network Layer component of Oracle Database Server.  Supported versions that are affected are 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2 and  11.2.0.3. Easily exploitable vulnerability allows successful unauthenticated network attacks via Oracle NET.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Network Layer.   Note: The vulnerability affects Microsoft Windows platforms only. CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1747</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-219V-10.2.0.3</ProductID>
            <ProductID>P-219V-10.2.0.4</ProductID>
            <ProductID>P-219V-10.2.0.5</ProductID>
            <ProductID>P-219V-11.1.0.7</ProductID>
            <ProductID>P-219V-11.2.0.2</ProductID>
            <ProductID>P-219V-11.2.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-219V-10.2.0.3</ProductID>
            <ProductID>P-219V-10.2.0.4</ProductID>
            <ProductID>P-219V-10.2.0.5</ProductID>
            <ProductID>P-219V-11.1.0.7</ProductID>
            <ProductID>P-219V-11.2.0.2</ProductID>
            <ProductID>P-219V-11.2.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="37" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1748</Title>
      <Notes>
         <Note Type="Details" Ordinal="37" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise HRMS component of Oracle PeopleSoft Products (subcomponent: Candidate Gateway).   The supported version that is affected is 9.1. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of PeopleSoft Enterprise HRMS accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1748</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5043V-9.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-5043V-9.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="38" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1749</Title>
      <Notes>
         <Note Type="Details" Ordinal="38" Title="Details" Audience="All">Vulnerability in the Oracle MapViewer component of Oracle Fusion Middleware (subcomponent: Oracle Maps).  Supported versions that are affected are 10.1.3.1 and  11.1.1.5. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to all Oracle MapViewer accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1749</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1215V-10.1.3.1</ProductID>
            <ProductID>P-1215V-11.1.1.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-1215V-10.1.3.1</ProductID>
            <ProductID>P-1215V-11.1.1.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="39" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1750</Title>
      <Notes>
         <Note Type="Details" Ordinal="39" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: mailx(1)).  Supported versions that are affected are 8, 9, 10 and  11. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Solaris accessible data as well as  read access to a subset of Solaris accessible data and ability to cause a partial denial of service (partial DOS) of Solaris.  CVSS Base Score 4.4 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:L/AC:M/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1750</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-8</ProductID>
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.4</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8752V-8</ProductID>
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="40" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1752</Title>
      <Notes>
         <Note Type="Details" Ordinal="40" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: Kernel/NFS).   The supported version that is affected is 11. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 4.9 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1752</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.9</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8752V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="41" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1753</Title>
      <Notes>
         <Note Type="Details" Ordinal="41" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: PC).  Supported versions that are affected are 8.50, 8.51 and  8.52. Difficult to exploit vulnerability allows successful network attacks via HTTP, requiring multiple authentications.  Successful attack of this vulnerability can result in unauthorized  read access to all PeopleSoft Enterprise PeopleTools accessible data as well as  update, insert or delete access to some PeopleSoft Enterprise PeopleTools accessible data and ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools.  CVSS Base Score 5.4 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:M/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:M/Au:M/C:P+/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1753</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.4</BaseScore>
            <Vector>AV:N/AC:M/Au:M/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="42" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1754</Title>
      <Notes>
         <Note Type="Details" Ordinal="42" Title="Details" Audience="All">Vulnerability in the Siebel CRM component of Oracle Siebel CRM (subcomponent: UI Framework).  Supported versions that are affected are 8.1.1 and  8.2.2. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Siebel CRM accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1754</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="43" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1756</Title>
      <Notes>
         <Note Type="Details" Ordinal="43" Title="Details" Audience="All">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server).  Supported versions that are affected are 5.5.23 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1756</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.23 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8478V-5.5.23 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="44" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1757</Title>
      <Notes>
         <Note Type="Details" Ordinal="44" Title="Details" Audience="All">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB).  Supported versions that are affected are 5.5.23 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1757</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.23 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8478V-5.5.23 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="45" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1758</Title>
      <Notes>
         <Note Type="Details" Ordinal="45" Title="Details" Audience="All">Vulnerability in the Oracle AutoVue component of Oracle Supply Chain Products Suite.  Supported versions that are affected are 20.0.2 and  20.1. Easily exploitable vulnerability allows successful authenticated network attacks via File.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle AutoVue.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1758</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4453V-20.0.2</ProductID>
            <ProductID>P-4453V-20.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-4453V-20.0.2</ProductID>
            <ProductID>P-4453V-20.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="46" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1759</Title>
      <Notes>
         <Note Type="Details" Ordinal="46" Title="Details" Audience="All">Vulnerability in the Oracle AutoVue  component of Oracle Supply Chain Products Suite.  Supported versions that are affected are 20.0.2 and  20.1. Easily exploitable vulnerability allows successful authenticated network attacks via File.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle AutoVue .  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1759</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4453V-20.0.2</ProductID>
            <ProductID>P-4453V-20.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-4453V-20.0.2</ProductID>
            <ProductID>P-4453V-20.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="47" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1760</Title>
      <Notes>
         <Note Type="Details" Ordinal="47" Title="Details" Audience="All">Vulnerability in the Siebel CRM component of Oracle Siebel CRM (subcomponent: UI Framework).  Supported versions that are affected are 8.1.1 and  8.2.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM.  CVSS Base Score 4.3 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1760</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="48" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1761</Title>
      <Notes>
         <Note Type="Details" Ordinal="48" Title="Details" Audience="All">Vulnerability in the Siebel CRM component of Oracle Siebel CRM (subcomponent: UI Framework).  Supported versions that are affected are 8.1.1 and  8.2.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Siebel CRM accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1761</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="49" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1762</Title>
      <Notes>
         <Note Type="Details" Ordinal="49" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: TECH).  Supported versions that are affected are 8.50, 8.51 and  8.52. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1762</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="50" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1764</Title>
      <Notes>
         <Note Type="Details" Ordinal="50" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: MCF).  Supported versions that are affected are 8.50, 8.51 and  8.52. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1764</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="51" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1765</Title>
      <Notes>
         <Note Type="Details" Ordinal="51" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: Branded Zone).   The supported version that is affected is 10. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  write access to any arbitrary Operating System location.  CVSS Base Score 4.7 (Integrity impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:N/I:C/A:N).  Oracle Vector: (AV:L/AC:M/Au:N/C:N/I:C/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1765</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.7</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:N/I:C/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8752V-10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="52" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1766</Title>
      <Notes>
         <Note Type="Details" Ordinal="52" Title="Details" Audience="All">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.3.5 and  8.3.7. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology.   Note: Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. If the hosting software passes data received over the network to Outside In Technology code, the CVSS score would increase to 6.8. CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1766</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="53" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1767</Title>
      <Notes>
         <Note Type="Details" Ordinal="53" Title="Details" Audience="All">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.3.5 and  8.3.7. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology.   Note: Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. If the hosting software passes data received over the network to Outside In Technology code, the CVSS score would increase to 6.8. CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1767</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="54" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1768</Title>
      <Notes>
         <Note Type="Details" Ordinal="54" Title="Details" Audience="All">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).   The supported version that is affected is 8.3.7. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology.   Note: Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. If the hosting software passes data received over the network to Outside In Technology code, the CVSS score would increase to 6.8. CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1768</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.3.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="55" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1769</Title>
      <Notes>
         <Note Type="Details" Ordinal="55" Title="Details" Audience="All">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.3.5 and  8.3.7. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology.   Note: Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. If the hosting software passes data received over the network to Outside In Technology code, the CVSS score would increase to 6.8. CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1769</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="56" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1770</Title>
      <Notes>
         <Note Type="Details" Ordinal="56" Title="Details" Audience="All">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.3.5 and  8.3.7. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology.   Note: Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. If the hosting software passes data received over the network to Outside In Technology code, the CVSS score would increase to 6.8. CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1770</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="57" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1771</Title>
      <Notes>
         <Note Type="Details" Ordinal="57" Title="Details" Audience="All">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.3.5 and  8.3.7. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology.   Note: Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. If the hosting software passes data received over the network to Outside In Technology code, the CVSS score would increase to 6.8. CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1771</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="58" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1772</Title>
      <Notes>
         <Note Type="Details" Ordinal="58" Title="Details" Audience="All">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.3.5 and  8.3.7. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology.   Note: Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. If the hosting software passes data received over the network to Outside In Technology code, the CVSS score would increase to 6.8. CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1772</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="59" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-1773</Title>
      <Notes>
         <Note Type="Details" Ordinal="59" Title="Details" Audience="All">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.3.5 and  8.3.7. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology.   Note: Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. If the hosting software passes data received over the network to Outside In Technology code, the CVSS score would increase to 6.8. CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-1773</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="60" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3106</Title>
      <Notes>
         <Note Type="Details" Ordinal="60" Title="Details" Audience="All">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.3.5 and  8.3.7. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology.   Note: Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. If the hosting software passes data received over the network to Outside In Technology code, the CVSS score would increase to 6.8. CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3106</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="61" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3107</Title>
      <Notes>
         <Note Type="Details" Ordinal="61" Title="Details" Audience="All">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.3.5 and  8.3.7. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology.   Note: Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. If the hosting software passes data received over the network to Outside In Technology code, the CVSS score would increase to 6.8. CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3107</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="62" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3108</Title>
      <Notes>
         <Note Type="Details" Ordinal="62" Title="Details" Audience="All">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.3.5 and  8.3.7. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology.   Note: Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. If the hosting software passes data received over the network to Outside In Technology code, the CVSS score would increase to 6.8. CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3108</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="63" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3109</Title>
      <Notes>
         <Note Type="Details" Ordinal="63" Title="Details" Audience="All">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).   The supported version that is affected is 8.3.7. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology.   Note: Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. If the hosting software passes data received over the network to Outside In Technology code, the CVSS score would increase to 6.8. CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3109</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.3.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="64" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3110</Title>
      <Notes>
         <Note Type="Details" Ordinal="64" Title="Details" Audience="All">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.3.5 and  8.3.7. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology.   Note: Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. If the hosting software passes data received over the network to Outside In Technology code, the CVSS score would increase to 6.8. CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3110</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-2276V-8.3.5</ProductID>
            <ProductID>P-2276V-8.3.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="65" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3111</Title>
      <Notes>
         <Note Type="Details" Ordinal="65" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: TECH).  Supported versions that are affected are 8.50, 8.51 and  8.52. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3111</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-5085V-8.50</ProductID>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="66" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3112</Title>
      <Notes>
         <Note Type="Details" Ordinal="66" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: Solaris Management Console).   The supported version that is affected is 10. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Solaris accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3112</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8752V-10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="67" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3113</Title>
      <Notes>
         <Note Type="Details" Ordinal="67" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise HRMS component of Oracle PeopleSoft Products (subcomponent: EPERF).   The supported version that is affected is 9.0.20. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some PeopleSoft Enterprise HRMS accessible data as well as  read access to a subset of PeopleSoft Enterprise HRMS accessible data.  CVSS Base Score 5.5 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3113</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5050V-9.0.20</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-5050V-9.0.20</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="68" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3114</Title>
      <Notes>
         <Note Type="Details" Ordinal="68" Title="Details" Audience="All">Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suite.  Supported versions that are affected are 5.5.06, 6.0, 6.1 and  6.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Transportation Management accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3114</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1991V-5.5.06</ProductID>
            <ProductID>P-1991V-6.0</ProductID>
            <ProductID>P-1991V-6.1</ProductID>
            <ProductID>P-1991V-6.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-1991V-5.5.06</ProductID>
            <ProductID>P-1991V-6.0</ProductID>
            <ProductID>P-1991V-6.1</ProductID>
            <ProductID>P-1991V-6.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="69" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3115</Title>
      <Notes>
         <Note Type="Details" Ordinal="69" Title="Details" Audience="All">Vulnerability in the Oracle MapViewer component of Oracle Fusion Middleware (subcomponent: Install).  Supported versions that are affected are 10.1.3.1, 11.1.1.5 and  11.1.1.6. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle MapViewer accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3115</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1215V-10.1.3.1</ProductID>
            <ProductID>P-1215V-11.1.1.5</ProductID>
            <ProductID>P-1215V-11.1.1.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-1215V-10.1.3.1</ProductID>
            <ProductID>P-1215V-11.1.1.5</ProductID>
            <ProductID>P-1215V-11.1.1.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="70" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3116</Title>
      <Notes>
         <Note Type="Details" Ordinal="70" Title="Details" Audience="All">Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suite.  Supported versions that are affected are 5.5.06, 6.0, 6.1 and  6.2. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Transportation Management accessible data.  CVSS Base Score 1.9 (Confidentiality impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:L/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3116</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1991V-5.5.06</ProductID>
            <ProductID>P-1991V-6.0</ProductID>
            <ProductID>P-1991V-6.1</ProductID>
            <ProductID>P-1991V-6.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>1.9</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-1991V-5.5.06</ProductID>
            <ProductID>P-1991V-6.0</ProductID>
            <ProductID>P-1991V-6.1</ProductID>
            <ProductID>P-1991V-6.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="71" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3117</Title>
      <Notes>
         <Note Type="Details" Ordinal="71" Title="Details" Audience="All">Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suite.  Supported versions that are affected are 5.5.06, 6.0, 6.1 and  6.2. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Transportation Management accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3117</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1991V-5.5.06</ProductID>
            <ProductID>P-1991V-6.0</ProductID>
            <ProductID>P-1991V-6.1</ProductID>
            <ProductID>P-1991V-6.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-1991V-5.5.06</ProductID>
            <ProductID>P-1991V-6.0</ProductID>
            <ProductID>P-1991V-6.1</ProductID>
            <ProductID>P-1991V-6.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="72" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3118</Title>
      <Notes>
         <Note Type="Details" Ordinal="72" Title="Details" Audience="All">Vulnerability in the PeoleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: PANPROC).   The supported version that is affected is 8.52. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of PeoleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3118</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.52</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-5085V-8.52</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="73" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3119</Title>
      <Notes>
         <Note Type="Details" Ordinal="73" Title="Details" Audience="All">Vulnerability in the PeopleSoft Enterprise HRMS component of Oracle PeopleSoft Products (subcomponent: Candidate Gateway).   The supported version that is affected is 9.0.20. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP .  Successful attack of this vulnerability can result in unauthorized  read access to a subset of PeopleSoft Enterprise HRMS accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3119</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5043V-9.0.20</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-5043V-9.0.20</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="74" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3120</Title>
      <Notes>
         <Note Type="Details" Ordinal="74" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: TCP/IP).   The supported version that is affected is 8. Easily exploitable vulnerability allows successful unauthenticated network attacks via TCP.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 7.8 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3120</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-8</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.8</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8752V-8</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="75" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3121</Title>
      <Notes>
         <Note Type="Details" Ordinal="75" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: in.tnamed(1M)).  Supported versions that are affected are 9 and  10. Easily exploitable vulnerability allows successful unauthenticated network attacks via NameServer.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Solaris.  CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3121</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="76" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3122</Title>
      <Notes>
         <Note Type="Details" Ordinal="76" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: sort(1)).  Supported versions that are affected are 8 and  9. Very difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Solaris accessible data as well as  read access to a subset of Solaris accessible data.  CVSS Base Score 2.6 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:L/AC:H/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:L/AC:H/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3122</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-8</ProductID>
            <ProductID>P-8752V-9</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.6</BaseScore>
            <Vector>AV:L/AC:H/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8752V-8</ProductID>
            <ProductID>P-8752V-9</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="77" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3123</Title>
      <Notes>
         <Note Type="Details" Ordinal="77" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: Apache HTTP Server).   The supported version that is affected is 10. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Solaris accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3123</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8752V-10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="78" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3124</Title>
      <Notes>
         <Note Type="Details" Ordinal="78" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: Kernel/KSSL).   The supported version that is affected is 10. Easily exploitable vulnerability allows successful unauthenticated network attacks via SSL.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Solaris.  CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3124</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8752V-10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="79" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3125</Title>
      <Notes>
         <Note Type="Details" Ordinal="79" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: TCP/IP).  Supported versions that are affected are 8, 9 and  10. Difficult to exploit vulnerability allows successful unauthenticated network attacks via TCP.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 7.1 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3125</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-8</ProductID>
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.1</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8752V-8</ProductID>
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="80" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3126</Title>
      <Notes>
         <Note Type="Details" Ordinal="80" Title="Details" Audience="All">Vulnerability in the Solaris Cluster component of Oracle Sun Products Suite (subcomponent: Apache Tomcat Agent).   The supported version that is affected is 3.3. Very difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.  CVSS Base Score 6.2 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:H/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:L/AC:H/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3126</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-3.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.2</BaseScore>
            <Vector>AV:L/AC:H/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8752V-3.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="81" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3127</Title>
      <Notes>
         <Note Type="Details" Ordinal="81" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: SCTP(7P)).   The supported version that is affected is 10. Very difficult to exploit vulnerability allows successful unauthenticated network attacks via SCTP.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 5.4 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:N/AC:H/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3127</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.4</BaseScore>
            <Vector>AV:N/AC:H/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8752V-10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="82" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3128</Title>
      <Notes>
         <Note Type="Details" Ordinal="82" Title="Details" Audience="All">Vulnerability in the SPARC T-Series Servers component of Oracle Sun Products Suite (subcomponent: Integrated Lights Out Manager).  Supported versions that are affected are System Firmware 8.1.4.e or earlier and  System Firmware 8.2.0. Very difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some SPARC T-Series Servers accessible data as well as  read access to a subset of SPARC T-Series Servers accessible data and ability to cause a partial denial of service (partial DOS) of SPARC T-Series Servers.   Note: CVE-2012-3128: Specific server products affected are: SPARC T4-1, SPARC T4-1B, SPARC T4-2, SPARC T4-4, Netra SPARC T4-1, Netra SPARC T4-1B, Netra SPARC T4-2, SPARC T3-1, SPARC T3-1B, SPARC T3-2, SPARC T3-4, Netra SPARC T3-1, Netra SPARC T3-1B. CVSS Base Score 3.7 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:H/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:L/AC:H/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3128</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-System Firmware 8.1.4.e or earlier</ProductID>
            <ProductID>P-8752V-System Firmware 8.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.7</BaseScore>
            <Vector>AV:L/AC:H/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8752V-System Firmware 8.1.4.e or earlier</ProductID>
            <ProductID>P-8752V-System Firmware 8.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="83" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3129</Title>
      <Notes>
         <Note Type="Details" Ordinal="83" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: Gnome PDF viewer).   The supported version that is affected is 10. Very difficult to exploit vulnerability allows successful unauthenticated network attacks via None.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Solaris accessible data as well as  read access to a subset of Solaris accessible data and ability to cause a partial denial of service (partial DOS) of Solaris.  CVSS Base Score 5.1 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:H/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3129</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.1</BaseScore>
            <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8752V-10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="84" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3130</Title>
      <Notes>
         <Note Type="Details" Ordinal="84" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: pkg.depotd(1M)).   The supported version that is affected is 11. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Solaris accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3130</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8752V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="85" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3131</Title>
      <Notes>
         <Note Type="Details" Ordinal="85" Title="Details" Audience="All">Vulnerability in the Solaris component of Oracle Sun Products Suite (subcomponent: Network/NFS).  Supported versions that are affected are 9, 10 and  11. Difficult to exploit vulnerability allows successful unauthenticated network attacks via NFS.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Solaris accessible data.  CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3131</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-8752V-9</ProductID>
            <ProductID>P-8752V-10</ProductID>
            <ProductID>P-8752V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="86" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3134</Title>
      <Notes>
         <Note Type="Details" Ordinal="86" Title="Details" Audience="All">Vulnerability in the Core RDBMS component of Oracle Database Server.  This vulnerability requires Create session privileges for a successful attack.  Supported versions that are affected are 11.1.0.7, 11.2.0.2 and  11.2.0.3. Easily exploitable vulnerability allows successful authenticated network attacks via Oracle NET.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Core RDBMS.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3134</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-11.1.0.7</ProductID>
            <ProductID>P-5V-11.2.0.2</ProductID>
            <ProductID>P-5V-11.2.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-5V-11.1.0.7</ProductID>
            <ProductID>P-5V-11.2.0.2</ProductID>
            <ProductID>P-5V-11.2.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="87" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-3135</Title>
      <Notes>
         <Note Type="Details" Ordinal="87" Title="Details" Audience="All">Vulnerability in the Oracle JRockit component of Oracle Fusion Middleware.  Supported versions that are affected are 28.2.3 and before: JDK/JRE 5 and 6 and  27.7.2 and before: JKD/JRE 5 and 6. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Oracle released a Java SE Critical Patch Update in June 2012 to address multiple vulnerabilities affecting the Java Runtime Environment. Oracle CVE-2012-3135 refers to the advisories that were applicable to JRockit from the Java SE Critical Patch Update. The CVSS score of this vulnerability CVE# reflects the highest among those fixed in JRockit. The complete list of all vulnerabilities addressed in JRockit under CVE-2012-3135 is as follows: CVE-2012-1713, CVE-2012-1724, CVE-2012-1718, CVE-2012-1717, and CVE-2012-1720. CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-3135</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5260V-28.2.3 and before: JDK/JRE 5 and 6</ProductID>
            <ProductID>P-5260V-27.7.2 and before: JKD/JRE 5 and 6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJul2012</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujul2012.html</URL>
            <ProductID>P-5260V-28.2.3 and before: JDK/JRE 5 and 6</ProductID>
            <ProductID>P-5260V-27.7.2 and before: JKD/JRE 5 and 6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
</cvrf:cvrfdoc>
