<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet type="text/xsl" href="2967710.xsl"?>
<?xml-stylesheet type="text/css" href="2967708.css"?>
<cvrf:cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
   <DocumentTitle xml:lang="en">Oracle Critical Patch Update Advisory - January 2016 - Beta Oracle CVRF</DocumentTitle>
   <DocumentType xml:lang="en">Oracle Critical Patch Update Advisory</DocumentType>
   <DocumentPublisher Type="Vendor"/>
   <DocumentTracking>
      <Identification>
         <ID>CPUJan2016</ID>
      </Identification>
      <Status>Final</Status>
      <Version>1.0</Version>
      <RevisionHistory>
         <Revision>
            <Number>1.0</Number>
            <Date>2016-01-19T13:00:00-07:00</Date>
            <Description>Initial Distribution</Description>
         </Revision>
      </RevisionHistory>
      <InitialReleaseDate>2016-01-19T13:00:00-07:00</InitialReleaseDate>
      <CurrentReleaseDate>2016-01-19T13:00:00-07:00</CurrentReleaseDate>
   </DocumentTracking>
   <DocumentNotes>
      <Note Audience="All" Ordinal="1" Title="Summary" Type="Summary" xml:lang="en">This document contains descriptions of Oracle product security vulnerabilities which have had fixes released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including fix distribution information can be found at the Oracle sites referenced in this document.</Note>
   </DocumentNotes>
   <DocumentDistribution>This document is published at: http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/2368796.xml</DocumentDistribution>
   <DocumentReferences>
      <Reference Type="External">
         <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
         <Description>URL to html version of Advisory</Description>
      </Reference>
   </DocumentReferences>
   <Acknowledgments>
      <Acknowledgment>
         <Name>Adam Willard</Name>
         <Organization>Raytheon Foreground Security</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ahmed Adel Abdelfattah</Name>
         <Organization>Ahmed Adel Abdelfattah</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Alexey Tyurin</Name>
         <Organization>ERPScan</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Andrea Micalizzi</Name>
         <Organization>HP's Zero Day Initiative</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ayoub Ait Elmokhtar</Name>
         <Organization>Ayoub Ait Elmokhtar</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ben Khlifa Fahmi</Name>
         <Organization>Ben Khlifa Fahmi</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Brandon Vincent</Name>
         <Organization>Brandon Vincent</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Calum Hutton</Name>
         <Organization>Calum Hutton</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Cyber Warrior Bug Researchers</Name>
         <Organization>Cyber Warrior Bug Researchers</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Cybersecurity-upv</Name>
         <Organization>Cybersecurity-upv</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Danyal Zafar</Name>
         <Organization>Danyal Zafar</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>David Litchfield</Name>
         <Organization>Google</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Dmitry Janushkevich</Name>
         <Organization>Secunia Research</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Fernando Russ</Name>
         <Organization>Onapsis</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>FortiGuard Labs</Name>
         <Organization>Fortinet, Inc.</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Francois Goichon</Name>
         <Organization>Context Information Security</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Hamza Zulfiqar Bhatti</Name>
         <Organization>Hamza Zulfiqar Bhatti</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Igor Kopylenko</Name>
         <Organization>McAfee Security Research</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ivan Chalykin</Name>
         <Organization>ERPScan</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jakub Palaczynski</Name>
         <Organization>ING Services Polska</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>John Page</Name>
         <Organization>John Page</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jose Carlos Exposito Bueno</Name>
         <Organization>Jose Carlos Exposito Bueno</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Karthikeyan Bhargavan</Name>
         <Organization>Karthikeyan Bhargavan (and Gaetan Leurent)</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Khair Alhamad</Name>
         <Organization>Khair Alhamad</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Lovi Yu</Name>
         <Organization>Salesforce.com</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Luca Carettoni</Name>
         <Organization>Luca Carettoni</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Matias Mevied</Name>
         <Organization>Onapsis</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Mike Arnold</Name>
         <Organization>HPs Zero Day Initiative ( Tippingpoint)</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Mohamed Khaled Fathy</Name>
         <Organization>Mohamed Khaled Fathy</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Mohammed Al Bess, Mohammad Abuhassan</Name>
         <Organization>Mohammed Al Bess ,Mohammad Abuhassan</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Muhammed Gamal Fahmy</Name>
         <Organization>Muhammed Gamal Fahmy</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Nassim Bouali</Name>
         <Organization>Nassim Bouali</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Nicholas Lemonias</Name>
         <Organization>Advanced Information Security Corporation</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Nikita Kelesis</Name>
         <Organization>ERPScan</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Peter Kostiuk</Name>
         <Organization>Salesforce.com</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Pradeep Kumar</Name>
         <Organization>Pradeep Kumar</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Prem Kumar</Name>
         <Organization>Prem Kumar</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Renato Rodrigues</Name>
         <Organization>Renato Rodrigues</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ryan Giobbi</Name>
         <Organization>American Eagle Outfitters</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Samuel Orellana</Name>
         <Organization>Samuel Orellana</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Sergey Gorbaty</Name>
         <Organization>Salesforce.com</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Shahmeer Amir</Name>
         <Organization>Maads Security</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Shai Meir</Name>
         <Organization>McAfee Security Research</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Shawar Khan</Name>
         <Organization>Shawar Khan</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Spyridon Chatzimichail</Name>
         <Organization>COSMOTE - Mobile Telecommunications S.A.</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Stefan Kanthak</Name>
         <Organization>Stefan Kanthak</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Stephen Kost</Name>
         <Organization>Integrigy</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Travis Emmert</Name>
         <Organization>Salesforce.com</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Waleed Ezz Eldin</Name>
         <Organization>WIBF Kevin</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Weijun Lin</Name>
         <Organization>Future-Sec</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Will Dormann</Name>
         <Organization>CERT/CC</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Wouter Coekaerts</Name>
         <Organization>Wouter Coekaerts</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>an Anonymous Reporter</Name>
         <Organization>HP's Zero Day Initiative</Organization>
      </Acknowledgment>
   </Acknowledgments>
   <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
      <Branch Name="Oracle" Type="Vendor">
         <Branch Name="Oracle Communications Applications" Type="Product Family">
            <Branch Name="Communications Service Broker" Type="Product Name">
               <Branch Name="6.0" Type="Product Version">
                  <FullProductName ProductID="P-8565V-6.0">Communications Service Broker Version 6.0</FullProductName>
               </Branch>
               <Branch Name="6.1" Type="Product Version">
                  <FullProductName ProductID="P-8565V-6.1">Communications Service Broker Version 6.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Service Broker Engineered System Edition" Type="Product Name">
               <Branch Name="6.0" Type="Product Version">
                  <FullProductName ProductID="P-9056V-6.0">Communications Service Broker Engineered System Edition Version 6.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Converged Application Server - Service Controller" Type="Product Name">
               <Branch Name="6.1" Type="Product Version">
                  <FullProductName ProductID="P-10593V-6.1">Communications Converged Application Server - Service Controller Version 6.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Online Mediation Controller" Type="Product Name">
               <Branch Name="6.1" Type="Product Version">
                  <FullProductName ProductID="P-10594V-6.1">Communications Online Mediation Controller Version 6.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications EAGLE LNP Application Processor" Type="Product Name">
               <Branch Name="10.0" Type="Product Version">
                  <FullProductName ProductID="P-11118V-10.0">Communications EAGLE LNP Application Processor Version 10.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Database Server" Type="Product Family">
            <Branch Name="Oracle Database" Type="Product Name">
               <Branch Name="11.2.0.4" Type="Product Version">
                  <FullProductName ProductID="P-5V-11.2.0.4">Oracle Database Version 11.2.0.4</FullProductName>
               </Branch>
               <Branch Name="12.1.0.1" Type="Product Version">
                  <FullProductName ProductID="P-5V-12.1.0.1">Oracle Database Version 12.1.0.1</FullProductName>
               </Branch>
               <Branch Name="12.1.0.2" Type="Product Version">
                  <FullProductName ProductID="P-5V-12.1.0.2">Oracle Database Version 12.1.0.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="XML Developers Kit" Type="Product Name">
               <Branch Name="11.2.0.4" Type="Product Version">
                  <FullProductName ProductID="P-1068V-11.2.0.4">XML Developers Kit Version 11.2.0.4</FullProductName>
               </Branch>
               <Branch Name="12.1.0.1" Type="Product Version">
                  <FullProductName ProductID="P-1068V-12.1.0.1">XML Developers Kit Version 12.1.0.1</FullProductName>
               </Branch>
               <Branch Name="12.1.0.2" Type="Product Version">
                  <FullProductName ProductID="P-1068V-12.1.0.2">XML Developers Kit Version 12.1.0.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Workspace Manager" Type="Product Name">
               <Branch Name="11.2.0.4" Type="Product Version">
                  <FullProductName ProductID="P-1105V-11.2.0.4">Workspace Manager Version 11.2.0.4</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle E-Business Suite" Type="Product Family">
            <Branch Name="Applications Manager" Type="Product Name">
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-99V-12.1.3">Applications Manager Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="E-Business Intelligence" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-163V-11.5.10.2">E-Business Intelligence Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-163V-12.1.1">E-Business Intelligence Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-163V-12.1.2">E-Business Intelligence Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-163V-12.1.3">E-Business Intelligence Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Interaction Blending" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-182V-11.5.10.2">Interaction Blending Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-182V-12.1.1">Interaction Blending Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-182V-12.1.2">Interaction Blending Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-182V-12.1.3">Interaction Blending Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-182V-12.2.3">Interaction Blending Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-182V-12.2.4">Interaction Blending Version 12.2.4</FullProductName>
               </Branch>
               <Branch Name="12.2.5" Type="Product Version">
                  <FullProductName ProductID="P-182V-12.2.5">Interaction Blending Version 12.2.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Balanced Scorecard" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-205V-11.5.10.2">Balanced Scorecard Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Name="12.1" Type="Product Version">
                  <FullProductName ProductID="P-205V-12.1">Balanced Scorecard Version 12.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Quality" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-214V-11.5.10.2">Quality Version 11.5.10.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Marketing" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-229V-11.5.10.2">Marketing Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-229V-12.1.1">Marketing Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-229V-12.1.2">Marketing Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-229V-12.1.3">Marketing Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-229V-12.2.3">Marketing Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-229V-12.2.4">Marketing Version 12.2.4</FullProductName>
               </Branch>
               <Branch Name="12.2.5" Type="Product Version">
                  <FullProductName ProductID="P-229V-12.2.5">Marketing Version 12.2.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Interaction Center Intelligence" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-298V-11.5.10.2">Interaction Center Intelligence Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-298V-12.1.1">Interaction Center Intelligence Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-298V-12.1.2">Interaction Center Intelligence Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-298V-12.1.3">Interaction Center Intelligence Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Customer Intelligence" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-390V-11.5.10.2">Customer Intelligence Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-390V-12.1.1">Customer Intelligence Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-390V-12.1.2">Customer Intelligence Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-390V-12.1.3">Customer Intelligence Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-390V-12.2.3">Customer Intelligence Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-390V-12.2.4">Customer Intelligence Version 12.2.4</FullProductName>
               </Branch>
               <Branch Name="12.2.5" Type="Product Version">
                  <FullProductName ProductID="P-390V-12.2.5">Customer Intelligence Version 12.2.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Internet Expenses" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-397V-11.5.10.2">Internet Expenses Version 11.5.10.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="iProcurement" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-398V-11.5.10.2">iProcurement Version 11.5.10.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Service Contracts" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-432V-11.5.10.2">Service Contracts Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-432V-12.1.1">Service Contracts Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-432V-12.1.2">Service Contracts Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-432V-12.1.3">Service Contracts Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="General Ledger" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-500V-11.5.10.2">General Ledger Version 11.5.10.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Human Resources" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-507V-11.5.10.2">Human Resources Version 11.5.10.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Application Object Library" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-510V-11.5.10.2">Application Object Library Version 11.5.10.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Field Service" Type="Product Name">
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-747V-12.1.1">Field Service Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-747V-12.1.2">Field Service Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-747V-12.1.3">Field Service Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-747V-12.2.3">Field Service Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-747V-12.2.4">Field Service Version 12.2.4</FullProductName>
               </Branch>
               <Branch Name="12.2.5" Type="Product Version">
                  <FullProductName ProductID="P-747V-12.2.5">Field Service Version 12.2.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Report Manager" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-777V-11.5.10.2">Report Manager Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-777V-12.1.3">Report Manager Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-777V-12.2.3">Report Manager Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-777V-12.2.4">Report Manager Version 12.2.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Universal Work Queue" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-778V-11.5.10.2">Universal Work Queue Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-778V-12.1.1">Universal Work Queue Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-778V-12.1.2">Universal Work Queue Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-778V-12.1.3">Universal Work Queue Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Advanced Collections" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-782V-11.5.10.2">Advanced Collections Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-782V-12.1.1">Advanced Collections Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-782V-12.1.2">Advanced Collections Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-782V-12.1.3">Advanced Collections Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Project Contracts" Type="Product Name">
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-799V-12.1.1">Project Contracts Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-799V-12.1.2">Project Contracts Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-799V-12.1.3">Project Contracts Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Learning Management" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-937V-11.5.10.2">Learning Management Version 11.5.10.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Email Center" Type="Product Name">
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-950V-12.1.1">Email Center Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-950V-12.1.2">Email Center Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-950V-12.1.3">Email Center Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Mobile Application Server" Type="Product Name">
               <Branch Name="12.1" Type="Product Version">
                  <FullProductName ProductID="P-995V-12.1">Mobile Application Server Version 12.1</FullProductName>
               </Branch>
               <Branch Name="12.2" Type="Product Version">
                  <FullProductName ProductID="P-995V-12.2">Mobile Application Server Version 12.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="iReceivables" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-1106V-11.5.10.2">iReceivables Version 11.5.10.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Approvals Management" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-1168V-11.5.10.2">Approvals Management Version 11.5.10.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Common Applications" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-1198V-11.5.10.2">Common Applications Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-1198V-12.1.1">Common Applications Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-1198V-12.1.2">Common Applications Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1198V-12.1.3">Common Applications Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="CRM Technical Foundation" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-1199V-11.5.10.2">CRM Technical Foundation Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1199V-12.1.3">CRM Technical Foundation Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-1199V-12.2.3">CRM Technical Foundation Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-1199V-12.2.4">CRM Technical Foundation Version 12.2.4</FullProductName>
               </Branch>
               <Branch Name="12.2.5" Type="Product Version">
                  <FullProductName ProductID="P-1199V-12.2.5">CRM Technical Foundation Version 12.2.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="CADView-3D" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-1285V-11.5.10.2">CADView-3D Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-1285V-12.1.1">CADView-3D Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-1285V-12.1.2">CADView-3D Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1285V-12.1.3">CADView-3D Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Customer Interaction History" Type="Product Name">
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-1374V-12.1.1">Customer Interaction History Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-1374V-12.1.2">Customer Interaction History Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1374V-12.1.3">Customer Interaction History Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-1374V-12.2.3">Customer Interaction History Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-1374V-12.2.4">Customer Interaction History Version 12.2.4</FullProductName>
               </Branch>
               <Branch Name="12.2.5" Type="Product Version">
                  <FullProductName ProductID="P-1374V-12.2.5">Customer Interaction History Version 12.2.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Consolidation Hub" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-1375V-11.5.10.2">Financial Consolidation Hub Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-1375V-12.1.1">Financial Consolidation Hub Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-1375V-12.1.2">Financial Consolidation Hub Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1375V-12.1.3">Financial Consolidation Hub Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Applications Framework" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-1472V-11.5.10.2">Applications Framework Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Name="12.1" Type="Product Version">
                  <FullProductName ProductID="P-1472V-12.1">Applications Framework Version 12.1</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1472V-12.1.3">Applications Framework Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2" Type="Product Version">
                  <FullProductName ProductID="P-1472V-12.2">Applications Framework Version 12.2</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-1472V-12.2.3">Applications Framework Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-1472V-12.2.4">Applications Framework Version 12.2.4</FullProductName>
               </Branch>
               <Branch Name="12.2.5" Type="Product Version">
                  <FullProductName ProductID="P-1472V-12.2.5">Applications Framework Version 12.2.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Self-Service Human Resources" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-1566V-11.5.10.2">Self-Service Human Resources Version 11.5.10.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Applications Technology Stack" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-1745V-11.5.10.2">Applications Technology Stack Version 11.5.10.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="HCM Configuration Workbench" Type="Product Name">
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-2011V-12.1.1">HCM Configuration Workbench Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-2011V-12.1.2">HCM Configuration Workbench Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-2011V-12.1.3">HCM Configuration Workbench Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Application Management Pack for Oracle E-Business Suite" Type="Product Name">
               <Branch Name="12.1" Type="Product Version">
                  <FullProductName ProductID="P-2294V-12.1">Application Management Pack for Oracle E-Business Suite Version 12.1</FullProductName>
               </Branch>
               <Branch Name="12.2" Type="Product Version">
                  <FullProductName ProductID="P-2294V-12.2">Application Management Pack for Oracle E-Business Suite Version 12.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Enterprise Manager Grid Control" Type="Product Family">
            <Branch Name="Enterprise Manager Base Platform" Type="Product Name">
               <Branch Name="11.1.0.1" Type="Product Version">
                  <FullProductName ProductID="P-1370V-11.1.0.1">Enterprise Manager Base Platform Version 11.1.0.1</FullProductName>
               </Branch>
               <Branch Name="11.2.0.4" Type="Product Version">
                  <FullProductName ProductID="P-1370V-11.2.0.4">Enterprise Manager Base Platform Version 11.2.0.4</FullProductName>
               </Branch>
               <Branch Name="12.1.0.4" Type="Product Version">
                  <FullProductName ProductID="P-1370V-12.1.0.4">Enterprise Manager Base Platform Version 12.1.0.4</FullProductName>
               </Branch>
               <Branch Name="12.1.0.5" Type="Product Version">
                  <FullProductName ProductID="P-1370V-12.1.0.5">Enterprise Manager Base Platform Version 12.1.0.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Application Testing Suite" Type="Product Name">
               <Branch Name="12.4.0.2" Type="Product Version">
                  <FullProductName ProductID="P-4622V-12.4.0.2">Application Testing Suite Version 12.4.0.2</FullProductName>
               </Branch>
               <Branch Name="12.5.0.2" Type="Product Version">
                  <FullProductName ProductID="P-4622V-12.5.0.2">Application Testing Suite Version 12.5.0.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Enterprise Manager Ops Center" Type="Product Name">
               <Branch Name="12.2.0" Type="Product Version">
                  <FullProductName ProductID="P-9835V-12.2.0">Enterprise Manager Ops Center Version 12.2.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1" Type="Product Version">
                  <FullProductName ProductID="P-9835V-12.2.1">Enterprise Manager Ops Center Version 12.2.1</FullProductName>
               </Branch>
               <Branch Name="12.3.0" Type="Product Version">
                  <FullProductName ProductID="P-9835V-12.3.0">Enterprise Manager Ops Center Version 12.3.0</FullProductName>
               </Branch>
               <Branch Name="Prior to 12.1.4" Type="Product Version">
                  <FullProductName ProductID="P-9835V-Prior to 12.1.4">Enterprise Manager Ops Center Version Prior to 12.1.4</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Fusion Middleware" Type="Product Family">
            <Branch Name="Web Cache" Type="Product Name">
               <Branch Name="11.1.1.7.0" Type="Product Version">
                  <FullProductName ProductID="P-1059V-11.1.1.7.0">Web Cache Version 11.1.1.7.0</FullProductName>
               </Branch>
               <Branch Name="11.1.1.9.0" Type="Product Version">
                  <FullProductName ProductID="P-1059V-11.1.1.9.0">Web Cache Version 11.1.1.9.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="BI Publisher (formerly XML Publisher)" Type="Product Name">
               <Branch Name="11.1.1.7.0" Type="Product Version">
                  <FullProductName ProductID="P-1479V-11.1.1.7.0">BI Publisher (formerly XML Publisher) Version 11.1.1.7.0</FullProductName>
               </Branch>
               <Branch Name="11.1.1.9.0" Type="Product Version">
                  <FullProductName ProductID="P-1479V-11.1.1.9.0">BI Publisher (formerly XML Publisher) Version 11.1.1.9.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.0.0" Type="Product Version">
                  <FullProductName ProductID="P-1479V-12.2.1.0.0">BI Publisher (formerly XML Publisher) Version 12.2.1.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Identity Federation" Type="Product Name">
               <Branch Name="11.1.1.7" Type="Product Version">
                  <FullProductName ProductID="P-1741V-11.1.1.7">Identity Federation Version 11.1.1.7</FullProductName>
               </Branch>
               <Branch Name="11.1.2.2" Type="Product Version">
                  <FullProductName ProductID="P-1741V-11.1.2.2">Identity Federation Version 11.1.2.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Business Intelligence Enterprise Edition" Type="Product Name">
               <Branch Name="11.1.1.7.0" Type="Product Version">
                  <FullProductName ProductID="P-2025V-11.1.1.7.0">Business Intelligence Enterprise Edition Version 11.1.1.7.0</FullProductName>
               </Branch>
               <Branch Name="11.1.1.9.0" Type="Product Version">
                  <FullProductName ProductID="P-2025V-11.1.1.9.0">Business Intelligence Enterprise Edition Version 11.1.1.9.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Outside In Technology" Type="Product Name">
               <Branch Name="8.5.0" Type="Product Version">
                  <FullProductName ProductID="P-2276V-8.5.0">Outside In Technology Version 8.5.0</FullProductName>
               </Branch>
               <Branch Name="8.5.1" Type="Product Version">
                  <FullProductName ProductID="P-2276V-8.5.1">Outside In Technology Version 8.5.1</FullProductName>
               </Branch>
               <Branch Name="8.5.2" Type="Product Version">
                  <FullProductName ProductID="P-2276V-8.5.2">Outside In Technology Version 8.5.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="WebLogic Server" Type="Product Name">
               <Branch Name="10.3.6" Type="Product Version">
                  <FullProductName ProductID="P-5242V-10.3.6">WebLogic Server Version 10.3.6</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-5242V-12.1.2">WebLogic Server Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-5242V-12.1.3">WebLogic Server Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.1" Type="Product Version">
                  <FullProductName ProductID="P-5242V-12.2.1">WebLogic Server Version 12.2.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="WebLogic Portal" Type="Product Name">
               <Branch Name="10.3.6" Type="Product Version">
                  <FullProductName ProductID="P-5307V-10.3.6">WebLogic Portal Version 10.3.6</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Tuxedo" Type="Product Name">
               <Branch Name="12.1.1.0" Type="Product Version">
                  <FullProductName ProductID="P-5433V-12.1.1.0">Tuxedo Version 12.1.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="GlassFish Server" Type="Product Name">
               <Branch Name="3.1.2" Type="Product Version">
                  <FullProductName ProductID="P-8493V-3.1.2">GlassFish Server Version 3.1.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="WebCenter Sites" Type="Product Name">
               <Branch Name="11.1.1.8.0" Type="Product Version">
                  <FullProductName ProductID="P-9617V-11.1.1.8.0">WebCenter Sites Version 11.1.1.8.0</FullProductName>
               </Branch>
               <Branch Name="7.6.2" Type="Product Version">
                  <FullProductName ProductID="P-9617V-7.6.2">WebCenter Sites Version 7.6.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Endeca Server" Type="Product Name">
               <Branch Name="7.3.0.0" Type="Product Version">
                  <FullProductName ProductID="P-10217V-7.3.0.0">Endeca Server Version 7.3.0.0</FullProductName>
               </Branch>
               <Branch Name="7.4.0.0" Type="Product Version">
                  <FullProductName ProductID="P-10217V-7.4.0.0">Endeca Server Version 7.4.0.0</FullProductName>
               </Branch>
               <Branch Name="7.5.0.0" Type="Product Version">
                  <FullProductName ProductID="P-10217V-7.5.0.0">Endeca Server Version 7.5.0.0</FullProductName>
               </Branch>
               <Branch Name="7.6.0.0" Type="Product Version">
                  <FullProductName ProductID="P-10217V-7.6.0.0">Endeca Server Version 7.6.0.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle GoldenGate" Type="Product Family">
            <Branch Name="GoldenGate" Type="Product Name">
               <Branch Name="11.2" Type="Product Version">
                  <FullProductName ProductID="P-5757V-11.2">GoldenGate Version 11.2</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-5757V-12.1.2">GoldenGate Version 12.1.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle JD Edwards Products" Type="Product Family">
            <Branch Name="JD Edwards EnterpriseOne Tools" Type="Product Name">
               <Branch Name="9.1" Type="Product Version">
                  <FullProductName ProductID="P-4781V-9.1">JD Edwards EnterpriseOne Tools Version 9.1</FullProductName>
               </Branch>
               <Branch Name="9.2" Type="Product Version">
                  <FullProductName ProductID="P-4781V-9.2">JD Edwards EnterpriseOne Tools Version 9.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Java SE" Type="Product Family">
            <Branch Name="Java" Type="Product Name">
               <Branch Name="7u91" Type="Product Version">
                  <FullProductName ProductID="P-856V-7u91">Java Version 7u91</FullProductName>
               </Branch>
               <Branch Name="8u66; Java SE Embedded: 8u65" Type="Product Version">
                  <FullProductName ProductID="P-856V-8u66; Java SE Embedded: 8u65">Java Version 8u66; Java SE Embedded: 8u65</FullProductName>
               </Branch>
               <Branch Name="8u66; Java SE Embedded: 8u65; JRockit: R28.3.8" Type="Product Version">
                  <FullProductName ProductID="P-856V-8u66; Java SE Embedded: 8u65; JRockit: R28.3.8">Java Version 8u66; Java SE Embedded: 8u65; JRockit: R28.3.8</FullProductName>
               </Branch>
               <Branch Name="Java SE: 6u105" Type="Product Version">
                  <FullProductName ProductID="P-856V-Java SE: 6u105">Java Version Java SE: 6u105</FullProductName>
               </Branch>
               <Branch Name="Java SE: 8u66; Java SE Embedded: 8u65; JRockit: R28.3.8" Type="Product Version">
                  <FullProductName ProductID="P-856V-Java SE: 8u66; Java SE Embedded: 8u65; JRockit: R28.3.8">Java Version Java SE: 8u66; Java SE Embedded: 8u65; JRockit: R28.3.8</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle MySQL" Type="Product Family">
            <Branch Name="MySQL Server" Type="Product Name">
               <Branch Name="5.5.31 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.5.31 and earlier">MySQL Server Version 5.5.31 and earlier</FullProductName>
               </Branch>
               <Branch Name="5.5.45 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.5.45 and earlier">MySQL Server Version 5.5.45 and earlier</FullProductName>
               </Branch>
               <Branch Name="5.5.46 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.5.46 and earlier">MySQL Server Version 5.5.46 and earlier</FullProductName>
               </Branch>
               <Branch Name="5.6.11 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.6.11 and earlier">MySQL Server Version 5.6.11 and earlier</FullProductName>
               </Branch>
               <Branch Name="5.6.21 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.6.21 and earlier">MySQL Server Version 5.6.21 and earlier</FullProductName>
               </Branch>
               <Branch Name="5.6.26 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.6.26 and earlier">MySQL Server Version 5.6.26 and earlier</FullProductName>
               </Branch>
               <Branch Name="5.6.27 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.6.27 and earlier">MySQL Server Version 5.6.27 and earlier</FullProductName>
               </Branch>
               <Branch Name="5.7.9" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.7.9">MySQL Server Version 5.7.9</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle PeopleSoft Products" Type="Product Family">
            <Branch Name="PeopleSoft Enterprise HCM Global Payroll Switzerland" Type="Product Name">
               <Branch Name="9.1" Type="Product Version">
                  <FullProductName ProductID="P-5068V-9.1">PeopleSoft Enterprise HCM Global Payroll Switzerland Version 9.1</FullProductName>
               </Branch>
               <Branch Name="9.2" Type="Product Version">
                  <FullProductName ProductID="P-5068V-9.2">PeopleSoft Enterprise HCM Global Payroll Switzerland Version 9.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="PeopleSoft Enterprise PT PeopleTools" Type="Product Name">
               <Branch Name="8.53" Type="Product Version">
                  <FullProductName ProductID="P-5085V-8.53">PeopleSoft Enterprise PT PeopleTools Version 8.53</FullProductName>
               </Branch>
               <Branch Name="8.54" Type="Product Version">
                  <FullProductName ProductID="P-5085V-8.54">PeopleSoft Enterprise PT PeopleTools Version 8.54</FullProductName>
               </Branch>
               <Branch Name="8.55" Type="Product Version">
                  <FullProductName ProductID="P-5085V-8.55">PeopleSoft Enterprise PT PeopleTools Version 8.55</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="PeopleSoft Enterprise SCM eProcurement" Type="Product Name">
               <Branch Name="9.1" Type="Product Version">
                  <FullProductName ProductID="P-5118V-9.1">PeopleSoft Enterprise SCM eProcurement Version 9.1</FullProductName>
               </Branch>
               <Branch Name="9.2" Type="Product Version">
                  <FullProductName ProductID="P-5118V-9.2">PeopleSoft Enterprise SCM eProcurement Version 9.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="PeopleSoft Enterprise SCM Order Management" Type="Product Name">
               <Branch Name="9.1" Type="Product Version">
                  <FullProductName ProductID="P-5127V-9.1">PeopleSoft Enterprise SCM Order Management Version 9.1</FullProductName>
               </Branch>
               <Branch Name="9.2" Type="Product Version">
                  <FullProductName ProductID="P-5127V-9.2">PeopleSoft Enterprise SCM Order Management Version 9.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="PeopleSoft Enterprise SCM Purchasing" Type="Product Name">
               <Branch Name="9.1" Type="Product Version">
                  <FullProductName ProductID="P-5133V-9.1">PeopleSoft Enterprise SCM Purchasing Version 9.1</FullProductName>
               </Branch>
               <Branch Name="9.2" Type="Product Version">
                  <FullProductName ProductID="P-5133V-9.2">PeopleSoft Enterprise SCM Purchasing Version 9.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Retail Applications" Type="Product Family">
            <Branch Name="Retail Point-of-Service" Type="Product Name">
               <Branch Name="13.4" Type="Product Version">
                  <FullProductName ProductID="P-2017V-13.4">Retail Point-of-Service Version 13.4</FullProductName>
               </Branch>
               <Branch Name="14.0" Type="Product Version">
                  <FullProductName ProductID="P-2017V-14.0">Retail Point-of-Service Version 14.0</FullProductName>
               </Branch>
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-2017V-14.1">Retail Point-of-Service Version 14.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Order Management System Cloud Service" Type="Product Name">
               <Branch Name="15.0" Type="Product Version">
                  <FullProductName ProductID="P-11519V-15.0">Retail Order Management System Cloud Service Version 15.0</FullProductName>
               </Branch>
               <Branch Name="3.5" Type="Product Version">
                  <FullProductName ProductID="P-11519V-3.5">Retail Order Management System Cloud Service Version 3.5</FullProductName>
               </Branch>
               <Branch Name="4.5" Type="Product Version">
                  <FullProductName ProductID="P-11519V-4.5">Retail Order Management System Cloud Service Version 4.5</FullProductName>
               </Branch>
               <Branch Name="4.7" Type="Product Version">
                  <FullProductName ProductID="P-11519V-4.7">Retail Order Management System Cloud Service Version 4.7</FullProductName>
               </Branch>
               <Branch Name="5.0" Type="Product Version">
                  <FullProductName ProductID="P-11519V-5.0">Retail Order Management System Cloud Service Version 5.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Order Broker Cloud Service" Type="Product Name">
               <Branch Name="4.0" Type="Product Version">
                  <FullProductName ProductID="P-11520V-4.0">Retail Order Broker Cloud Service Version 4.0</FullProductName>
               </Branch>
               <Branch Name="4.1." Type="Product Version">
                  <FullProductName ProductID="P-11520V-4.1.">Retail Order Broker Cloud Service Version 4.1.</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Open Commerce Platform Cloud Service" Type="Product Name">
               <Branch Name="3.5" Type="Product Version">
                  <FullProductName ProductID="P-11521V-3.5">Retail Open Commerce Platform Cloud Service Version 3.5</FullProductName>
               </Branch>
               <Branch Name="4.5" Type="Product Version">
                  <FullProductName ProductID="P-11521V-4.5">Retail Open Commerce Platform Cloud Service Version 4.5</FullProductName>
               </Branch>
               <Branch Name="4.7" Type="Product Version">
                  <FullProductName ProductID="P-11521V-4.7">Retail Open Commerce Platform Cloud Service Version 4.7</FullProductName>
               </Branch>
               <Branch Name="5.0" Type="Product Version">
                  <FullProductName ProductID="P-11521V-5.0">Retail Open Commerce Platform Cloud Service Version 5.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="MICROS CWDirect" Type="Product Name">
               <Branch Name="12.5" Type="Product Version">
                  <FullProductName ProductID="P-11547V-12.5">MICROS CWDirect Version 12.5</FullProductName>
               </Branch>
               <Branch Name="13.0" Type="Product Version">
                  <FullProductName ProductID="P-11547V-13.0">MICROS CWDirect Version 13.0</FullProductName>
               </Branch>
               <Branch Name="14.0" Type="Product Version">
                  <FullProductName ProductID="P-11547V-14.0">MICROS CWDirect Version 14.0</FullProductName>
               </Branch>
               <Branch Name="15.0" Type="Product Version">
                  <FullProductName ProductID="P-11547V-15.0">MICROS CWDirect Version 15.0</FullProductName>
               </Branch>
               <Branch Name="16.0" Type="Product Version">
                  <FullProductName ProductID="P-11547V-16.0">MICROS CWDirect Version 16.0</FullProductName>
               </Branch>
               <Branch Name="17.018.0" Type="Product Version">
                  <FullProductName ProductID="P-11547V-17.018.0">MICROS CWDirect Version 17.018.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Sun Systems Products Suite" Type="Product Family">
            <Branch Name="OPUS 10G Ethernet Switch Family" Type="Product Name">
               <Branch Name="Versions prior to 1.2.2.13" Type="Product Version">
                  <FullProductName ProductID="P-9889V-Versions prior to 1.2.2.13">OPUS 10G Ethernet Switch Family Version Versions prior to 1.2.2.13</FullProductName>
               </Branch>
               <Branch Name="Versions prior to 1.2.2.15" Type="Product Version">
                  <FullProductName ProductID="P-9889V-Versions prior to 1.2.2.15">OPUS 10G Ethernet Switch Family Version Versions prior to 1.2.2.15</FullProductName>
               </Branch>
               <Branch Name="Versions prior to 1.3.1.13" Type="Product Version">
                  <FullProductName ProductID="P-9889V-Versions prior to 1.3.1.13">OPUS 10G Ethernet Switch Family Version Versions prior to 1.3.1.13</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Solaris Cluster" Type="Product Name">
               <Branch Name="3.3" Type="Product Version">
                  <FullProductName ProductID="P-10005V-3.3">Solaris Cluster Version 3.3</FullProductName>
               </Branch>
               <Branch Name="4" Type="Product Version">
                  <FullProductName ProductID="P-10005V-4">Solaris Cluster Version 4</FullProductName>
               </Branch>
               <Branch Name="4.2" Type="Product Version">
                  <FullProductName ProductID="P-10005V-4.2">Solaris Cluster Version 4.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Solaris Operating System" Type="Product Name">
               <Branch Name="10" Type="Product Version">
                  <FullProductName ProductID="P-10006V-10">Solaris Operating System Version 10</FullProductName>
               </Branch>
               <Branch Name="11" Type="Product Version">
                  <FullProductName ProductID="P-10006V-11">Solaris Operating System Version 11</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Supply Chain Products Suite" Type="Product Family">
            <Branch Name="Configurator" Type="Product Name">
               <Branch Name="11.5.10.2" Type="Product Version">
                  <FullProductName ProductID="P-31V-11.5.10.2">Configurator Version 11.5.10.2</FullProductName>
               </Branch>
               <Branch Name="12.1" Type="Product Version">
                  <FullProductName ProductID="P-31V-12.1">Configurator Version 12.1</FullProductName>
               </Branch>
               <Branch Name="12.2" Type="Product Version">
                  <FullProductName ProductID="P-31V-12.2">Configurator Version 12.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Agile Engineering Data Management" Type="Product Name">
               <Branch Name="6.1.2.2" Type="Product Version">
                  <FullProductName ProductID="P-4436V-6.1.2.2">Agile Engineering Data Management Version 6.1.2.2</FullProductName>
               </Branch>
               <Branch Name="6.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-4436V-6.1.3.0">Agile Engineering Data Management Version 6.1.3.0</FullProductName>
               </Branch>
               <Branch Name="6.2.0.0" Type="Product Version">
                  <FullProductName ProductID="P-4436V-6.2.0.0">Agile Engineering Data Management Version 6.2.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Agile PLM Framework" Type="Product Name">
               <Branch Name="9.3.1.1" Type="Product Version">
                  <FullProductName ProductID="P-4461V-9.3.1.1">Agile PLM Framework Version 9.3.1.1</FullProductName>
               </Branch>
               <Branch Name="9.3.1.2" Type="Product Version">
                  <FullProductName ProductID="P-4461V-9.3.1.2">Agile PLM Framework Version 9.3.1.2</FullProductName>
               </Branch>
               <Branch Name="9.3.2" Type="Product Version">
                  <FullProductName ProductID="P-4461V-9.3.2">Agile PLM Framework Version 9.3.2</FullProductName>
               </Branch>
               <Branch Name="9.3.3" Type="Product Version">
                  <FullProductName ProductID="P-4461V-9.3.3">Agile PLM Framework Version 9.3.3</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Virtualization" Type="Product Family">
            <Branch Name="Oracle VM VirtualBox" Type="Product Name">
               <Branch Name="VirtualBox prior to 4.0.36" Type="Product Version">
                  <FullProductName ProductID="P-8370V-VirtualBox prior to 4.0.36">Oracle VM VirtualBox Version VirtualBox prior to 4.0.36</FullProductName>
               </Branch>
               <Branch Name="VirtualBox prior to 4.3.36" Type="Product Version">
                  <FullProductName ProductID="P-8370V-VirtualBox prior to 4.3.36">Oracle VM VirtualBox Version VirtualBox prior to 4.3.36</FullProductName>
               </Branch>
               <Branch Name="VirtualBox prior to 5.0.14" Type="Product Version">
                  <FullProductName ProductID="P-8370V-VirtualBox prior to 5.0.14">Oracle VM VirtualBox Version VirtualBox prior to 5.0.14</FullProductName>
               </Branch>
               <Branch Name="prior to 4.1.44" Type="Product Version">
                  <FullProductName ProductID="P-8370V-prior to 4.1.44">Oracle VM VirtualBox Version prior to 4.1.44</FullProductName>
               </Branch>
               <Branch Name="prior to 4.2.36" Type="Product Version">
                  <FullProductName ProductID="P-8370V-prior to 4.2.36">Oracle VM VirtualBox Version prior to 4.2.36</FullProductName>
               </Branch>
               <Branch Name="prior to 4.3.34" Type="Product Version">
                  <FullProductName ProductID="P-8370V-prior to 4.3.34">Oracle VM VirtualBox Version prior to 4.3.34</FullProductName>
               </Branch>
               <Branch Name="prior to 5.0.10" Type="Product Version">
                  <FullProductName ProductID="P-8370V-prior to 5.0.10">Oracle VM VirtualBox Version prior to 5.0.10</FullProductName>
               </Branch>
               <Branch Name="prior to 5.0.14" Type="Product Version">
                  <FullProductName ProductID="P-8370V-prior to 5.0.14">Oracle VM VirtualBox Version prior to 5.0.14</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Secure Global Desktop" Type="Product Name">
               <Branch Name="4.63" Type="Product Version">
                  <FullProductName ProductID="P-8539V-4.63">Secure Global Desktop Version 4.63</FullProductName>
               </Branch>
               <Branch Name="4.71" Type="Product Version">
                  <FullProductName ProductID="P-8539V-4.71">Secure Global Desktop Version 4.71</FullProductName>
               </Branch>
               <Branch Name="5.2" Type="Product Version">
                  <FullProductName ProductID="P-8539V-5.2">Secure Global Desktop Version 5.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle iLearning" Type="Product Family">
            <Branch Name="iLearning" Type="Product Name">
               <Branch Name="6.0" Type="Product Version">
                  <FullProductName ProductID="P-902V-6.0">iLearning Version 6.0</FullProductName>
               </Branch>
               <Branch Name="6.1" Type="Product Version">
                  <FullProductName ProductID="P-902V-6.1">iLearning Version 6.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
      </Branch>
   </ProductTree>
   <Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-1741</Title>
      <Notes>
         <Note Audience="All" Ordinal="1" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Ops Center component of Oracle Enterprise Manager Grid Control (subcomponent: Satellite Framework).  Supported versions that are affected are Prior to 12.1.4, 12.2.0, 12.2.1 and  12.3.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized takeover of Enterprise Manager Ops Center possibly including arbitrary code execution within the Enterprise Manager Ops Center.  CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-1741</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9835V-Prior to 12.1.4</ProductID>
            <ProductID>P-9835V-12.2.0</ProductID>
            <ProductID>P-9835V-12.2.1</ProductID>
            <ProductID>P-9835V-12.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-9835V-Prior to 12.1.4</ProductID>
            <ProductID>P-9835V-12.2.0</ProductID>
            <ProductID>P-9835V-12.2.1</ProductID>
            <ProductID>P-9835V-12.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-2186</Title>
      <Notes>
         <Note Audience="All" Ordinal="2" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Portal component of Oracle Fusion Middleware (subcomponent: Core Services).   The supported version that is affected is 10.3.6. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle WebLogic Portal accessible data as well as  read access to a subset of Oracle WebLogic Portal accessible data and ability to cause a partial denial of service (partial DOS) of Oracle WebLogic Portal.  CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-2186</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5307V-10.3.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-5307V-10.3.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="3" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-0050</Title>
      <Notes>
         <Note Audience="All" Ordinal="3" Title="Details" Type="Details">Vulnerability in the Oracle Communications Service Broker component of Oracle Communications Applications (subcomponent: Apache Commons FileUpLoad).  Supported versions that are affected are 6.0 and  6.1. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP, but can only be launched from an adjacent network.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Communications Service Broker accessible data as well as  read access to a subset of Oracle Communications Service Broker accessible data and ability to cause a partial denial of service (partial DOS) of Oracle Communications Service Broker.  CVSS Base Score 5.8 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:A/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:A/AC:L/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-0050</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8565V-6.0</ProductID>
            <ProductID>P-8565V-6.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.8</BaseScore>
            <Vector>AV:A/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8565V-6.0</ProductID>
            <ProductID>P-8565V-6.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="4" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-0050</Title>
      <Notes>
         <Note Audience="All" Ordinal="4" Title="Details" Type="Details">Vulnerability in the Oracle Communications Service Broker Engineered System Edition component of Oracle Communications Applications (subcomponent: Apache Commons FileUpLoad).   The supported version that is affected is 6.0. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Communications Service Broker Engineered System Edition accessible data as well as  read access to a subset of Oracle Communications Service Broker Engineered System Edition accessible data.  CVSS Base Score 5.5 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-0050</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9056V-6.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-9056V-6.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="5" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-0050</Title>
      <Notes>
         <Note Audience="All" Ordinal="5" Title="Details" Type="Details">Vulnerability in the Oracle Communications Converged Application Server - Service Controller component of Oracle Communications Applications (subcomponent: Apache Commons FileUpLoad).   The supported version that is affected is 6.1. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP, but can only be launched from an adjacent network.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Communications Converged Application Server - Service Controller accessible data as well as  read access to a subset of Oracle Communications Converged Application Server - Service Controller accessible data and ability to cause a partial denial of service (partial DOS) of Oracle Communications Converged Application Server - Service Controller.  CVSS Base Score 5.8 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:A/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:A/AC:L/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-0050</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10593V-6.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.8</BaseScore>
            <Vector>AV:A/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-10593V-6.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="6" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-0050</Title>
      <Notes>
         <Note Audience="All" Ordinal="6" Title="Details" Type="Details">Vulnerability in the Oracle Communications Online Mediation Controller component of Oracle Communications Applications (subcomponent: Apache Commons FileUpLoad).   The supported version that is affected is 6.1. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP, but can only be launched from an adjacent network.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Communications Online Mediation Controller accessible data as well as  read access to a subset of Oracle Communications Online Mediation Controller accessible data and ability to cause a partial denial of service (partial DOS) of Oracle Communications Online Mediation Controller.  CVSS Base Score 5.8 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:A/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:A/AC:L/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-0050</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10594V-6.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.8</BaseScore>
            <Vector>AV:A/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-10594V-6.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="7" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-0107</Title>
      <Notes>
         <Note Audience="All" Ordinal="7" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: XML Parser).  Supported versions that are affected are 10.3.6, 12.1.2 and  12.1.3. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle WebLogic Server accessible data as well as  read access to a subset of Oracle WebLogic Server accessible data and ability to cause a partial denial of service (partial DOS) of Oracle WebLogic Server.  CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-0107</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.3.6</ProductID>
            <ProductID>P-5242V-12.1.2</ProductID>
            <ProductID>P-5242V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-5242V-10.3.6</ProductID>
            <ProductID>P-5242V-12.1.2</ProductID>
            <ProductID>P-5242V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="8" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-0107</Title>
      <Notes>
         <Note Audience="All" Ordinal="8" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Sites).  Supported versions that are affected are 7.6.2 and 11.1.1.8.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle WebCenter Sites accessible data as well as  read access to a subset of Oracle WebCenter Sites accessible data and ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Sites.  CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-0107</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9617V-7.6.2</ProductID>
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-9617V-7.6.2</ProductID>
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="9" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-3583</Title>
      <Notes>
         <Note Audience="All" Ordinal="9" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Ops Center component of Oracle Enterprise Manager Grid Control (subcomponent: Update Provisioning).  Supported versions that are affected are Prior to 12.1.4, 12.2.0, 12.2.1 and  12.3.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Enterprise Manager Ops Center accessible data.  CVSS Base Score 5.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-3583</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9835V-Prior to 12.1.4</ProductID>
            <ProductID>P-9835V-12.2.0</ProductID>
            <ProductID>P-9835V-12.2.1</ProductID>
            <ProductID>P-9835V-12.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-9835V-Prior to 12.1.4</ProductID>
            <ProductID>P-9835V-12.2.0</ProductID>
            <ProductID>P-9835V-12.2.1</ProductID>
            <ProductID>P-9835V-12.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="10" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0235</Title>
      <Notes>
         <Note Audience="All" Ordinal="10" Title="Details" Type="Details">Vulnerability in the Oracle Communications EAGLE LNP Application Processor component of Oracle Communications Applications (subcomponent: Glibc).   The supported version that is affected is 10.0. Difficult to exploit vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Communications EAGLE LNP Application Processor accessible data as well as  read access to a subset of Oracle Communications EAGLE LNP Application Processor accessible data and ability to cause a partial denial of service (partial DOS) of Oracle Communications EAGLE LNP Application Processor.  CVSS Base Score 6.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:M/Au:S/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0235</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11118V-10.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.0</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-11118V-10.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="11" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0286</Title>
      <Notes>
         <Note Audience="All" Ordinal="11" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Ops Center component of Oracle Enterprise Manager Grid Control (subcomponent: Networking).  Supported versions that are affected are Prior to 12.1.4, 12.2.0, 12.2.1 and  12.3.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Enterprise Manager Ops Center.  CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0286</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9835V-Prior to 12.1.4</ProductID>
            <ProductID>P-9835V-12.2.0</ProductID>
            <ProductID>P-9835V-12.2.1</ProductID>
            <ProductID>P-9835V-12.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-9835V-Prior to 12.1.4</ProductID>
            <ProductID>P-9835V-12.2.0</ProductID>
            <ProductID>P-9835V-12.2.1</ProductID>
            <ProductID>P-9835V-12.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="12" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-1793</Title>
      <Notes>
         <Note Audience="All" Ordinal="12" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Discovery Framework).  Supported versions that are affected are 12.1.0.4 and 
12.1.0.5. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTPS.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Enterprise Manager Base Platform accessible data as well as  read access to a subset of Enterprise Manager Base Platform accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-1793</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-12.1.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1370V-12.1.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="13" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-1793</Title>
      <Notes>
         <Note Audience="All" Ordinal="13" Title="Details" Type="Details">Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: BI Platform Security).  Supported versions that are affected are 11.1.1.7.0 and 11.1.1.9.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTPS.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Business Intelligence Enterprise Edition accessible data as well as  read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-1793</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2025V-11.1.1.7.0</ProductID>
            <ProductID>P-2025V-11.1.1.9.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-2025V-11.1.1.7.0</ProductID>
            <ProductID>P-2025V-11.1.1.9.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="14" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-1793</Title>
      <Notes>
         <Note Audience="All" Ordinal="14" Title="Details" Type="Details">Vulnerability in the Oracle Tuxedo component of Oracle Fusion Middleware (subcomponent: SSL/TLS).   The supported version that is affected is 12.1.1.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTPS.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Tuxedo accessible data as well as  read access to a subset of Oracle Tuxedo accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-1793</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5433V-12.1.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-5433V-12.1.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="15" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-1793</Title>
      <Notes>
         <Note Audience="All" Ordinal="15" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Ops Center component of Oracle Enterprise Manager Grid Control (subcomponent: Networking).  Supported versions that are affected are Prior to 12.1.4, 12.2.0, 12.2.1 and  12.3.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTPS.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Enterprise Manager Ops Center accessible data as well as  read access to a subset of Enterprise Manager Ops Center accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-1793</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9835V-Prior to 12.1.4</ProductID>
            <ProductID>P-9835V-12.2.0</ProductID>
            <ProductID>P-9835V-12.2.1</ProductID>
            <ProductID>P-9835V-12.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-9835V-Prior to 12.1.4</ProductID>
            <ProductID>P-9835V-12.2.0</ProductID>
            <ProductID>P-9835V-12.2.1</ProductID>
            <ProductID>P-9835V-12.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="16" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-1793</Title>
      <Notes>
         <Note Audience="All" Ordinal="16" Title="Details" Type="Details">Vulnerability in the Oracle Switch ES1-24 component of Oracle Sun Systems Products Suite (subcomponent: Firmware).   The supported version that is affected is Versions prior to 1.3.1.13. Easily exploitable vulnerability allows successful unauthenticated network attacks via SSL/TLS.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Switch ES1-24 accessible data as well as  read access to a subset of Oracle Switch ES1-24 accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-1793</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9889V-Versions prior to 1.3.1.13</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-9889V-Versions prior to 1.3.1.13</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="17" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-1793</Title>
      <Notes>
         <Note Audience="All" Ordinal="17" Title="Details" Type="Details">Vulnerability in the Sun Blade 6000 Ethernet Switched NEM 24P 10GE component of Oracle Sun Systems Products Suite (subcomponent: Firmware).   The supported version that is affected is Versions prior to 1.2.2.13. Easily exploitable vulnerability allows successful unauthenticated network attacks via SSL/TLS.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Sun Blade 6000 Ethernet Switched NEM 24P 10GE accessible data as well as  read access to a subset of Sun Blade 6000 Ethernet Switched NEM 24P 10GE accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-1793</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9889V-Versions prior to 1.2.2.13</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-9889V-Versions prior to 1.2.2.13</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="18" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-1793</Title>
      <Notes>
         <Note Audience="All" Ordinal="18" Title="Details" Type="Details">Vulnerability in the Sun Network 10GE Switch 72p component of Oracle Sun Systems Products Suite (subcomponent: Firmware).   The supported version that is affected is Versions prior to 1.2.2.15. Easily exploitable vulnerability allows successful unauthenticated network attacks via SSL/TLS.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Sun Network 10GE Switch 72p accessible data as well as  read access to a subset of Sun Network 10GE Switch 72p accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-1793</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9889V-Versions prior to 1.2.2.15</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-9889V-Versions prior to 1.2.2.15</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="19" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-1793</Title>
      <Notes>
         <Note Audience="All" Ordinal="19" Title="Details" Type="Details">Vulnerability in the Oracle Endeca Server component of Oracle Fusion Middleware (subcomponent: SSL/TLS).  Supported versions that are affected are 7.3.0.0, 7.4.0.0, 7.5.0.0 and  7.6.0.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTPS.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Endeca Server accessible data as well as  read access to a subset of Oracle Endeca Server accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-1793</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10217V-7.3.0.0</ProductID>
            <ProductID>P-10217V-7.4.0.0</ProductID>
            <ProductID>P-10217V-7.5.0.0</ProductID>
            <ProductID>P-10217V-7.6.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-10217V-7.3.0.0</ProductID>
            <ProductID>P-10217V-7.4.0.0</ProductID>
            <ProductID>P-10217V-7.5.0.0</ProductID>
            <ProductID>P-10217V-7.6.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="20" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-3153</Title>
      <Notes>
         <Note Audience="All" Ordinal="20" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Ops Center component of Oracle Enterprise Manager Grid Control (subcomponent: Networking).  Supported versions that are affected are Prior to 12.1.4, 12.2.0, 12.2.1 and  12.3.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Enterprise Manager Ops Center accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-3153</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9835V-Prior to 12.1.4</ProductID>
            <ProductID>P-9835V-12.2.0</ProductID>
            <ProductID>P-9835V-12.2.1</ProductID>
            <ProductID>P-9835V-12.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-9835V-Prior to 12.1.4</ProductID>
            <ProductID>P-9835V-12.2.0</ProductID>
            <ProductID>P-9835V-12.2.1</ProductID>
            <ProductID>P-9835V-12.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="21" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-3183</Title>
      <Notes>
         <Note Audience="All" Ordinal="21" Title="Details" Type="Details">Vulnerability in the Oracle Secure Global Desktop component of Oracle Virtualization (subcomponent: Apache HTTP Server).  Supported versions that are affected are 4.63, 4.71 and  5.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Secure Global Desktop accessible data.  CVSS Base Score 5.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-3183</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8539V-4.63</ProductID>
            <ProductID>P-8539V-4.71</ProductID>
            <ProductID>P-8539V-5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8539V-4.63</ProductID>
            <ProductID>P-8539V-4.71</ProductID>
            <ProductID>P-8539V-5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="22" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-3195</Title>
      <Notes>
         <Note Audience="All" Ordinal="22" Title="Details" Type="Details">Vulnerability in the Oracle HTTP Server component of Oracle E-Business Suite (subcomponent: Open SSL).   The supported version that is affected is 11.5.10.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HTTP Server.  CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-3195</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1745V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1745V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="23" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-4000</Title>
      <Notes>
         <Note Audience="All" Ordinal="23" Title="Details" Type="Details">Vulnerability in the Oracle Secure Global Desktop component of Oracle Virtualization (subcomponent: OpenSSL).  Supported versions that are affected are 4.63, 4.71 and  5.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via SSL/TLS.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Secure Global Desktop accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-4000</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8539V-4.63</ProductID>
            <ProductID>P-8539V-4.71</ProductID>
            <ProductID>P-8539V-5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8539V-4.63</ProductID>
            <ProductID>P-8539V-4.71</ProductID>
            <ProductID>P-8539V-5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="24" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-4808</Title>
      <Notes>
         <Note Audience="All" Ordinal="24" Title="Details" Type="Details">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.5.0, 8.5.1 and 8.5.2. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology.   Note: Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. If the hosting software passes data received over the network to Outside In Technology code, the CVSS Base Score would increase to 6.8. CVSS Base Score 1.9 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:M/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-4808</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>1.9</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="25" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-4885</Title>
      <Notes>
         <Note Audience="All" Ordinal="25" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Agent Next Gen).   The supported version that is affected is 12.1.0.4. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Enterprise Manager Base Platform accessible data.  CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-4885</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-12.1.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1370V-12.1.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="26" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-4919</Title>
      <Notes>
         <Note Audience="All" Ordinal="26" Title="Details" Type="Details">Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Monitoring and Diagnostics SEC).  Supported versions that are affected are 9.1 and  9.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized takeover of JD Edwards EnterpriseOne Tools possibly including arbitrary code execution within the JD Edwards EnterpriseOne Tools.  CVSS Base Score 6.8 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-4919</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4781V-9.1</ProductID>
            <ProductID>P-4781V-9.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-4781V-9.1</ProductID>
            <ProductID>P-4781V-9.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="27" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-4920</Title>
      <Notes>
         <Note Audience="All" Ordinal="27" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: NDMP Backup Service).   The supported version that is affected is 11. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Solaris accessible data.   Note: Unsupported Solaris 11.x versions should be upgraded to a supported release or patch set. Refer to the Critical Patch Update January 2015 Patch Availability Document for Oracle Sun Systems Products Suite. CVSS Base Score 2.1 (Integrity impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-4920</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="28" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-4921</Title>
      <Notes>
         <Note Audience="All" Ordinal="28" Title="Details" Type="Details">Vulnerability in the Database Vault component of Oracle Database Server.  This vulnerability requires Create Session privileges for a successful attack.  Supported versions that are affected are 11.2.0.4, 12.1.0.1 and 12.1.0.2. Easily exploitable vulnerability allows successful authenticated network attacks via Oracle Net.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Database Vault accessible data.  CVSS Base Score 4.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-4921</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.1</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.1</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="29" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-4922</Title>
      <Notes>
         <Note Audience="All" Ordinal="29" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Boot).   The supported version that is affected is 11. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Solaris.   Note: Unsupported Solaris 11.x versions should be upgraded to a supported release or patch set. Refer to the Critical Patch Update January 2015 Patch Availability Document for Oracle Sun Systems Products Suite. CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-4922</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="30" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-4923</Title>
      <Notes>
         <Note Audience="All" Ordinal="30" Title="Details" Type="Details">Vulnerability in the XML Developer's Kit for C component of Oracle Database Server.  This vulnerability requires Valid account privileges for a successful attack.  Supported versions that are affected are 11.2.0.4, 12.1.0.1 and 12.1.0.2. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of XML Developer's Kit for C.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-4923</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1068V-11.2.0.4</ProductID>
            <ProductID>P-1068V-12.1.0.1</ProductID>
            <ProductID>P-1068V-12.1.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1068V-11.2.0.4</ProductID>
            <ProductID>P-1068V-12.1.0.1</ProductID>
            <ProductID>P-1068V-12.1.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="31" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-4924</Title>
      <Notes>
         <Note Audience="All" Ordinal="31" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security).  Supported versions that are affected are 9.3.1.1, 9.3.1.2, 9.3.2 and  9.3.3. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Agile PLM accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-4924</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.1.1</ProductID>
            <ProductID>P-4461V-9.3.1.2</ProductID>
            <ProductID>P-4461V-9.3.2</ProductID>
            <ProductID>P-4461V-9.3.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-4461V-9.3.1.1</ProductID>
            <ProductID>P-4461V-9.3.1.2</ProductID>
            <ProductID>P-4461V-9.3.2</ProductID>
            <ProductID>P-4461V-9.3.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="32" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-4925</Title>
      <Notes>
         <Note Audience="All" Ordinal="32" Title="Details" Type="Details">Vulnerability in the Workspace Manager component of Oracle Database Server.  This vulnerability requires Create Session, Create Table, Create Procedure privileges for a successful attack.   The supported version that is affected is 11.2.0.4. Easily exploitable vulnerability allows successful authenticated network attacks via Oracle Net.  Successful attack of this vulnerability can result in unauthorized takeover of Workspace Manager possibly including arbitrary code execution within the Workspace Manager.  CVSS Base Score 6.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-4925</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1105V-11.2.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1105V-11.2.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="33" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-4926</Title>
      <Notes>
         <Note Audience="All" Ordinal="33" Title="Details" Type="Details">Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: UIX).  Supported versions that are affected are 11.5.10.2, 12.1 and  12.2. Very difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Applications Framework accessible data.  CVSS Base Score 2.6 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:H/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-4926</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1472V-11.5.10.2</ProductID>
            <ProductID>P-1472V-12.1</ProductID>
            <ProductID>P-1472V-12.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.6</BaseScore>
            <Vector>AV:N/AC:H/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1472V-11.5.10.2</ProductID>
            <ProductID>P-1472V-12.1</ProductID>
            <ProductID>P-1472V-12.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="34" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-5307</Title>
      <Notes>
         <Note Audience="All" Ordinal="34" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core).  Supported versions that are affected are VirtualBox prior to 4.0.36, prior to 4.1.44, prior to 4.2.36, prior to 4.3.34 and  prior to 5.0.10. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 4.9 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-5307</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-VirtualBox prior to 4.0.36</ProductID>
            <ProductID>P-8370V-prior to 4.1.44</ProductID>
            <ProductID>P-8370V-prior to 4.2.36</ProductID>
            <ProductID>P-8370V-prior to 4.3.34</ProductID>
            <ProductID>P-8370V-prior to 5.0.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.9</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8370V-VirtualBox prior to 4.0.36</ProductID>
            <ProductID>P-8370V-prior to 4.1.44</ProductID>
            <ProductID>P-8370V-prior to 4.2.36</ProductID>
            <ProductID>P-8370V-prior to 4.3.34</ProductID>
            <ProductID>P-8370V-prior to 5.0.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="35" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-6013</Title>
      <Notes>
         <Note Audience="All" Ordinal="35" Title="Details" Type="Details">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.5.0, 8.5.1 and  8.5.2. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology.   Note: Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. If the hosting software passes data received over the network to Outside In Technology code, the CVSS Base Score would increase to 6.8. CVSS Base Score 1.9 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:M/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-6013</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>1.9</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="36" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-6014</Title>
      <Notes>
         <Note Audience="All" Ordinal="36" Title="Details" Type="Details">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.5.0, 8.5.1 and  8.5.2. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology.   Note: Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. If the hosting software passes data received over the network to Outside In Technology code, the CVSS Base Score would increase to 6.8. CVSS Base Score 1.9 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:M/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-6014</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>1.9</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="37" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-6015</Title>
      <Notes>
         <Note Audience="All" Ordinal="37" Title="Details" Type="Details">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.5.0, 8.5.1 and  8.5.2. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology.   Note: Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. If the hosting software passes data received over the network to Outside In Technology code, the CVSS Base Score would increase to 6.8. CVSS Base Score 1.9 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:M/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-6015</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>1.9</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="38" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7183</Title>
      <Notes>
         <Note Audience="All" Ordinal="38" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core).  Supported versions that are affected are VirtualBox prior to 4.0.36, prior to 4.1.44, prior to 4.2.36, prior to 4.3.34 and  prior to 5.0.10. Easily exploitable vulnerability allows successful unauthenticated network attacks via SSL/TLS.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle VM VirtualBox accessible data as well as  read access to a subset of Oracle VM VirtualBox accessible data and ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox.  CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7183</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-VirtualBox prior to 4.0.36</ProductID>
            <ProductID>P-8370V-prior to 4.1.44</ProductID>
            <ProductID>P-8370V-prior to 4.2.36</ProductID>
            <ProductID>P-8370V-prior to 4.3.34</ProductID>
            <ProductID>P-8370V-prior to 5.0.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8370V-VirtualBox prior to 4.0.36</ProductID>
            <ProductID>P-8370V-prior to 4.1.44</ProductID>
            <ProductID>P-8370V-prior to 4.2.36</ProductID>
            <ProductID>P-8370V-prior to 4.3.34</ProductID>
            <ProductID>P-8370V-prior to 5.0.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="39" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7575</Title>
      <Notes>
         <Note Audience="All" Ordinal="39" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security).  Supported versions that are affected are Java SE: 6u105, 7u91 and  8u66; Java SE Embedded: 8u65; JRockit: R28.3.8. Very difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java SE, Java SE Embedded, JRockit accessible data as well as  read access to a subset of Java SE, Java SE Embedded, JRockit accessible data.   Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS Base Score 4.0 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:H/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7575</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 6u105</ProductID>
            <ProductID>P-856V-7u91</ProductID>
            <ProductID>P-856V-8u66; Java SE Embedded: 8u65; JRockit: R28.3.8</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-856V-Java SE: 6u105</ProductID>
            <ProductID>P-856V-7u91</ProductID>
            <ProductID>P-856V-8u66; Java SE Embedded: 8u65; JRockit: R28.3.8</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="40" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7744</Title>
      <Notes>
         <Note Audience="All" Ordinal="40" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encryption).  Supported versions that are affected are 5.5.45 and earlier and  5.6.26 and earlier. Very difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of MySQL Server accessible data.  CVSS Base Score 2.6 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:H/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7744</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.45 and earlier</ProductID>
            <ProductID>P-8478V-5.6.26 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.6</BaseScore>
            <Vector>AV:N/AC:H/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8478V-5.5.45 and earlier</ProductID>
            <ProductID>P-8478V-5.6.26 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="41" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-8104</Title>
      <Notes>
         <Note Audience="All" Ordinal="41" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core).  Supported versions that are affected are VirtualBox prior to 4.0.36, prior to 4.1.44, prior to 4.2.36, prior to 4.3.34 and  prior to 5.0.10. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 4.7 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:L/AC:M/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-8104</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-VirtualBox prior to 4.0.36</ProductID>
            <ProductID>P-8370V-prior to 4.1.44</ProductID>
            <ProductID>P-8370V-prior to 4.2.36</ProductID>
            <ProductID>P-8370V-prior to 4.3.34</ProductID>
            <ProductID>P-8370V-prior to 5.0.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.7</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8370V-VirtualBox prior to 4.0.36</ProductID>
            <ProductID>P-8370V-prior to 4.1.44</ProductID>
            <ProductID>P-8370V-prior to 4.2.36</ProductID>
            <ProductID>P-8370V-prior to 4.3.34</ProductID>
            <ProductID>P-8370V-prior to 5.0.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="42" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-8126</Title>
      <Notes>
         <Note Audience="All" Ordinal="42" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: AWT).  Supported versions that are affected are Java SE: 6u105, 7u91 and  8u66; Java SE Embedded: 8u65. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-8126</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 6u105</ProductID>
            <ProductID>P-856V-7u91</ProductID>
            <ProductID>P-856V-8u66; Java SE Embedded: 8u65</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-856V-Java SE: 6u105</ProductID>
            <ProductID>P-856V-7u91</ProductID>
            <ProductID>P-856V-8u66; Java SE Embedded: 8u65</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="43" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-8370</Title>
      <Notes>
         <Note Audience="All" Ordinal="43" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Grub2).   The supported version that is affected is 11. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.  CVSS Base Score 6.9 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:L/AC:M/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-8370</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.9</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="44" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0401</Title>
      <Notes>
         <Note Audience="All" Ordinal="44" Title="Details" Type="Details">Vulnerability in the Oracle BI Publisher component of Oracle Fusion Middleware (subcomponent: Scheduler).  Supported versions that are affected are 11.1.1.7.0 and  11.1.1.9.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle BI Publisher accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0401</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1479V-11.1.1.7.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1479V-11.1.1.7.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="45" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0402</Title>
      <Notes>
         <Note Audience="All" Ordinal="45" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking).  Supported versions that are affected are Java SE: 6u105, 7u91 and  8u66; Java SE Embedded: 8u65. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java SE, Java SE Embedded accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 5.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0402</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 6u105</ProductID>
            <ProductID>P-856V-7u91</ProductID>
            <ProductID>P-856V-8u66; Java SE Embedded: 8u65</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-856V-Java SE: 6u105</ProductID>
            <ProductID>P-856V-7u91</ProductID>
            <ProductID>P-856V-8u66; Java SE Embedded: 8u65</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="46" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0403</Title>
      <Notes>
         <Note Audience="All" Ordinal="46" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: SMB Utilities).   The supported version that is affected is 11. Easily exploitable vulnerability allows successful unauthenticated network attacks via SMB.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).   Note: Unsupported Solaris 11.x versions should be upgraded to a supported release or patch set. Refer to the Critical Patch Update January 2015 Patch Availability Document for Oracle Sun Systems Products Suite. CVSS Base Score 7.8 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0403</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.8</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="47" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0404</Title>
      <Notes>
         <Note Audience="All" Ordinal="47" Title="Details" Type="Details">Vulnerability in the Oracle Identity Federation component of Oracle Fusion Middleware (subcomponent: Admin).   The supported version that is affected is 11.1.2.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Identity Federation accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0404</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1741V-11.1.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1741V-11.1.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="48" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0405</Title>
      <Notes>
         <Note Audience="All" Ordinal="48" Title="Details" Type="Details">Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: Cluster Manageability and Serviceability).  Supported versions that are affected are 3.3 and  4. Easily exploitable vulnerability requiring logon to Operating System plus additional login/authentication to component or subcomponent.  Successful attack of this vulnerability can escalate attacker privileges resulting in unauthorized  read access to a subset of Solaris Cluster accessible data.  CVSS Base Score 1.7 (Confidentiality impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:L/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0405</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10005V-3.3</ProductID>
            <ProductID>P-10005V-4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>1.7</BaseScore>
            <Vector>AV:L/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-10005V-3.3</ProductID>
            <ProductID>P-10005V-4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="49" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0406</Title>
      <Notes>
         <Note Audience="All" Ordinal="49" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Libc Library).   The supported version that is affected is 11. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Solaris accessible data and ability to cause a partial denial of service (partial DOS) of Solaris.  CVSS Base Score 3.3 (Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:N/I:P/A:P).  Oracle Vector: (AV:L/AC:M/Au:N/C:N/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0406</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.3</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:N/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="50" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0409</Title>
      <Notes>
         <Note Audience="All" Ordinal="50" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Switzerland component of Oracle PeopleSoft Products (subcomponent: Security).  Supported versions that are affected are 9.1 and  9.2. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of PeopleSoft Enterprise HCM Global Payroll Switzerland accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0409</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5068V-9.1</ProductID>
            <ProductID>P-5068V-9.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-5068V-9.1</ProductID>
            <ProductID>P-5068V-9.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="51" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0411</Title>
      <Notes>
         <Note Audience="All" Ordinal="51" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Agent Next Gen).  Supported versions that are affected are 11.1.0.1 and 
11.2.0.4. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized takeover of Enterprise Manager Base Platform possibly including arbitrary code execution within the Enterprise Manager Base Platform.  CVSS Base Score 4.6 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0411</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-11.1.0.1</ProductID>
            <ProductID>P-1370V-11.2.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.6</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1370V-11.1.0.1</ProductID>
            <ProductID>P-1370V-11.2.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="52" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0412</Title>
      <Notes>
         <Note Audience="All" Ordinal="52" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise SCM eProcurement component of Oracle PeopleSoft Products (subcomponent: Manage Requisition Status).  Supported versions that are affected are 9.1 and  9.2. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some PeopleSoft Enterprise SCM eProcurement accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0412</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5118V-9.1</ProductID>
            <ProductID>P-5118V-9.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-5118V-9.1</ProductID>
            <ProductID>P-5118V-9.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="53" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0413</Title>
      <Notes>
         <Note Audience="All" Ordinal="53" Title="Details" Type="Details">Vulnerability in the Oracle Identity Federation component of Oracle Fusion Middleware (subcomponent: Federation protocol support).   The supported version that is affected is 11.1.1.7. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Identity Federation accessible data.  CVSS Base Score 4.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0413</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1741V-11.1.1.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1741V-11.1.1.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="54" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0414</Title>
      <Notes>
         <Note Audience="All" Ordinal="54" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Solaris Kernel Zones).   The supported version that is affected is 11. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Unsupported Solaris 11.x versions should be upgraded to a supported release or patch set. Refer to the Critical Patch Update January 2015 Patch Availability Document for Oracle Sun Systems Products Suite. CVSS Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:L/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0414</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.2</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="55" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0415</Title>
      <Notes>
         <Note Audience="All" Ordinal="55" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: UI Framework).  Supported versions that are affected are 11.1.0.1, 
12.1.0.4 and 
12.1.0.5. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Enterprise Manager Base Platform accessible data as well as  read access to a subset of Enterprise Manager Base Platform accessible data and ability to cause a partial denial of service (partial DOS) of Enterprise Manager Base Platform.  CVSS Base Score 6.8 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0415</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-11.1.0.1</ProductID>
            <ProductID>P-1370V-12.1.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1370V-11.1.0.1</ProductID>
            <ProductID>P-1370V-12.1.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="56" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0416</Title>
      <Notes>
         <Note Audience="All" Ordinal="56" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: System Archive Utility).   The supported version that is affected is 11. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Solaris accessible data.   Note: Unsupported Solaris 11.x versions should be upgraded to a supported release or patch set. Refer to the Critical Patch Update January 2015 Patch Availability Document for Oracle Sun Systems Products Suite. CVSS Base Score 5.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0416</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="57" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0417</Title>
      <Notes>
         <Note Audience="All" Ordinal="57" Title="Details" Type="Details">Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: HA for MySQL).  Supported versions that are affected are 3.3 and  4.2. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Solaris Cluster accessible data as well as  read access to a subset of Solaris Cluster accessible data and ability to cause a partial denial of service (partial DOS) of Solaris Cluster.  CVSS Base Score 4.6 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0417</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10005V-3.3</ProductID>
            <ProductID>P-10005V-4.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.6</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-10005V-3.3</ProductID>
            <ProductID>P-10005V-4.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="58" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0418</Title>
      <Notes>
         <Note Audience="All" Ordinal="58" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Solaris Kernel Zones).   The supported version that is affected is 11. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS) as well as  update, insert or delete access to some Solaris accessible data and  read access to a subset of Solaris accessible data.   Note: Unsupported Solaris 11.x versions should be upgraded to a supported release or patch set. Refer to the Critical Patch Update January 2015 Patch Availability Document for Oracle Sun Systems Products Suite. CVSS Base Score 6.1 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:P/I:P/A:C).  Oracle Vector: (AV:L/AC:L/Au:N/C:P/I:P/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0418</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:P/I:P/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="59" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0419</Title>
      <Notes>
         <Note Audience="All" Ordinal="59" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Solaris Kernel Zones).   The supported version that is affected is 11. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).   Note: Unsupported Solaris 11.x versions should be upgraded to a supported release or patch set. Refer to the Critical Patch Update January 2015 Patch Availability Document for Oracle Sun Systems Products Suite. CVSS Base Score 4.9 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0419</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.9</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="60" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0420</Title>
      <Notes>
         <Note Audience="All" Ordinal="60" Title="Details" Type="Details">Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Monitoring and Diagnostics).  Supported versions that are affected are 9.1 and  9.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 7.8 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0420</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4781V-9.1</ProductID>
            <ProductID>P-4781V-9.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.8</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-4781V-9.1</ProductID>
            <ProductID>P-4781V-9.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="61" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0421</Title>
      <Notes>
         <Note Audience="All" Ordinal="61" Title="Details" Type="Details">Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Monitoring and Diagnostics SEC).  Supported versions that are affected are 9.1 and  9.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools.  CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0421</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4781V-9.1</ProductID>
            <ProductID>P-4781V-9.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-4781V-9.1</ProductID>
            <ProductID>P-4781V-9.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="62" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0422</Title>
      <Notes>
         <Note Audience="All" Ordinal="62" Title="Details" Type="Details">Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Enterprise Infrastructure SEC).  Supported versions that are affected are 9.1 and  9.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 7.1 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0422</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4781V-9.1</ProductID>
            <ProductID>P-4781V-9.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.1</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-4781V-9.1</ProductID>
            <ProductID>P-4781V-9.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="63" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0423</Title>
      <Notes>
         <Note Audience="All" Ordinal="63" Title="Details" Type="Details">Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Enterprise Infrastructure SEC).  Supported versions that are affected are 9.1 and  9.2. Very difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  write access to any arbitrary Operating System location as well as  read access to any arbitrary Operating System location and ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools.  CVSS Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:N/C:C/I:C/A:P).  Oracle Vector: (AV:N/AC:H/Au:N/C:C/I:C/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0423</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4781V-9.1</ProductID>
            <ProductID>P-4781V-9.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.3</BaseScore>
            <Vector>AV:N/AC:H/Au:N/C:C/I:C/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-4781V-9.1</ProductID>
            <ProductID>P-4781V-9.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="64" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0424</Title>
      <Notes>
         <Note Audience="All" Ordinal="64" Title="Details" Type="Details">Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Enterprise Infrastructure SEC).  Supported versions that are affected are 9.1 and  9.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 7.1 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0424</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4781V-9.1</ProductID>
            <ProductID>P-4781V-9.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.1</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-4781V-9.1</ProductID>
            <ProductID>P-4781V-9.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="65" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0425</Title>
      <Notes>
         <Note Audience="All" Ordinal="65" Title="Details" Type="Details">Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Monitoring and Diagnostics).  Supported versions that are affected are 9.1 and  9.2. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized takeover of JD Edwards EnterpriseOne Tools possibly including arbitrary code execution within the JD Edwards EnterpriseOne Tools.  CVSS Base Score 6.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:M/Au:S/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0425</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4781V-9.1</ProductID>
            <ProductID>P-4781V-9.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.0</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-4781V-9.1</ProductID>
            <ProductID>P-4781V-9.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="66" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0426</Title>
      <Notes>
         <Note Audience="All" Ordinal="66" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Solaris Kernel Zones).   The supported version that is affected is 11. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Solaris accessible data and ability to cause a partial denial of service (partial DOS) of Solaris.   Note: Unsupported Solaris 11.x versions should be upgraded to a supported release or patch set. Refer to the Critical Patch Update January 2015 Patch Availability Document for Oracle Sun Systems Products Suite. CVSS Base Score 3.6 (Confidentiality and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:P/I:N/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:P/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0426</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.6</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:P/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="67" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0427</Title>
      <Notes>
         <Note Audience="All" Ordinal="67" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: UI Framework).  Supported versions that are affected are 11.1.0.1, 
11.2.0.4, 
12.1.0.4 and 
12.1.0.5. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Enterprise Manager Base Platform accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0427</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-11.1.0.1</ProductID>
            <ProductID>P-1370V-11.2.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1370V-11.1.0.1</ProductID>
            <ProductID>P-1370V-11.2.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="68" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0428</Title>
      <Notes>
         <Note Audience="All" Ordinal="68" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Verified Boot).   The supported version that is affected is 11. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).   Note: Unsupported Solaris 11.x versions should be upgraded to a supported release or patch set. Refer to the Critical Patch Update January 2015 Patch Availability Document for Oracle Sun Systems Products Suite. CVSS Base Score 4.9 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0428</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.9</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="69" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0429</Title>
      <Notes>
         <Note Audience="All" Ordinal="69" Title="Details" Type="Details">Vulnerability in the Oracle BI Publisher component of Oracle Fusion Middleware (subcomponent: Scheduler).  Supported versions that are affected are 11.1.1.7.0 and  11.1.1.9.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle BI Publisher accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0429</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1479V-11.1.1.7.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1479V-11.1.1.7.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="70" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0430</Title>
      <Notes>
         <Note Audience="All" Ordinal="70" Title="Details" Type="Details">Vulnerability in the Web Cache component of Oracle Fusion Middleware (subcomponent: SSL Support).  Supported versions that are affected are 11.1.1.7.0 and 11.1.1.9.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTPS.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Web Cache accessible data.  CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0430</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1059V-11.1.1.7.0</ProductID>
            <ProductID>P-1059V-11.1.1.9.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1059V-11.1.1.7.0</ProductID>
            <ProductID>P-1059V-11.1.1.9.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="71" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0431</Title>
      <Notes>
         <Note Audience="All" Ordinal="71" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Solaris Kernel Zones).   The supported version that is affected is 11. Very difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Solaris.   Note: Unsupported Solaris 11.x versions should be upgraded to a supported release or patch set. Refer to the Critical Patch Update January 2015 Patch Availability Document for Oracle Sun Systems Products Suite. CVSS Base Score 1.2 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:H/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:H/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0431</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>1.2</BaseScore>
            <Vector>AV:L/AC:H/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="72" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0432</Title>
      <Notes>
         <Note Audience="All" Ordinal="72" Title="Details" Type="Details">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.5.0, 8.5.1 and  8.5.2. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology.   Note: Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. If the hosting software passes data received over the network to Outside In Technology code, the CVSS Base Score would increase to 6.8. CVSS Base Score 1.9 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:M/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0432</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>1.9</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-2276V-8.5.0</ProductID>
            <ProductID>P-2276V-8.5.1</ProductID>
            <ProductID>P-2276V-8.5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="73" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0433</Title>
      <Notes>
         <Note Audience="All" Ordinal="73" Title="Details" Type="Details">Vulnerability in the Web Cache component of Oracle Fusion Middleware (subcomponent: SSL Support).   The supported version that is affected is 11.1.1.9.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTPS.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Web Cache accessible data.  CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0433</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1059V-11.1.1.9.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1059V-11.1.1.9.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="74" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0434</Title>
      <Notes>
         <Note Audience="All" Ordinal="74" Title="Details" Type="Details">Vulnerability in the Oracle Retail Point-of-Service component of Oracle Retail Applications (subcomponent: Mobile POS).  Supported versions that are affected are 13.4, 
14.0 and 
14.1. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Retail Point-of-Service accessible data.  CVSS Base Score 1.9 (Confidentiality impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:L/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0434</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2017V-13.4</ProductID>
            <ProductID>P-2017V-14.0</ProductID>
            <ProductID>P-2017V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>1.9</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-2017V-13.4</ProductID>
            <ProductID>P-2017V-14.0</ProductID>
            <ProductID>P-2017V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="75" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0435</Title>
      <Notes>
         <Note Audience="All" Ordinal="75" Title="Details" Type="Details">Vulnerability in the Oracle Retail Point-of-Service component of Oracle Retail Applications (subcomponent: Mobile POS).  Supported versions that are affected are 13.4, 
14.0 and 
14.1. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Retail Point-of-Service accessible data as well as  read access to all Oracle Retail Point-of-Service accessible data.  CVSS Base Score 3.3 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:L/AC:M/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0435</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2017V-13.4</ProductID>
            <ProductID>P-2017V-14.0</ProductID>
            <ProductID>P-2017V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.3</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-2017V-13.4</ProductID>
            <ProductID>P-2017V-14.0</ProductID>
            <ProductID>P-2017V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="76" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0436</Title>
      <Notes>
         <Note Audience="All" Ordinal="76" Title="Details" Type="Details">Vulnerability in the Oracle Retail Point-of-Service component of Oracle Retail Applications (subcomponent: Mobile POS).  Supported versions that are affected are 13.4, 
14.0 and 
14.1. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Retail Point-of-Service accessible data.  CVSS Base Score 1.9 (Confidentiality impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:L/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0436</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2017V-13.4</ProductID>
            <ProductID>P-2017V-14.0</ProductID>
            <ProductID>P-2017V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>1.9</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-2017V-13.4</ProductID>
            <ProductID>P-2017V-14.0</ProductID>
            <ProductID>P-2017V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="77" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0437</Title>
      <Notes>
         <Note Audience="All" Ordinal="77" Title="Details" Type="Details">Vulnerability in the Oracle Retail Point-of-Service component of Oracle Retail Applications (subcomponent: Mobile POS).  Supported versions that are affected are 13.4, 
14.0 and 
14.1. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Retail Point-of-Service accessible data.  CVSS Base Score 1.9 (Confidentiality impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:L/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0437</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2017V-13.4</ProductID>
            <ProductID>P-2017V-14.0</ProductID>
            <ProductID>P-2017V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>1.9</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-2017V-13.4</ProductID>
            <ProductID>P-2017V-14.0</ProductID>
            <ProductID>P-2017V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="78" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0438</Title>
      <Notes>
         <Note Audience="All" Ordinal="78" Title="Details" Type="Details">Vulnerability in the Oracle Retail Point-of-Service component of Oracle Retail Applications (subcomponent: Mobile POS).  Supported versions that are affected are 13.4, 
14.0 and 
14.1. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Retail Point-of-Service accessible data.  CVSS Base Score 1.9 (Confidentiality impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:L/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0438</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2017V-13.4</ProductID>
            <ProductID>P-2017V-14.0</ProductID>
            <ProductID>P-2017V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>1.9</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-2017V-13.4</ProductID>
            <ProductID>P-2017V-14.0</ProductID>
            <ProductID>P-2017V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="79" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0439</Title>
      <Notes>
         <Note Audience="All" Ordinal="79" Title="Details" Type="Details">Vulnerability in the Web Cache component of Oracle Fusion Middleware (subcomponent: SSL Support).  Supported versions that are affected are 11.1.1.7.0 and 11.1.1.9.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTPS.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Web Cache accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0439</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1059V-11.1.1.7.0</ProductID>
            <ProductID>P-1059V-11.1.1.9.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1059V-11.1.1.7.0</ProductID>
            <ProductID>P-1059V-11.1.1.9.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="80" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0440</Title>
      <Notes>
         <Note Audience="All" Ordinal="80" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: NFSv4).   The supported version that is affected is 11. Easily exploitable vulnerability allows successful unauthenticated network attacks via NFS.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 7.8 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0440</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.8</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="81" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0441</Title>
      <Notes>
         <Note Audience="All" Ordinal="81" Title="Details" Type="Details">Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Embedded Server).   The supported version that is affected is 3.1.2. Very difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  write access to any arbitrary Operating System location as well as  read access to any arbitrary Operating System location and ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GlassFish Server.  CVSS Base Score 6.8 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:S/C:C/I:C/A:P).  Oracle Vector: (AV:N/AC:H/Au:S/C:C/I:C/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0441</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8493V-3.1.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.8</BaseScore>
            <Vector>AV:N/AC:H/Au:S/C:C/I:C/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8493V-3.1.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="82" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0442</Title>
      <Notes>
         <Note Audience="All" Ordinal="82" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Loader Service).  Supported versions that are affected are 12.1.0.4 and   12.1.0.5. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Enterprise Manager Base Platform as well as  update, insert or delete access to some Enterprise Manager Base Platform accessible data and  read access to a subset of Enterprise Manager Base Platform accessible data.  CVSS Base Score 6.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0442</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-12.1.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1370V-12.1.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="83" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0443</Title>
      <Notes>
         <Note Audience="All" Ordinal="83" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Agent Next Gen).  Supported versions that are affected are 11.1.0.1, 
12.1.0.4 and 
12.1.0.5. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to all Enterprise Manager Base Platform accessible data.  CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P+/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0443</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-11.1.0.1</ProductID>
            <ProductID>P-1370V-12.1.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1370V-11.1.0.1</ProductID>
            <ProductID>P-1370V-12.1.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="84" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0444</Title>
      <Notes>
         <Note Audience="All" Ordinal="84" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Agent Next Gen).  Supported versions that are affected are 11.1.0.1, 
11.2.0.4, 
12.1.0.4 and 
12.1.0.5. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  read access to all Enterprise Manager Base Platform accessible data as well as  update, insert or delete access to some Enterprise Manager Base Platform accessible data and ability to cause a partial denial of service (partial DOS) of Enterprise Manager Base Platform.  CVSS Base Score 4.4 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:L/AC:M/Au:N/C:P+/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0444</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-11.1.0.1</ProductID>
            <ProductID>P-1370V-11.2.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.4</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1370V-11.1.0.1</ProductID>
            <ProductID>P-1370V-11.2.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="85" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0445</Title>
      <Notes>
         <Note Audience="All" Ordinal="85" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Agent Next Gen).  Supported versions that are affected are 11.1.0.1, 
11.2.0.4, 
12.1.0.4, 
12.1.0.5 and . Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized takeover of Enterprise Manager Base Platform possibly including arbitrary code execution within the Enterprise Manager Base Platform.  CVSS Base Score 4.6 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0445</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-11.1.0.1</ProductID>
            <ProductID>P-1370V-11.2.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.6</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1370V-11.1.0.1</ProductID>
            <ProductID>P-1370V-11.2.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="86" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0446</Title>
      <Notes>
         <Note Audience="All" Ordinal="86" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform  component of Oracle Enterprise Manager Grid Control (subcomponent: Agent Next Gen).  Supported versions that are affected are 11.1.0.1, 
11.2.0.4, 
12.1.0.4 and 
12.1.0.5. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  read access to all Enterprise Manager Base Platform  accessible data.  CVSS Base Score 2.1 (Confidentiality impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:L/AC:L/Au:N/C:P+/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0446</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-11.1.0.1</ProductID>
            <ProductID>P-1370V-11.2.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1370V-11.1.0.1</ProductID>
            <ProductID>P-1370V-11.2.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="87" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0447</Title>
      <Notes>
         <Note Audience="All" Ordinal="87" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Agent Next Gen).  Supported versions that are affected are 11.1.0.1, 
11.2.0.4, 
12.1.0.4 and 
12.1.0.5. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Enterprise Manager Base Platform accessible data as well as  read access to a subset of Enterprise Manager Base Platform accessible data and ability to cause a partial denial of service (partial DOS) of Enterprise Manager Base Platform.  CVSS Base Score 4.6 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0447</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-11.1.0.1</ProductID>
            <ProductID>P-1370V-11.2.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.6</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1370V-11.1.0.1</ProductID>
            <ProductID>P-1370V-11.2.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="88" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0448</Title>
      <Notes>
         <Note Audience="All" Ordinal="88" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JMX).  Supported versions that are affected are Java SE: 6u105, 7u91 and  8u66; Java SE Embedded: 8u65. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Java SE, Java SE Embedded accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0448</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 6u105</ProductID>
            <ProductID>P-856V-7u91</ProductID>
            <ProductID>P-856V-8u66; Java SE Embedded: 8u65</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-856V-Java SE: 6u105</ProductID>
            <ProductID>P-856V-7u91</ProductID>
            <ProductID>P-856V-8u66; Java SE Embedded: 8u65</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="89" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0449</Title>
      <Notes>
         <Note Audience="All" Ordinal="89" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform  component of Oracle Enterprise Manager Grid Control (subcomponent: Agent Next Gen).  Supported versions that are affected are 11.1.0.1, 
11.2.0.4, 
12.1.0.4 and 
12.1.0.5. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Enterprise Manager Base Platform  accessible data as well as  read access to a subset of Enterprise Manager Base Platform  accessible data and ability to cause a partial denial of service (partial DOS) of Enterprise Manager Base Platform .  CVSS Base Score 4.6 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0449</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-11.1.0.1</ProductID>
            <ProductID>P-1370V-11.2.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.6</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1370V-11.1.0.1</ProductID>
            <ProductID>P-1370V-11.2.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="90" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0450</Title>
      <Notes>
         <Note Audience="All" Ordinal="90" Title="Details" Type="Details">Vulnerability in the Oracle GoldenGate component of Oracle GoldenGate.  Supported versions that are affected are 11.2 and  12.1.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via Oracle Golden Gate.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GoldenGate.  CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0450</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5757V-11.2</ProductID>
            <ProductID>P-5757V-12.1.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-5757V-11.2</ProductID>
            <ProductID>P-5757V-12.1.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="91" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0451</Title>
      <Notes>
         <Note Audience="All" Ordinal="91" Title="Details" Type="Details">Vulnerability in the Oracle GoldenGate component of Oracle GoldenGate.  Supported versions that are affected are 11.2 and  12.1.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via Oracle Golden Gate.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: The CVSS score is 10.0 only on Windows for Database versions prior to 12c. The CVSS is 7.5 (Confidentiality, Integrity and Availability is "Partial+") for Database 12c on Windows and for all versions of Database on Linux, Unix and other platforms. CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0451</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5757V-11.2</ProductID>
            <ProductID>P-5757V-12.1.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-5757V-11.2</ProductID>
            <ProductID>P-5757V-12.1.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="92" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0452</Title>
      <Notes>
         <Note Audience="All" Ordinal="92" Title="Details" Type="Details">Vulnerability in the Oracle GoldenGate component of Oracle GoldenGate.  Supported versions that are affected are 11.2 and  12.1.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via Oracle Golden Gate.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: The CVSS score is 10.0 only on Windows for Database versions prior to 12c. The CVSS is 7.5 (Confidentiality, Integrity and Availability is "Partial+") for Database 12c on Windows and for all versions of Database on Linux, Unix and other platforms. CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0452</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5757V-11.2</ProductID>
            <ProductID>P-5757V-12.1.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-5757V-11.2</ProductID>
            <ProductID>P-5757V-12.1.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="93" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0453</Title>
      <Notes>
         <Note Audience="All" Ordinal="93" Title="Details" Type="Details">Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Embedded Server).   The supported version that is affected is 3.1.2. Very difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP, but can only be launched from an adjacent network.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle GlassFish Server accessible data.  CVSS Base Score 1.8 (Integrity impacts).  CVSS V2 Vector: (AV:A/AC:H/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:A/AC:H/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0453</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8493V-3.1.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>1.8</BaseScore>
            <Vector>AV:A/AC:H/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8493V-3.1.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="94" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0454</Title>
      <Notes>
         <Note Audience="All" Ordinal="94" Title="Details" Type="Details">Vulnerability in the Oracle Mobile Application Servlet component of Oracle E-Business Suite (subcomponent: MWA Server Manager).  Supported versions that are affected are 12.1 and  12.2. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Mobile Application Servlet accessible data.  CVSS Base Score 2.1 (Confidentiality impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:L/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0454</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-995V-12.1</ProductID>
            <ProductID>P-995V-12.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-995V-12.1</ProductID>
            <ProductID>P-995V-12.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="95" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0455</Title>
      <Notes>
         <Note Audience="All" Ordinal="95" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Agent Next Gen).  Supported versions that are affected are 11.1.0.1, 
11.2.0.4, 
12.1.0.4 and 
12.1.0.5. Easily exploitable vulnerability requiring logon to Operating System plus additional login/authentication to component or subcomponent.  Successful attack of this vulnerability can escalate attacker privileges resulting in unauthorized  read access to any arbitrary Operating System location and ability to cause a partial denial of service (partial DOS) of Enterprise Manager Base Platform.  CVSS Base Score 5.2 (Confidentiality and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:S/C:C/I:N/A:P).  Oracle Vector: (AV:L/AC:L/Au:S/C:C/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0455</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-11.1.0.1</ProductID>
            <ProductID>P-1370V-11.2.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.2</BaseScore>
            <Vector>AV:L/AC:L/Au:S/C:C/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1370V-11.1.0.1</ProductID>
            <ProductID>P-1370V-11.2.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.4</ProductID>
            <ProductID>P-1370V-12.1.0.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="96" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0456</Title>
      <Notes>
         <Note Audience="All" Ordinal="96" Title="Details" Type="Details">Vulnerability in the Application Mgmt Pack for E-Business Suite component of Oracle E-Business Suite (subcomponent: REST Framework).  Supported versions that are affected are 12.1 and  12.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Application Mgmt Pack for E-Business Suite accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0456</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2294V-12.1</ProductID>
            <ProductID>P-2294V-12.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-2294V-12.1</ProductID>
            <ProductID>P-2294V-12.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="97" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0457</Title>
      <Notes>
         <Note Audience="All" Ordinal="97" Title="Details" Type="Details">Vulnerability in the Application Mgmt Pack for E-Business Suite component of Oracle E-Business Suite (subcomponent: REST Framework).  Supported versions that are affected are 12.1 and  12.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Application Mgmt Pack for E-Business Suite accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0457</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2294V-12.1</ProductID>
            <ProductID>P-2294V-12.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-2294V-12.1</ProductID>
            <ProductID>P-2294V-12.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="98" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0458</Title>
      <Notes>
         <Note Audience="All" Ordinal="98" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel DAX).   The supported version that is affected is 11. Very difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:H/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:L/AC:H/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0458</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:L/AC:H/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="99" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0459</Title>
      <Notes>
         <Note Audience="All" Ordinal="99" Title="Details" Type="Details">Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: Popup Windows).  Supported versions that are affected are 11.5.10.2, 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Applications Framework accessible data.  CVSS Base Score 4.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0459</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1472V-11.5.10.2</ProductID>
            <ProductID>P-1472V-12.1.3</ProductID>
            <ProductID>P-1472V-12.2.3</ProductID>
            <ProductID>P-1472V-12.2.4</ProductID>
            <ProductID>P-1472V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1472V-11.5.10.2</ProductID>
            <ProductID>P-1472V-12.1.3</ProductID>
            <ProductID>P-1472V-12.2.3</ProductID>
            <ProductID>P-1472V-12.2.4</ProductID>
            <ProductID>P-1472V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="100" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0460</Title>
      <Notes>
         <Note Audience="All" Ordinal="100" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Fluid Homepage and NavBar).   The supported version that is affected is 8.55. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 5.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0460</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.55</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-5085V-8.55</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="101" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0461</Title>
      <Notes>
         <Note Audience="All" Ordinal="101" Title="Details" Type="Details">Vulnerability in the XDB - XML Database component of Oracle Database Server.  This vulnerability requires Create Session privileges for a successful attack.  Supported versions that are affected are 11.2.0.4, 12.1.0.1 and 12.1.0.2. Easily exploitable vulnerability allows successful authenticated network attacks via Oracle Net.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of XDB - XML Database.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0461</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.1</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.1</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="102" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0462</Title>
      <Notes>
         <Note Audience="All" Ordinal="102" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Multichannel Framework).  Supported versions that are affected are 8.53 and  8.54. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0462</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.53</ProductID>
            <ProductID>P-5085V-8.54</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-5085V-8.53</ProductID>
            <ProductID>P-5085V-8.54</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="103" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0463</Title>
      <Notes>
         <Note Audience="All" Ordinal="103" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Portal).  Supported versions that are affected are 8.53, 8.54 and  8.55. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0463</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.53</ProductID>
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-5085V-8.53</ProductID>
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="104" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0464</Title>
      <Notes>
         <Note Audience="All" Ordinal="104" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS-Console).  Supported versions that are affected are 10.3.6, 12.1.2 and  12.1.3. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle WebLogic Server accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0464</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.3.6</ProductID>
            <ProductID>P-5242V-12.1.2</ProductID>
            <ProductID>P-5242V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-5242V-10.3.6</ProductID>
            <ProductID>P-5242V-12.1.2</ProductID>
            <ProductID>P-5242V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="105" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0465</Title>
      <Notes>
         <Note Audience="All" Ordinal="105" Title="Details" Type="Details">Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: Resource Group Manager).  Supported versions that are affected are 3.3 and  4. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 4.9 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0465</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10005V-3.3</ProductID>
            <ProductID>P-10005V-4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.9</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-10005V-3.3</ProductID>
            <ProductID>P-10005V-4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="106" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0466</Title>
      <Notes>
         <Note Audience="All" Ordinal="106" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAXP).  Supported versions that are affected are Java SE: 6u105, 7u91 and  8u66; Java SE Embedded: 8u65; JRockit: R28.3.8. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit.   Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0466</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 6u105</ProductID>
            <ProductID>P-856V-7u91</ProductID>
            <ProductID>P-856V-8u66; Java SE Embedded: 8u65; JRockit: R28.3.8</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-856V-Java SE: 6u105</ProductID>
            <ProductID>P-856V-7u91</ProductID>
            <ProductID>P-856V-8u66; Java SE Embedded: 8u65; JRockit: R28.3.8</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="107" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0467</Title>
      <Notes>
         <Note Audience="All" Ordinal="107" Title="Details" Type="Details">Vulnerability in the Security component of Oracle Database Server.  This vulnerability requires Create Session, Create Java Source privileges for a successful attack.  Supported versions that are affected are 11.2.0.4, 12.1.0.1 and 12.1.0.2. Easily exploitable vulnerability allows successful authenticated network attacks via Oracle Net.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Security accessible data.  CVSS Base Score 4.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0467</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.1</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.1</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="108" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0470</Title>
      <Notes>
         <Note Audience="All" Ordinal="108" Title="Details" Type="Details">Vulnerability in the Oracle BI Publisher component of Oracle Fusion Middleware (subcomponent: BI Publisher Security).  Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0 and 12.2.1.0.0. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle BI Publisher accessible data as well as  read access to a subset of Oracle BI Publisher accessible data.  CVSS Base Score 5.5 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0470</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1479V-11.1.1.7.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
            <ProductID>P-1479V-12.2.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1479V-11.1.1.7.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
            <ProductID>P-1479V-12.2.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="109" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0471</Title>
      <Notes>
         <Note Audience="All" Ordinal="109" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Multichannel Framework).  Supported versions that are affected are 8.53 and  8.54. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0471</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.53</ProductID>
            <ProductID>P-5085V-8.54</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-5085V-8.53</ProductID>
            <ProductID>P-5085V-8.54</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="110" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0472</Title>
      <Notes>
         <Note Audience="All" Ordinal="110" Title="Details" Type="Details">Vulnerability in the XDB - XML Database component of Oracle Database Server.  This vulnerability requires Create Session privileges for a successful attack.  Supported versions that are affected are 11.2.0.4, 12.1.0.1 and 12.1.0.2. Easily exploitable vulnerability allows successful authenticated network attacks via Oracle Net.  Successful attack of this vulnerability can result in unauthorized  read access to all XDB - XML Database accessible data and ability to cause a partial denial of service (partial DOS) of XDB - XML Database.  CVSS Base Score 5.5 (Confidentiality and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:P+/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0472</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.1</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.1</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="111" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0473</Title>
      <Notes>
         <Note Audience="All" Ordinal="111" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Fluid Core).  Supported versions that are affected are 8.54 and  8.55. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0473</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="112" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0474</Title>
      <Notes>
         <Note Audience="All" Ordinal="112" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: PIA Core Technology).  Supported versions that are affected are 8.54 and  8.55. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0474</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="113" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0475</Title>
      <Notes>
         <Note Audience="All" Ordinal="113" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries).   The supported version that is affected is Java SE: 8u66; Java SE Embedded: 8u65; JRockit: R28.3.8. Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java SE, Java SE Embedded, JRockit accessible data as well as  read access to a subset of Java SE, Java SE Embedded, JRockit accessible data.   Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS Base Score 5.8 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0475</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 8u66; Java SE Embedded: 8u65; JRockit: R28.3.8</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-856V-Java SE: 8u66; Java SE Embedded: 8u65; JRockit: R28.3.8</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="114" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0476</Title>
      <Notes>
         <Note Audience="All" Ordinal="114" Title="Details" Type="Details">Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Grid Control (subcomponent: Load Testing for Web Apps).  Supported versions that are affected are 12.4.0.2 and 
12.5.0.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to all Oracle Application Testing Suite accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0476</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="115" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0477</Title>
      <Notes>
         <Note Audience="All" Ordinal="115" Title="Details" Type="Details">Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Grid Control (subcomponent: Load Testing for Web Apps).  Supported versions that are affected are 12.4.0.2 and 
12.5.0.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to all Oracle Application Testing Suite accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0477</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="116" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0478</Title>
      <Notes>
         <Note Audience="All" Ordinal="116" Title="Details" Type="Details">Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Grid Control (subcomponent: Load Testing for Web Apps).  Supported versions that are affected are 12.4.0.2 and 
12.5.0.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to all Oracle Application Testing Suite accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0478</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="117" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0480</Title>
      <Notes>
         <Note Audience="All" Ordinal="117" Title="Details" Type="Details">Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Grid Control (subcomponent: Test Manager for Web Apps).  Supported versions that are affected are 12.4.0.2 and 
12.5.0.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Application Testing Suite accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0480</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="118" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0481</Title>
      <Notes>
         <Note Audience="All" Ordinal="118" Title="Details" Type="Details">Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Grid Control (subcomponent: Test Manager for Web Apps).  Supported versions that are affected are 12.4.0.2 and 
12.5.0.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Application Testing Suite accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0481</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="119" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0482</Title>
      <Notes>
         <Note Audience="All" Ordinal="119" Title="Details" Type="Details">Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Grid Control (subcomponent: Test Manager for Web Apps).  Supported versions that are affected are 12.4.0.2 and 
12.5.0.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Application Testing Suite accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0482</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="120" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0483</Title>
      <Notes>
         <Note Audience="All" Ordinal="120" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: AWT).  Supported versions that are affected are Java SE: 6u105, 7u91 and  8u66; Java SE Embedded: 8u65; JRockit: R28.3.8. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0483</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 6u105</ProductID>
            <ProductID>P-856V-7u91</ProductID>
            <ProductID>P-856V-8u66; Java SE Embedded: 8u65; JRockit: R28.3.8</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-856V-Java SE: 6u105</ProductID>
            <ProductID>P-856V-7u91</ProductID>
            <ProductID>P-856V-8u66; Java SE Embedded: 8u65; JRockit: R28.3.8</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="121" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0484</Title>
      <Notes>
         <Note Audience="All" Ordinal="121" Title="Details" Type="Details">Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Grid Control (subcomponent: Test Manager for Web Apps).  Supported versions that are affected are 12.4.0.2  and 
12.5.0.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to all Oracle Application Testing Suite accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0484</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="122" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0485</Title>
      <Notes>
         <Note Audience="All" Ordinal="122" Title="Details" Type="Details">Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Grid Control (subcomponent: Test Manager for Web Apps).  Supported versions that are affected are 12.4.0.2 and 
12.5.0.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Application Testing Suite accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0485</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="123" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0486</Title>
      <Notes>
         <Note Audience="All" Ordinal="123" Title="Details" Type="Details">Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Grid Control (subcomponent: Test Manager for Web Apps).  Supported versions that are affected are 12.4.0.2 and 
12.5.0.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to all Oracle Application Testing Suite accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0486</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="124" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0487</Title>
      <Notes>
         <Note Audience="All" Ordinal="124" Title="Details" Type="Details">Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Grid Control (subcomponent: Test Manager for Web Apps).  Supported versions that are affected are 12.4.0.2 and 
12.5.0.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Application Testing Suite accessible data as well as  read access to a subset of Oracle Application Testing Suite accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0487</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="125" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0488</Title>
      <Notes>
         <Note Audience="All" Ordinal="125" Title="Details" Type="Details">Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Grid Control (subcomponent: Load Testing for Web Apps).  Supported versions that are affected are 12.4.0.2 and 
12.5.0.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Application Testing Suite accessible data as well as  read access to a subset of Oracle Application Testing Suite accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="126" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0489</Title>
      <Notes>
         <Note Audience="All" Ordinal="126" Title="Details" Type="Details">Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Grid Control (subcomponent: Test Manager for Web Apps).  Supported versions that are affected are 12.4.0.2 and 
12.5.0.2. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Application Testing Suite accessible data as well as  read access to a subset of Oracle Application Testing Suite accessible data and ability to cause a partial denial of service (partial DOS) of Oracle Application Testing Suite.  CVSS Base Score 6.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0489</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="127" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0490</Title>
      <Notes>
         <Note Audience="All" Ordinal="127" Title="Details" Type="Details">Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Grid Control (subcomponent: Test Manager for Web Apps).  Supported versions that are affected are 12.4.0.2 and 
12.5.0.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Application Testing Suite accessible data as well as  read access to a subset of Oracle Application Testing Suite accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0490</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="128" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0491</Title>
      <Notes>
         <Note Audience="All" Ordinal="128" Title="Details" Type="Details">Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Grid Control (subcomponent: Load Testing for Web Apps).  Supported versions that are affected are 12.4.0.2 and 
12.5.0.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Application Testing Suite accessible data and ability to cause a partial denial of service (partial DOS) of Oracle Application Testing Suite.  CVSS Base Score 6.4 (Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:P+/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0491</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="129" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0492</Title>
      <Notes>
         <Note Audience="All" Ordinal="129" Title="Details" Type="Details">Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Grid Control (subcomponent: Load Testing for Web Apps).  Supported versions that are affected are 12.4.0.2 and 
12.5.0.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Application Testing Suite accessible data as well as  read access to a subset of Oracle Application Testing Suite accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0492</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-4622V-12.4.0.2</ProductID>
            <ProductID>P-4622V-12.5.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="130" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0493</Title>
      <Notes>
         <Note Audience="All" Ordinal="130" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Cryptography).   The supported version that is affected is 11. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Solaris accessible data and ability to cause a partial denial of service (partial DOS) of Solaris.  CVSS Base Score 3.3 (Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:N/I:P/A:P).  Oracle Vector: (AV:L/AC:M/Au:N/C:N/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0493</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.3</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:N/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="131" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0494</Title>
      <Notes>
         <Note Audience="All" Ordinal="131" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: 2D).  Supported versions that are affected are Java SE: 6u105, 7u91 and  8u66; Java SE Embedded: 8u65. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0494</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 6u105</ProductID>
            <ProductID>P-856V-7u91</ProductID>
            <ProductID>P-856V-8u66; Java SE Embedded: 8u65</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-856V-Java SE: 6u105</ProductID>
            <ProductID>P-856V-7u91</ProductID>
            <ProductID>P-856V-8u66; Java SE Embedded: 8u65</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="132" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0495</Title>
      <Notes>
         <Note Audience="All" Ordinal="132" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core).  Supported versions that are affected are VirtualBox prior to 4.3.36 and  prior to 5.0.14. Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox.  CVSS Base Score 4.3 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0495</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-VirtualBox prior to 4.3.36</ProductID>
            <ProductID>P-8370V-prior to 5.0.14</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8370V-VirtualBox prior to 4.3.36</ProductID>
            <ProductID>P-8370V-prior to 5.0.14</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="133" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0496</Title>
      <Notes>
         <Note Audience="All" Ordinal="133" Title="Details" Type="Details">Vulnerability in the MICROS CWDirect component of Oracle Retail Applications (subcomponent: Order Entry).  Supported versions that are affected are 12.5,  
13.0,  
14.0,
15.0,  
16.0 and   
17.0
18.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of MICROS CWDirect accessible data.  CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0496</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11547V-12.5</ProductID>
            <ProductID>P-11547V-13.0</ProductID>
            <ProductID>P-11547V-14.0</ProductID>
            <ProductID>P-11547V-15.0</ProductID>
            <ProductID>P-11547V-16.0</ProductID>
            <ProductID>P-11547V-17.018.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-11547V-12.5</ProductID>
            <ProductID>P-11547V-13.0</ProductID>
            <ProductID>P-11547V-14.0</ProductID>
            <ProductID>P-11547V-15.0</ProductID>
            <ProductID>P-11547V-16.0</ProductID>
            <ProductID>P-11547V-17.018.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="134" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0497</Title>
      <Notes>
         <Note Audience="All" Ordinal="134" Title="Details" Type="Details">Vulnerability in the Oracle Agile Engineering Data Management component of Oracle Supply Chain Products Suite (subcomponent: Web Client).  Supported versions that are affected are 6.1.2.2, 6.1.3.0 and  6.2.0.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Agile Engineering Data Management accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0497</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4436V-6.1.2.2</ProductID>
            <ProductID>P-4436V-6.1.3.0</ProductID>
            <ProductID>P-4436V-6.2.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-4436V-6.1.2.2</ProductID>
            <ProductID>P-4436V-6.1.3.0</ProductID>
            <ProductID>P-4436V-6.2.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="135" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0498</Title>
      <Notes>
         <Note Audience="All" Ordinal="135" Title="Details" Type="Details">Vulnerability in the Oracle Agile Engineering Data Management component of Oracle Supply Chain Products Suite (subcomponent: Install).  Supported versions that are affected are 6.1.2.2, 6.1.3.0 and  6.2.0.0. Difficult to exploit vulnerability requiring logon to Operating System plus additional login/authentication to component or subcomponent.  Successful attack of this vulnerability can escalate attacker privileges resulting in unauthorized  read access to all Oracle Agile Engineering Data Management accessible data.  CVSS Base Score 1.5 (Confidentiality impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:L/AC:M/Au:S/C:P+/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0498</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4436V-6.1.2.2</ProductID>
            <ProductID>P-4436V-6.1.3.0</ProductID>
            <ProductID>P-4436V-6.2.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>1.5</BaseScore>
            <Vector>AV:L/AC:M/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-4436V-6.1.2.2</ProductID>
            <ProductID>P-4436V-6.1.3.0</ProductID>
            <ProductID>P-4436V-6.2.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="136" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0499</Title>
      <Notes>
         <Note Audience="All" Ordinal="136" Title="Details" Type="Details">Vulnerability in the Java VM component of Oracle Database Server.  This vulnerability requires Create Session privileges for a successful attack.  Supported versions that are affected are 11.2.0.4, 12.1.0.1 and  12.1.0.2. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: The CVSS score is 9.0 only on Windows for Database versions prior to 12&lt;i&gt;c&lt;/i&gt;. The CVSS is 6.5 (Confidentiality, Integrity and Availability is "Partial+") for Database 12&lt;i&gt;c&lt;/i&gt; on Windows and for all versions of Database on Linux, Unix and other platforms. CVSS Base Score 9.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:S/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0499</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.1</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>9.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.1</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="137" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0500</Title>
      <Notes>
         <Note Audience="All" Ordinal="137" Title="Details" Type="Details">Vulnerability in the Oracle Retail Order Broker Cloud Service component of Oracle Retail Applications (subcomponent: System Administration).  Supported versions that are affected are 4.0 and  4.1.. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized takeover of Oracle Retail Order Broker Cloud Service possibly including arbitrary code execution within the Oracle Retail Order Broker Cloud Service.  CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0500</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11520V-4.0</ProductID>
            <ProductID>P-11520V-4.1.</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-11520V-4.0</ProductID>
            <ProductID>P-11520V-4.1.</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="138" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0501</Title>
      <Notes>
         <Note Audience="All" Ordinal="138" Title="Details" Type="Details">Vulnerability in the Oracle Secure Global Desktop component of Oracle Virtualization (subcomponent: SGD Core).   The supported version that is affected is 5.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via WebSocket.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Secure Global Desktop.  CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8539V-5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8539V-5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="139" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0502</Title>
      <Notes>
         <Note Audience="All" Ordinal="139" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer).  Supported versions that are affected are 5.5.31 and earlier and  5.6.11 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0502</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.31 and earlier</ProductID>
            <ProductID>P-8478V-5.6.11 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8478V-5.5.31 and earlier</ProductID>
            <ProductID>P-8478V-5.6.11 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="140" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0503</Title>
      <Notes>
         <Note Audience="All" Ordinal="140" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML).  Supported versions that are affected are 5.6.27 and earlier and  5.7.9. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0503</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
            <ProductID>P-8478V-5.7.9</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
            <ProductID>P-8478V-5.7.9</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="141" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0504</Title>
      <Notes>
         <Note Audience="All" Ordinal="141" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML).  Supported versions that are affected are 5.6.27 and earlier and  5.7.9. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 6.8 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:C).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0504</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
            <ProductID>P-8478V-5.7.9</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.8</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
            <ProductID>P-8478V-5.7.9</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="142" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0505</Title>
      <Notes>
         <Note Audience="All" Ordinal="142" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options).  Supported versions that are affected are 5.5.46 and earlier, 5.6.27 and earlier and  5.7.9. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 6.8 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:C).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0505</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.46 and earlier</ProductID>
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
            <ProductID>P-8478V-5.7.9</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.8</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8478V-5.5.46 and earlier</ProductID>
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
            <ProductID>P-8478V-5.7.9</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="143" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0506</Title>
      <Notes>
         <Note Audience="All" Ordinal="143" Title="Details" Type="Details">Vulnerability in the Oracle Retail Order Management System Cloud Service component of Oracle Retail Applications (subcomponent: Order Entry).  Supported versions that are affected are 3.5,    
4.5,
4.7,
5.0 and 
15.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Retail Order Management System Cloud Service accessible data.  CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0506</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11519V-3.5</ProductID>
            <ProductID>P-11519V-4.5</ProductID>
            <ProductID>P-11519V-4.7</ProductID>
            <ProductID>P-11519V-5.0</ProductID>
            <ProductID>P-11519V-15.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-11519V-3.5</ProductID>
            <ProductID>P-11519V-4.5</ProductID>
            <ProductID>P-11519V-4.7</ProductID>
            <ProductID>P-11519V-5.0</ProductID>
            <ProductID>P-11519V-15.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="144" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0507</Title>
      <Notes>
         <Note Audience="All" Ordinal="144" Title="Details" Type="Details">Vulnerability in the Oracle iReceivables component of Oracle E-Business Suite (subcomponent: AR Web Utilities).   The supported version that is affected is 11.5.10.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle iReceivables accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0507</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1106V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1106V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="145" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0508</Title>
      <Notes>
         <Note Audience="All" Ordinal="145" Title="Details" Type="Details">Vulnerability in the Oracle iLearning component of Oracle iLearning (subcomponent: Learner Administration).  Supported versions that are affected are 6.0 and  6.1. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle iLearning accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0508</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-902V-6.0</ProductID>
            <ProductID>P-902V-6.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-902V-6.0</ProductID>
            <ProductID>P-902V-6.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="146" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0509</Title>
      <Notes>
         <Note Audience="All" Ordinal="146" Title="Details" Type="Details">Vulnerability in the Oracle Internet Expenses component of Oracle E-Business Suite (subcomponent: AP Web Utilities).   The supported version that is affected is 11.5.10.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Internet Expenses accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0509</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-397V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-397V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="147" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0510</Title>
      <Notes>
         <Note Audience="All" Ordinal="147" Title="Details" Type="Details">Vulnerability in the Oracle E-Business Intelligence component of Oracle E-Business Suite (subcomponent: Business Views Catalog).   The supported version that is affected is 11.5.10.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle E-Business Intelligence accessible data as well as  read access to all Oracle E-Business Intelligence accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0510</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-163V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-163V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="148" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0511</Title>
      <Notes>
         <Note Audience="All" Ordinal="148" Title="Details" Type="Details">Vulnerability in the Oracle E-Business Intelligence component of Oracle E-Business Suite (subcomponent: Common Components).   The supported version that is affected is 11.5.10.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle E-Business Intelligence accessible data as well as  read access to all Oracle E-Business Intelligence accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0511</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-163V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-163V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="149" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0512</Title>
      <Notes>
         <Note Audience="All" Ordinal="149" Title="Details" Type="Details">Vulnerability in the Oracle Human Resources component of Oracle E-Business Suite (subcomponent: Self Service - Common Modules ).   The supported version that is affected is 11.5.10.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Human Resources accessible data as well as  read access to all Oracle Human Resources accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0512</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1566V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1566V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="150" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0513</Title>
      <Notes>
         <Note Audience="All" Ordinal="150" Title="Details" Type="Details">Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: BIS Common Components).   The supported version that is affected is 11.5.10.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle CRM Technical Foundation accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0513</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1199V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1199V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="151" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0514</Title>
      <Notes>
         <Note Audience="All" Ordinal="151" Title="Details" Type="Details">Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: BIS Common Components).   The supported version that is affected is 11.5.10.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle CRM Technical Foundation accessible data as well as  read access to all Oracle CRM Technical Foundation accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0514</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1199V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1199V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="152" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0515</Title>
      <Notes>
         <Note Audience="All" Ordinal="152" Title="Details" Type="Details">Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: BIS Common Components).   The supported version that is affected is 11.5.10.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle CRM Technical Foundation accessible data as well as  read access to all Oracle CRM Technical Foundation accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0515</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1199V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1199V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="153" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0516</Title>
      <Notes>
         <Note Audience="All" Ordinal="153" Title="Details" Type="Details">Vulnerability in the Oracle Quality component of Oracle E-Business Suite (subcomponent: QA / Order Management Integration).   The supported version that is affected is 11.5.10.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Quality accessible data as well as  read access to all Oracle Quality accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0516</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-214V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-214V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="154" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0517</Title>
      <Notes>
         <Note Audience="All" Ordinal="154" Title="Details" Type="Details">Vulnerability in the Oracle Human Resources component of Oracle E-Business Suite (subcomponent: General utilities).   The supported version that is affected is 11.5.10.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Human Resources accessible data as well as  read access to all Oracle Human Resources accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0517</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-507V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-507V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="155" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0518</Title>
      <Notes>
         <Note Audience="All" Ordinal="155" Title="Details" Type="Details">Vulnerability in the Oracle Human Resources component of Oracle E-Business Suite (subcomponent: General utilities).   The supported version that is affected is 11.5.10.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Human Resources accessible data as well as  read access to all Oracle Human Resources accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0518</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-507V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-507V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="156" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0519</Title>
      <Notes>
         <Note Audience="All" Ordinal="156" Title="Details" Type="Details">Vulnerability in the Oracle iReceivables component of Oracle E-Business Suite (subcomponent: AR Web Utilities).   The supported version that is affected is 11.5.10.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle iReceivables accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0519</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1106V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1106V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="157" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0520</Title>
      <Notes>
         <Note Audience="All" Ordinal="157" Title="Details" Type="Details">Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Java APIs).   The supported version that is affected is 11.5.10.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Application Object Library accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0520</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-510V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-510V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="158" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0521</Title>
      <Notes>
         <Note Audience="All" Ordinal="158" Title="Details" Type="Details">Vulnerability in the Oracle iProcurement component of Oracle E-Business Suite (subcomponent: Redirection).   The supported version that is affected is 11.5.10.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle iProcurement accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0521</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-398V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-398V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="159" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0522</Title>
      <Notes>
         <Note Audience="All" Ordinal="159" Title="Details" Type="Details">Vulnerability in the Oracle Retail Open Commerce Platform Cloud Service component of Oracle Retail Applications (subcomponent: Framework).  Supported versions that are affected are 3.5,    
4.5,    
4.7 and    
5.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized takeover of Oracle Retail Open Commerce Platform Cloud Service possibly including arbitrary code execution within the Oracle Retail Open Commerce Platform Cloud Service.  CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0522</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11521V-3.5</ProductID>
            <ProductID>P-11521V-4.5</ProductID>
            <ProductID>P-11521V-4.7</ProductID>
            <ProductID>P-11521V-5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-11521V-3.5</ProductID>
            <ProductID>P-11521V-4.5</ProductID>
            <ProductID>P-11521V-4.7</ProductID>
            <ProductID>P-11521V-5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="160" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0523</Title>
      <Notes>
         <Note Audience="All" Ordinal="160" Title="Details" Type="Details">Vulnerability in the Oracle Interaction Blending component of Oracle E-Business Suite (subcomponent: Blending Administration).  Supported versions that are affected are 11.5.10.2, 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Interaction Blending accessible data as well as  read access to all Oracle Interaction Blending accessible data.  CVSS Base Score 5.5 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0523</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-182V-11.5.10.2</ProductID>
            <ProductID>P-182V-12.1.1</ProductID>
            <ProductID>P-182V-12.1.2</ProductID>
            <ProductID>P-182V-12.1.3</ProductID>
            <ProductID>P-182V-12.2.3</ProductID>
            <ProductID>P-182V-12.2.4</ProductID>
            <ProductID>P-182V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-182V-11.5.10.2</ProductID>
            <ProductID>P-182V-12.1.1</ProductID>
            <ProductID>P-182V-12.1.2</ProductID>
            <ProductID>P-182V-12.1.3</ProductID>
            <ProductID>P-182V-12.2.3</ProductID>
            <ProductID>P-182V-12.2.4</ProductID>
            <ProductID>P-182V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="161" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0524</Title>
      <Notes>
         <Note Audience="All" Ordinal="161" Title="Details" Type="Details">Vulnerability in the Oracle Universal Work Queue component of Oracle E-Business Suite (subcomponent: Work Provider Administration).   The supported version that is affected is 11.5.10.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Universal Work Queue accessible data as well as  read access to all Oracle Universal Work Queue accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0524</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-778V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-778V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="162" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0525</Title>
      <Notes>
         <Note Audience="All" Ordinal="162" Title="Details" Type="Details">Vulnerability in the Oracle Universal Work Queue component of Oracle E-Business Suite (subcomponent: Work Provider Administration).  Supported versions that are affected are 11.5.10.2, 12.1.1, 12.1.2 and  12.1.3. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Universal Work Queue accessible data as well as  read access to all Oracle Universal Work Queue accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0525</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-778V-11.5.10.2</ProductID>
            <ProductID>P-778V-12.1.1</ProductID>
            <ProductID>P-778V-12.1.2</ProductID>
            <ProductID>P-778V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-778V-11.5.10.2</ProductID>
            <ProductID>P-778V-12.1.1</ProductID>
            <ProductID>P-778V-12.1.2</ProductID>
            <ProductID>P-778V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="163" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0526</Title>
      <Notes>
         <Note Audience="All" Ordinal="163" Title="Details" Type="Details">Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Wireless Framework).  Supported versions that are affected are 11.5.10.2, 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle CRM Technical Foundation accessible data.  CVSS Base Score 5.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0526</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1199V-11.5.10.2</ProductID>
            <ProductID>P-1199V-12.1.3</ProductID>
            <ProductID>P-1199V-12.2.3</ProductID>
            <ProductID>P-1199V-12.2.4</ProductID>
            <ProductID>P-1199V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1199V-11.5.10.2</ProductID>
            <ProductID>P-1199V-12.1.3</ProductID>
            <ProductID>P-1199V-12.2.3</ProductID>
            <ProductID>P-1199V-12.2.4</ProductID>
            <ProductID>P-1199V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="164" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0527</Title>
      <Notes>
         <Note Audience="All" Ordinal="164" Title="Details" Type="Details">Vulnerability in the Oracle Customer Interaction History component of Oracle E-Business Suite (subcomponent: User GUI).  Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Customer Interaction History accessible data as well as  read access to a subset of Oracle Customer Interaction History accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0527</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1374V-12.1.1</ProductID>
            <ProductID>P-1374V-12.1.2</ProductID>
            <ProductID>P-1374V-12.1.3</ProductID>
            <ProductID>P-1374V-12.2.3</ProductID>
            <ProductID>P-1374V-12.2.4</ProductID>
            <ProductID>P-1374V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1374V-12.1.1</ProductID>
            <ProductID>P-1374V-12.1.2</ProductID>
            <ProductID>P-1374V-12.1.3</ProductID>
            <ProductID>P-1374V-12.2.3</ProductID>
            <ProductID>P-1374V-12.2.4</ProductID>
            <ProductID>P-1374V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="165" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0528</Title>
      <Notes>
         <Note Audience="All" Ordinal="165" Title="Details" Type="Details">Vulnerability in the Oracle Customer Interaction History component of Oracle E-Business Suite (subcomponent: User GUI).  Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Customer Interaction History accessible data as well as  read access to a subset of Oracle Customer Interaction History accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0528</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1374V-12.1.1</ProductID>
            <ProductID>P-1374V-12.1.2</ProductID>
            <ProductID>P-1374V-12.1.3</ProductID>
            <ProductID>P-1374V-12.2.3</ProductID>
            <ProductID>P-1374V-12.2.4</ProductID>
            <ProductID>P-1374V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1374V-12.1.1</ProductID>
            <ProductID>P-1374V-12.1.2</ProductID>
            <ProductID>P-1374V-12.1.3</ProductID>
            <ProductID>P-1374V-12.2.3</ProductID>
            <ProductID>P-1374V-12.2.4</ProductID>
            <ProductID>P-1374V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="166" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0529</Title>
      <Notes>
         <Note Audience="All" Ordinal="166" Title="Details" Type="Details">Vulnerability in the Oracle Customer Interaction History component of Oracle E-Business Suite (subcomponent: User GUI).  Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Customer Interaction History accessible data as well as  read access to a subset of Oracle Customer Interaction History accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0529</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1374V-12.1.1</ProductID>
            <ProductID>P-1374V-12.1.2</ProductID>
            <ProductID>P-1374V-12.1.3</ProductID>
            <ProductID>P-1374V-12.2.3</ProductID>
            <ProductID>P-1374V-12.2.4</ProductID>
            <ProductID>P-1374V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1374V-12.1.1</ProductID>
            <ProductID>P-1374V-12.1.2</ProductID>
            <ProductID>P-1374V-12.1.3</ProductID>
            <ProductID>P-1374V-12.2.3</ProductID>
            <ProductID>P-1374V-12.2.4</ProductID>
            <ProductID>P-1374V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="167" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0530</Title>
      <Notes>
         <Note Audience="All" Ordinal="167" Title="Details" Type="Details">Vulnerability in the Oracle Customer Interaction History component of Oracle E-Business Suite (subcomponent: User GUI).  Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Customer Interaction History accessible data as well as  read access to a subset of Oracle Customer Interaction History accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0530</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1374V-12.1.1</ProductID>
            <ProductID>P-1374V-12.1.2</ProductID>
            <ProductID>P-1374V-12.1.3</ProductID>
            <ProductID>P-1374V-12.2.3</ProductID>
            <ProductID>P-1374V-12.2.4</ProductID>
            <ProductID>P-1374V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1374V-12.1.1</ProductID>
            <ProductID>P-1374V-12.1.2</ProductID>
            <ProductID>P-1374V-12.1.3</ProductID>
            <ProductID>P-1374V-12.2.3</ProductID>
            <ProductID>P-1374V-12.2.4</ProductID>
            <ProductID>P-1374V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="168" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0531</Title>
      <Notes>
         <Note Audience="All" Ordinal="168" Title="Details" Type="Details">Vulnerability in the Oracle Applications Manager component of Oracle E-Business Suite (subcomponent: Oracle Diagnostics Interfaces).   The supported version that is affected is 12.1.3. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Applications Manager accessible data.  CVSS Base Score 4.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0531</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-99V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-99V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="169" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0532</Title>
      <Notes>
         <Note Audience="All" Ordinal="169" Title="Details" Type="Details">Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Security Assignments).  Supported versions that are affected are 11.5.10.2, 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle CRM Technical Foundation accessible data as well as  read access to a subset of Oracle CRM Technical Foundation accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0532</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1199V-11.5.10.2</ProductID>
            <ProductID>P-1199V-12.1.3</ProductID>
            <ProductID>P-1199V-12.2.3</ProductID>
            <ProductID>P-1199V-12.2.4</ProductID>
            <ProductID>P-1199V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1199V-11.5.10.2</ProductID>
            <ProductID>P-1199V-12.1.3</ProductID>
            <ProductID>P-1199V-12.2.3</ProductID>
            <ProductID>P-1199V-12.2.4</ProductID>
            <ProductID>P-1199V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="170" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0533</Title>
      <Notes>
         <Note Audience="All" Ordinal="170" Title="Details" Type="Details">Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Messaging).  Supported versions that are affected are 11.5.10.2 and  12.1.3. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle CRM Technical Foundation accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0533</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1199V-11.5.10.2</ProductID>
            <ProductID>P-1199V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1199V-11.5.10.2</ProductID>
            <ProductID>P-1199V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="171" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0534</Title>
      <Notes>
         <Note Audience="All" Ordinal="171" Title="Details" Type="Details">Vulnerability in the Oracle Project Contracts component of Oracle E-Business Suite (subcomponent: Printing).  Supported versions that are affected are 12.1.1, 12.1.2 and  12.1.3. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Project Contracts accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0534</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-799V-12.1.1</ProductID>
            <ProductID>P-799V-12.1.2</ProductID>
            <ProductID>P-799V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-799V-12.1.1</ProductID>
            <ProductID>P-799V-12.1.2</ProductID>
            <ProductID>P-799V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="172" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0535</Title>
      <Notes>
         <Note Audience="All" Ordinal="172" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RPC).  Supported versions that are affected are 10 and  11. Difficult to exploit vulnerability allows successful unauthenticated network attacks via RPC.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Solaris.  CVSS Base Score 4.3 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0535</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-10</ProductID>
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-10006V-10</ProductID>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="173" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0536</Title>
      <Notes>
         <Note Audience="All" Ordinal="173" Title="Details" Type="Details">Vulnerability in the Oracle Universal Work Queue component of Oracle E-Business Suite (subcomponent: Error Messages).   The supported version that is affected is 11.5.10.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Universal Work Queue accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0536</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-778V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-778V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="174" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0537</Title>
      <Notes>
         <Note Audience="All" Ordinal="174" Title="Details" Type="Details">Vulnerability in the Oracle Human Resources component of Oracle E-Business Suite (subcomponent: Person).   The supported version that is affected is 11.5.10.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Human Resources accessible data as well as  read access to all Oracle Human Resources accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0537</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-507V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-507V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="175" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0538</Title>
      <Notes>
         <Note Audience="All" Ordinal="175" Title="Details" Type="Details">Vulnerability in the Oracle Financial Consolidation Hub component of Oracle E-Business Suite (subcomponent: Business Intelligence).  Supported versions that are affected are 11.5.10.2, 12.1.1, 12.1.2 and  12.1.3. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Financial Consolidation Hub accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0538</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1375V-11.5.10.2</ProductID>
            <ProductID>P-1375V-12.1.1</ProductID>
            <ProductID>P-1375V-12.1.2</ProductID>
            <ProductID>P-1375V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1375V-11.5.10.2</ProductID>
            <ProductID>P-1375V-12.1.1</ProductID>
            <ProductID>P-1375V-12.1.2</ProductID>
            <ProductID>P-1375V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="176" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0539</Title>
      <Notes>
         <Note Audience="All" Ordinal="176" Title="Details" Type="Details">Vulnerability in the Oracle Report Manager component of Oracle E-Business Suite (subcomponent: Report Display).  Supported versions that are affected are 11.5.10.2, 12.1.3, 12.2.3 and  12.2.4. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Report Manager accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0539</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-777V-11.5.10.2</ProductID>
            <ProductID>P-777V-12.1.3</ProductID>
            <ProductID>P-777V-12.2.3</ProductID>
            <ProductID>P-777V-12.2.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-777V-11.5.10.2</ProductID>
            <ProductID>P-777V-12.1.3</ProductID>
            <ProductID>P-777V-12.2.3</ProductID>
            <ProductID>P-777V-12.2.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="177" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0540</Title>
      <Notes>
         <Note Audience="All" Ordinal="177" Title="Details" Type="Details">Vulnerability in the Oracle Configurator component of Oracle Supply Chain Products Suite (subcomponent: UI Servlet).  Supported versions that are affected are 11.5.10.2, 12.1 and  12.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Configurator accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0540</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-31V-11.5.10.2</ProductID>
            <ProductID>P-31V-12.1</ProductID>
            <ProductID>P-31V-12.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-31V-11.5.10.2</ProductID>
            <ProductID>P-31V-12.1</ProductID>
            <ProductID>P-31V-12.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="178" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0541</Title>
      <Notes>
         <Note Audience="All" Ordinal="178" Title="Details" Type="Details">Vulnerability in the Oracle Configurator component of Oracle Supply Chain Products Suite (subcomponent: UI Servlet).  Supported versions that are affected are 11.5.10.2, 12.1 and  12.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Configurator accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0541</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-31V-11.5.10.2</ProductID>
            <ProductID>P-31V-12.1</ProductID>
            <ProductID>P-31V-12.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-31V-11.5.10.2</ProductID>
            <ProductID>P-31V-12.1</ProductID>
            <ProductID>P-31V-12.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="179" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0542</Title>
      <Notes>
         <Note Audience="All" Ordinal="179" Title="Details" Type="Details">Vulnerability in the Oracle Field Service component of Oracle E-Business Suite (subcomponent: Field Service Map).  Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Field Service accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0542</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-747V-12.1.1</ProductID>
            <ProductID>P-747V-12.1.2</ProductID>
            <ProductID>P-747V-12.1.3</ProductID>
            <ProductID>P-747V-12.2.3</ProductID>
            <ProductID>P-747V-12.2.4</ProductID>
            <ProductID>P-747V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-747V-12.1.1</ProductID>
            <ProductID>P-747V-12.1.2</ProductID>
            <ProductID>P-747V-12.1.3</ProductID>
            <ProductID>P-747V-12.2.3</ProductID>
            <ProductID>P-747V-12.2.4</ProductID>
            <ProductID>P-747V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="180" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0543</Title>
      <Notes>
         <Note Audience="All" Ordinal="180" Title="Details" Type="Details">Vulnerability in the Oracle Marketing component of Oracle E-Business Suite (subcomponent: Preview).   The supported version that is affected is 11.5.10.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Marketing accessible data as well as  read access to all Oracle Marketing accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0543</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-229V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-229V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="181" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0544</Title>
      <Notes>
         <Note Audience="All" Ordinal="181" Title="Details" Type="Details">Vulnerability in the Oracle Marketing component of Oracle E-Business Suite (subcomponent: Architecture).   The supported version that is affected is 11.5.10.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Marketing accessible data as well as  read access to all Oracle Marketing accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0544</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-229V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-229V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="182" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0545</Title>
      <Notes>
         <Note Audience="All" Ordinal="182" Title="Details" Type="Details">Vulnerability in the Oracle Customer Intelligence component of Oracle E-Business Suite (subcomponent: Data Issues).  Supported versions that are affected are 11.5.10.2, 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Customer Intelligence accessible data as well as  read access to all Oracle Customer Intelligence accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0545</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-390V-11.5.10.2</ProductID>
            <ProductID>P-390V-12.1.1</ProductID>
            <ProductID>P-390V-12.1.2</ProductID>
            <ProductID>P-390V-12.1.3</ProductID>
            <ProductID>P-390V-12.2.3</ProductID>
            <ProductID>P-390V-12.2.4</ProductID>
            <ProductID>P-390V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-390V-11.5.10.2</ProductID>
            <ProductID>P-390V-12.1.1</ProductID>
            <ProductID>P-390V-12.1.2</ProductID>
            <ProductID>P-390V-12.1.3</ProductID>
            <ProductID>P-390V-12.2.3</ProductID>
            <ProductID>P-390V-12.2.4</ProductID>
            <ProductID>P-390V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="183" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0546</Title>
      <Notes>
         <Note Audience="All" Ordinal="183" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client).  Supported versions that are affected are 5.5.46 and earlier, 5.6.27 and earlier and  5.7.9. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: The CVSS score is 7.2 if MySQL client is run with admin or root privileges. Otherwise, CVSS score is 4.6 (Confidentiality, Integrity and Availability is  Partial+). CVSS Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:L/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0546</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.46 and earlier</ProductID>
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
            <ProductID>P-8478V-5.7.9</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.2</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8478V-5.5.46 and earlier</ProductID>
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
            <ProductID>P-8478V-5.7.9</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="184" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0547</Title>
      <Notes>
         <Note Audience="All" Ordinal="184" Title="Details" Type="Details">Vulnerability in the Oracle E-Business Intelligence component of Oracle E-Business Suite (subcomponent: Common Components).   The supported version that is affected is 11.5.10.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle E-Business Intelligence accessible data as well as  read access to all Oracle E-Business Intelligence accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0547</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-163V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-163V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="185" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0548</Title>
      <Notes>
         <Note Audience="All" Ordinal="185" Title="Details" Type="Details">Vulnerability in the Oracle E-Business Intelligence component of Oracle E-Business Suite (subcomponent: Common Components).   The supported version that is affected is 11.5.10.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle E-Business Intelligence accessible data as well as  read access to all Oracle E-Business Intelligence accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0548</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-163V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-163V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="186" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0549</Title>
      <Notes>
         <Note Audience="All" Ordinal="186" Title="Details" Type="Details">Vulnerability in the Oracle E-Business Intelligence component of Oracle E-Business Suite (subcomponent: Common Components).   The supported version that is affected is 11.5.10.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle E-Business Intelligence accessible data as well as  read access to all Oracle E-Business Intelligence accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0549</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-163V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-163V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="187" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0550</Title>
      <Notes>
         <Note Audience="All" Ordinal="187" Title="Details" Type="Details">Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: CRM HTML Administration).  Supported versions that are affected are 11.5.10.2, 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle CRM Technical Foundation accessible data as well as  read access to all Oracle CRM Technical Foundation accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0550</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1199V-11.5.10.2</ProductID>
            <ProductID>P-1199V-12.1.3</ProductID>
            <ProductID>P-1199V-12.2.3</ProductID>
            <ProductID>P-1199V-12.2.4</ProductID>
            <ProductID>P-1199V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1199V-11.5.10.2</ProductID>
            <ProductID>P-1199V-12.1.3</ProductID>
            <ProductID>P-1199V-12.2.3</ProductID>
            <ProductID>P-1199V-12.2.4</ProductID>
            <ProductID>P-1199V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="188" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0551</Title>
      <Notes>
         <Note Audience="All" Ordinal="188" Title="Details" Type="Details">Vulnerability in the Oracle Customer Intelligence component of Oracle E-Business Suite (subcomponent: Data Issues).  Supported versions that are affected are 11.5.10.2, 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Customer Intelligence accessible data as well as  read access to all Oracle Customer Intelligence accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0551</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-390V-11.5.10.2</ProductID>
            <ProductID>P-390V-12.1.1</ProductID>
            <ProductID>P-390V-12.1.2</ProductID>
            <ProductID>P-390V-12.1.3</ProductID>
            <ProductID>P-390V-12.2.3</ProductID>
            <ProductID>P-390V-12.2.4</ProductID>
            <ProductID>P-390V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-390V-11.5.10.2</ProductID>
            <ProductID>P-390V-12.1.1</ProductID>
            <ProductID>P-390V-12.1.2</ProductID>
            <ProductID>P-390V-12.1.3</ProductID>
            <ProductID>P-390V-12.2.3</ProductID>
            <ProductID>P-390V-12.2.4</ProductID>
            <ProductID>P-390V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="189" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0552</Title>
      <Notes>
         <Note Audience="All" Ordinal="189" Title="Details" Type="Details">Vulnerability in the Oracle Customer Intelligence component of Oracle E-Business Suite (subcomponent: Data Issues).  Supported versions that are affected are 11.5.10.2, 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Customer Intelligence accessible data as well as  read access to all Oracle Customer Intelligence accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0552</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-390V-11.5.10.2</ProductID>
            <ProductID>P-390V-12.1.1</ProductID>
            <ProductID>P-390V-12.1.2</ProductID>
            <ProductID>P-390V-12.1.3</ProductID>
            <ProductID>P-390V-12.2.3</ProductID>
            <ProductID>P-390V-12.2.4</ProductID>
            <ProductID>P-390V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-390V-11.5.10.2</ProductID>
            <ProductID>P-390V-12.1.1</ProductID>
            <ProductID>P-390V-12.1.2</ProductID>
            <ProductID>P-390V-12.1.3</ProductID>
            <ProductID>P-390V-12.2.3</ProductID>
            <ProductID>P-390V-12.2.4</ProductID>
            <ProductID>P-390V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="190" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0553</Title>
      <Notes>
         <Note Audience="All" Ordinal="190" Title="Details" Type="Details">Vulnerability in the Oracle E-Business Intelligence component of Oracle E-Business Suite (subcomponent: Definition).  Supported versions that are affected are 11.5.10.2, 12.1.1, 12.1.2 and  12.1.3. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle E-Business Intelligence accessible data as well as  read access to all Oracle E-Business Intelligence accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0553</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-163V-11.5.10.2</ProductID>
            <ProductID>P-163V-12.1.1</ProductID>
            <ProductID>P-163V-12.1.2</ProductID>
            <ProductID>P-163V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-163V-11.5.10.2</ProductID>
            <ProductID>P-163V-12.1.1</ProductID>
            <ProductID>P-163V-12.1.2</ProductID>
            <ProductID>P-163V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="191" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0554</Title>
      <Notes>
         <Note Audience="All" Ordinal="191" Title="Details" Type="Details">Vulnerability in the Oracle Interaction Center Intelligence component of Oracle E-Business Suite (subcomponent: Business Intelligence).  Supported versions that are affected are 11.5.10.2, 12.1.1, 12.1.2 and  12.1.3. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Interaction Center Intelligence accessible data as well as  read access to all Oracle Interaction Center Intelligence accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0554</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-298V-11.5.10.2</ProductID>
            <ProductID>P-298V-12.1.1</ProductID>
            <ProductID>P-298V-12.1.2</ProductID>
            <ProductID>P-298V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-298V-11.5.10.2</ProductID>
            <ProductID>P-298V-12.1.1</ProductID>
            <ProductID>P-298V-12.1.2</ProductID>
            <ProductID>P-298V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="192" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0555</Title>
      <Notes>
         <Note Audience="All" Ordinal="192" Title="Details" Type="Details">Vulnerability in the Oracle CADView-3D component of Oracle E-Business Suite (subcomponent: Studio).  Supported versions that are affected are 11.5.10.2, 12.1.1, 12.1.2 and  12.1.3. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle CADView-3D accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0555</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1285V-11.5.10.2</ProductID>
            <ProductID>P-1285V-12.1.1</ProductID>
            <ProductID>P-1285V-12.1.2</ProductID>
            <ProductID>P-1285V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1285V-11.5.10.2</ProductID>
            <ProductID>P-1285V-12.1.1</ProductID>
            <ProductID>P-1285V-12.1.2</ProductID>
            <ProductID>P-1285V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="193" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0556</Title>
      <Notes>
         <Note Audience="All" Ordinal="193" Title="Details" Type="Details">Vulnerability in the Oracle Advanced Collections component of Oracle E-Business Suite (subcomponent: Administration).  Supported versions that are affected are 11.5.10.2, 12.1.1, 12.1.2 and  12.1.3. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Advanced Collections accessible data as well as  read access to all Oracle Advanced Collections accessible data.  CVSS Base Score 5.5 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0556</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-782V-11.5.10.2</ProductID>
            <ProductID>P-782V-12.1.1</ProductID>
            <ProductID>P-782V-12.1.2</ProductID>
            <ProductID>P-782V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-782V-11.5.10.2</ProductID>
            <ProductID>P-782V-12.1.1</ProductID>
            <ProductID>P-782V-12.1.2</ProductID>
            <ProductID>P-782V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="194" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0557</Title>
      <Notes>
         <Note Audience="All" Ordinal="194" Title="Details" Type="Details">Vulnerability in the Oracle Advanced Collections component of Oracle E-Business Suite (subcomponent: Administration).  Supported versions that are affected are 11.5.10.2, 12.1.1, 12.1.2 and  12.1.3. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Advanced Collections accessible data as well as  read access to all Oracle Advanced Collections accessible data.  CVSS Base Score 5.5 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0557</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-782V-11.5.10.2</ProductID>
            <ProductID>P-782V-12.1.1</ProductID>
            <ProductID>P-782V-12.1.2</ProductID>
            <ProductID>P-782V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-782V-11.5.10.2</ProductID>
            <ProductID>P-782V-12.1.1</ProductID>
            <ProductID>P-782V-12.1.2</ProductID>
            <ProductID>P-782V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="195" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0558</Title>
      <Notes>
         <Note Audience="All" Ordinal="195" Title="Details" Type="Details">Vulnerability in the Oracle Service Contracts component of Oracle E-Business Suite (subcomponent: Renewals).  Supported versions that are affected are 11.5.10.2, 12.1.1, 12.1.2 and  12.1.3. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Service Contracts accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0558</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-432V-11.5.10.2</ProductID>
            <ProductID>P-432V-12.1.1</ProductID>
            <ProductID>P-432V-12.1.2</ProductID>
            <ProductID>P-432V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-432V-11.5.10.2</ProductID>
            <ProductID>P-432V-12.1.1</ProductID>
            <ProductID>P-432V-12.1.2</ProductID>
            <ProductID>P-432V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="196" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0559</Title>
      <Notes>
         <Note Audience="All" Ordinal="196" Title="Details" Type="Details">Vulnerability in the Oracle Customer Intelligence component of Oracle E-Business Suite (subcomponent: Data Issues).  Supported versions that are affected are 11.5.10.2, 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Customer Intelligence accessible data as well as  read access to all Oracle Customer Intelligence accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0559</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-390V-11.5.10.2</ProductID>
            <ProductID>P-390V-12.1.1</ProductID>
            <ProductID>P-390V-12.1.2</ProductID>
            <ProductID>P-390V-12.1.3</ProductID>
            <ProductID>P-390V-12.2.3</ProductID>
            <ProductID>P-390V-12.2.4</ProductID>
            <ProductID>P-390V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-390V-11.5.10.2</ProductID>
            <ProductID>P-390V-12.1.1</ProductID>
            <ProductID>P-390V-12.1.2</ProductID>
            <ProductID>P-390V-12.1.3</ProductID>
            <ProductID>P-390V-12.2.3</ProductID>
            <ProductID>P-390V-12.2.4</ProductID>
            <ProductID>P-390V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="197" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0560</Title>
      <Notes>
         <Note Audience="All" Ordinal="197" Title="Details" Type="Details">Vulnerability in the Oracle Customer Intelligence component of Oracle E-Business Suite (subcomponent: Data Issues).  Supported versions that are affected are 11.5.10.2, 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Customer Intelligence accessible data as well as  read access to all Oracle Customer Intelligence accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0560</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-390V-11.5.10.2</ProductID>
            <ProductID>P-390V-12.1.1</ProductID>
            <ProductID>P-390V-12.1.2</ProductID>
            <ProductID>P-390V-12.1.3</ProductID>
            <ProductID>P-390V-12.2.3</ProductID>
            <ProductID>P-390V-12.2.4</ProductID>
            <ProductID>P-390V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-390V-11.5.10.2</ProductID>
            <ProductID>P-390V-12.1.1</ProductID>
            <ProductID>P-390V-12.1.2</ProductID>
            <ProductID>P-390V-12.1.3</ProductID>
            <ProductID>P-390V-12.2.3</ProductID>
            <ProductID>P-390V-12.2.4</ProductID>
            <ProductID>P-390V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="198" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0561</Title>
      <Notes>
         <Note Audience="All" Ordinal="198" Title="Details" Type="Details">Vulnerability in the Oracle E-Business Intelligence component of Oracle E-Business Suite (subcomponent: Definition).  Supported versions that are affected are 11.5.10.2, 12.1.1, 12.1.2 and  12.1.3. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle E-Business Intelligence accessible data as well as  read access to all Oracle E-Business Intelligence accessible data.  CVSS Base Score 5.5 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0561</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-163V-11.5.10.2</ProductID>
            <ProductID>P-163V-12.1.1</ProductID>
            <ProductID>P-163V-12.1.2</ProductID>
            <ProductID>P-163V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-163V-11.5.10.2</ProductID>
            <ProductID>P-163V-12.1.1</ProductID>
            <ProductID>P-163V-12.1.2</ProductID>
            <ProductID>P-163V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="199" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0562</Title>
      <Notes>
         <Note Audience="All" Ordinal="199" Title="Details" Type="Details">Vulnerability in the Oracle Common Applications component of Oracle E-Business Suite (subcomponent: CRM User Management Framework).  Supported versions that are affected are 11.5.10.2, 12.1.1, 12.1.2 and  12.1.3. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Common Applications accessible data.  CVSS Base Score 4.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0562</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1198V-11.5.10.2</ProductID>
            <ProductID>P-1198V-12.1.1</ProductID>
            <ProductID>P-1198V-12.1.2</ProductID>
            <ProductID>P-1198V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1198V-11.5.10.2</ProductID>
            <ProductID>P-1198V-12.1.1</ProductID>
            <ProductID>P-1198V-12.1.2</ProductID>
            <ProductID>P-1198V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="200" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0563</Title>
      <Notes>
         <Note Audience="All" Ordinal="200" Title="Details" Type="Details">Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Common Techstack).  Supported versions that are affected are 11.5.10.2 and  12.1.3. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle CRM Technical Foundation accessible data as well as  read access to all Oracle CRM Technical Foundation accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0563</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1199V-11.5.10.2</ProductID>
            <ProductID>P-1199V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1199V-11.5.10.2</ProductID>
            <ProductID>P-1199V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="201" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0564</Title>
      <Notes>
         <Note Audience="All" Ordinal="201" Title="Details" Type="Details">Vulnerability in the Oracle E-Business Intelligence component of Oracle E-Business Suite (subcomponent: Overview Page/Report Rendering).  Supported versions that are affected are 11.5.10.2, 12.1.1, 12.1.2 and  12.1.3. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle E-Business Intelligence accessible data as well as  read access to all Oracle E-Business Intelligence accessible data.  CVSS Base Score 5.5 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0564</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-163V-11.5.10.2</ProductID>
            <ProductID>P-163V-12.1.1</ProductID>
            <ProductID>P-163V-12.1.2</ProductID>
            <ProductID>P-163V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-163V-11.5.10.2</ProductID>
            <ProductID>P-163V-12.1.1</ProductID>
            <ProductID>P-163V-12.1.2</ProductID>
            <ProductID>P-163V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="202" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0565</Title>
      <Notes>
         <Note Audience="All" Ordinal="202" Title="Details" Type="Details">Vulnerability in the Oracle Marketing component of Oracle E-Business Suite (subcomponent: Marketing Administration).  Supported versions that are affected are 11.5.10.2, 12.1.1, 12.1.2 and  12.1.3. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Marketing accessible data.  CVSS Base Score 5.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0565</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-229V-11.5.10.2</ProductID>
            <ProductID>P-229V-12.1.1</ProductID>
            <ProductID>P-229V-12.1.2</ProductID>
            <ProductID>P-229V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-229V-11.5.10.2</ProductID>
            <ProductID>P-229V-12.1.1</ProductID>
            <ProductID>P-229V-12.1.2</ProductID>
            <ProductID>P-229V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="203" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0566</Title>
      <Notes>
         <Note Audience="All" Ordinal="203" Title="Details" Type="Details">Vulnerability in the Oracle Marketing component of Oracle E-Business Suite (subcomponent: Deliverables).  Supported versions that are affected are 11.5.10.2, 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4 and  12.2.5. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Marketing accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0566</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-229V-11.5.10.2</ProductID>
            <ProductID>P-229V-12.1.1</ProductID>
            <ProductID>P-229V-12.1.2</ProductID>
            <ProductID>P-229V-12.1.3</ProductID>
            <ProductID>P-229V-12.2.3</ProductID>
            <ProductID>P-229V-12.2.4</ProductID>
            <ProductID>P-229V-12.2.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-229V-11.5.10.2</ProductID>
            <ProductID>P-229V-12.1.1</ProductID>
            <ProductID>P-229V-12.1.2</ProductID>
            <ProductID>P-229V-12.1.3</ProductID>
            <ProductID>P-229V-12.2.3</ProductID>
            <ProductID>P-229V-12.2.4</ProductID>
            <ProductID>P-229V-12.2.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="204" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0567</Title>
      <Notes>
         <Note Audience="All" Ordinal="204" Title="Details" Type="Details">Vulnerability in the Oracle E-Business Intelligence component of Oracle E-Business Suite (subcomponent: Embedded Data Warehouse).  Supported versions that are affected are 11.5.10.2, 12.1.1, 12.1.2 and  12.1.3. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle E-Business Intelligence accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0567</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-163V-11.5.10.2</ProductID>
            <ProductID>P-163V-12.1.1</ProductID>
            <ProductID>P-163V-12.1.2</ProductID>
            <ProductID>P-163V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-163V-11.5.10.2</ProductID>
            <ProductID>P-163V-12.1.1</ProductID>
            <ProductID>P-163V-12.1.2</ProductID>
            <ProductID>P-163V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="205" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0568</Title>
      <Notes>
         <Note Audience="All" Ordinal="205" Title="Details" Type="Details">Vulnerability in the Oracle Email Center component of Oracle E-Business Suite (subcomponent: Server Components).  Supported versions that are affected are 12.1.1, 12.1.2 and  12.1.3. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Email Center accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0568</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-950V-12.1.1</ProductID>
            <ProductID>P-950V-12.1.2</ProductID>
            <ProductID>P-950V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-950V-12.1.1</ProductID>
            <ProductID>P-950V-12.1.2</ProductID>
            <ProductID>P-950V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="206" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0569</Title>
      <Notes>
         <Note Audience="All" Ordinal="206" Title="Details" Type="Details">Vulnerability in the Oracle E-Business Intelligence component of Oracle E-Business Suite (subcomponent: Overview Page/Report Rendering).  Supported versions that are affected are 11.5.10.2, 12.1.1, 12.1.2 and  12.1.3. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle E-Business Intelligence accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0569</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-163V-11.5.10.2</ProductID>
            <ProductID>P-163V-12.1.1</ProductID>
            <ProductID>P-163V-12.1.2</ProductID>
            <ProductID>P-163V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-163V-11.5.10.2</ProductID>
            <ProductID>P-163V-12.1.1</ProductID>
            <ProductID>P-163V-12.1.2</ProductID>
            <ProductID>P-163V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="207" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0570</Title>
      <Notes>
         <Note Audience="All" Ordinal="207" Title="Details" Type="Details">Vulnerability in the Oracle HCM Configuration Workbench component of Oracle E-Business Suite (subcomponent: Internal Operations).  Supported versions that are affected are 12.1.1, 12.1.2 and  12.1.3. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle HCM Configuration Workbench accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0570</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2011V-12.1.1</ProductID>
            <ProductID>P-2011V-12.1.2</ProductID>
            <ProductID>P-2011V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-2011V-12.1.1</ProductID>
            <ProductID>P-2011V-12.1.2</ProductID>
            <ProductID>P-2011V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="208" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0571</Title>
      <Notes>
         <Note Audience="All" Ordinal="208" Title="Details" Type="Details">Vulnerability in the Oracle Balanced Scorecard component of Oracle E-Business Suite (subcomponent: Scorecard Security).  Supported versions that are affected are 11.5.10.2 and  12.1. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Balanced Scorecard accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0571</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-205V-11.5.10.2</ProductID>
            <ProductID>P-205V-12.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-205V-11.5.10.2</ProductID>
            <ProductID>P-205V-12.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="209" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0572</Title>
      <Notes>
         <Note Audience="All" Ordinal="209" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Coherence Container).  Supported versions that are affected are 10.3.6, 12.1.2, 12.1.3 and  12.2.1. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized takeover of Oracle WebLogic Server possibly including arbitrary code execution within the Oracle WebLogic Server.  CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0572</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.3.6</ProductID>
            <ProductID>P-5242V-12.1.2</ProductID>
            <ProductID>P-5242V-12.1.3</ProductID>
            <ProductID>P-5242V-12.2.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-5242V-10.3.6</ProductID>
            <ProductID>P-5242V-12.1.2</ProductID>
            <ProductID>P-5242V-12.1.3</ProductID>
            <ProductID>P-5242V-12.2.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="210" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0573</Title>
      <Notes>
         <Note Audience="All" Ordinal="210" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Java Messaging Service).  Supported versions that are affected are 10.3.6, 12.1.2, 12.1.3 and  12.2.1. Easily exploitable vulnerability allows successful unauthenticated network attacks via JMS.  Successful attack of this vulnerability can result in unauthorized takeover of Oracle WebLogic Server possibly including arbitrary code execution within the Oracle WebLogic Server.  CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0573</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.3.6</ProductID>
            <ProductID>P-5242V-12.1.2</ProductID>
            <ProductID>P-5242V-12.1.3</ProductID>
            <ProductID>P-5242V-12.2.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-5242V-10.3.6</ProductID>
            <ProductID>P-5242V-12.1.2</ProductID>
            <ProductID>P-5242V-12.1.3</ProductID>
            <ProductID>P-5242V-12.2.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="211" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0574</Title>
      <Notes>
         <Note Audience="All" Ordinal="211" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components).  Supported versions that are affected are 10.3.6, 12.1.2, 12.1.3 and  12.2.1. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized takeover of Oracle WebLogic Server possibly including arbitrary code execution within the Oracle WebLogic Server.  CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0574</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.3.6</ProductID>
            <ProductID>P-5242V-12.1.2</ProductID>
            <ProductID>P-5242V-12.1.3</ProductID>
            <ProductID>P-5242V-12.2.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-5242V-10.3.6</ProductID>
            <ProductID>P-5242V-12.1.2</ProductID>
            <ProductID>P-5242V-12.1.3</ProductID>
            <ProductID>P-5242V-12.2.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="212" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0575</Title>
      <Notes>
         <Note Audience="All" Ordinal="212" Title="Details" Type="Details">Vulnerability in the Oracle Learning Management component of Oracle E-Business Suite (subcomponent: OTA Self Service).   The supported version that is affected is 11.5.10.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Learning Management accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0575</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-937V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-937V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="213" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0576</Title>
      <Notes>
         <Note Audience="All" Ordinal="213" Title="Details" Type="Details">Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: ICX LOVs).   The supported version that is affected is 11.5.10.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Application Object Library accessible data as well as  read access to all Oracle Application Object Library accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0576</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-510V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-510V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="214" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0577</Title>
      <Notes>
         <Note Audience="All" Ordinal="214" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components).  Supported versions that are affected are 10.3.6, 12.1.2, 12.1.3 and  12.2.1. Easily exploitable vulnerability allows successful unauthenticated network attacks via T3.  Successful attack of this vulnerability can result in unauthorized takeover of Oracle WebLogic Server possibly including arbitrary code execution within the Oracle WebLogic Server.  CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0577</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.3.6</ProductID>
            <ProductID>P-5242V-12.1.2</ProductID>
            <ProductID>P-5242V-12.1.3</ProductID>
            <ProductID>P-5242V-12.2.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-5242V-10.3.6</ProductID>
            <ProductID>P-5242V-12.1.2</ProductID>
            <ProductID>P-5242V-12.1.3</ProductID>
            <ProductID>P-5242V-12.2.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="215" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0578</Title>
      <Notes>
         <Note Audience="All" Ordinal="215" Title="Details" Type="Details">Vulnerability in the Oracle CRM Technology Foundation component of Oracle E-Business Suite (subcomponent: BIS Common Components).   The supported version that is affected is 11.5.10.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle CRM Technology Foundation accessible data as well as  read access to all Oracle CRM Technology Foundation accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0578</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1199V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1199V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="216" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0579</Title>
      <Notes>
         <Note Audience="All" Ordinal="216" Title="Details" Type="Details">Vulnerability in the Oracle CRM Technology Foundation component of Oracle E-Business Suite (subcomponent: BIS Common Components).   The supported version that is affected is 11.5.10.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle CRM Technology Foundation accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0579</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1199V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1199V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="217" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0580</Title>
      <Notes>
         <Note Audience="All" Ordinal="217" Title="Details" Type="Details">Vulnerability in the Oracle Report Manager component of Oracle E-Business Suite (subcomponent: Publishing).   The supported version that is affected is 11.5.10.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Report Manager.  CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0580</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-777V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-777V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="218" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0581</Title>
      <Notes>
         <Note Audience="All" Ordinal="218" Title="Details" Type="Details">Vulnerability in the Oracle Approvals Management component of Oracle E-Business Suite (subcomponent: AME Page rendering).   The supported version that is affected is 11.5.10.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Approvals Management accessible data as well as  read access to all Oracle Approvals Management accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0581</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1168V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1168V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="219" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0582</Title>
      <Notes>
         <Note Audience="All" Ordinal="219" Title="Details" Type="Details">Vulnerability in the Oracle CRM Technology Foundation component of Oracle E-Business Suite (subcomponent: BIS Common Components).   The supported version that is affected is 11.5.10.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle CRM Technology Foundation accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0582</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1199V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1199V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="220" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0583</Title>
      <Notes>
         <Note Audience="All" Ordinal="220" Title="Details" Type="Details">Vulnerability in the Oracle CRM Technology Foundation component of Oracle E-Business Suite (subcomponent: BIS Common Components).   The supported version that is affected is 11.5.10.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle CRM Technology Foundation accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0583</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1199V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1199V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="221" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0584</Title>
      <Notes>
         <Note Audience="All" Ordinal="221" Title="Details" Type="Details">Vulnerability in the Oracle CRM Technology Foundation component of Oracle E-Business Suite (subcomponent: BIS Common Components).   The supported version that is affected is 11.5.10.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle CRM Technology Foundation accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0584</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1199V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1199V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="222" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0585</Title>
      <Notes>
         <Note Audience="All" Ordinal="222" Title="Details" Type="Details">Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: ICX Error).   The supported version that is affected is 11.5.10.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Application Object Library.  CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0585</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-510V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-510V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="223" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0586</Title>
      <Notes>
         <Note Audience="All" Ordinal="223" Title="Details" Type="Details">Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: iHelp).   The supported version that is affected is 11.5.10.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Application Object Library accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0586</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-510V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-510V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="224" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0587</Title>
      <Notes>
         <Note Audience="All" Ordinal="224" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: File Processing).  Supported versions that are affected are 8.53, 8.54 and  8.55. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0587</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.53</ProductID>
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-5085V-8.53</ProductID>
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="225" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0588</Title>
      <Notes>
         <Note Audience="All" Ordinal="225" Title="Details" Type="Details">Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Consolidation Hierarchy Viewer).   The supported version that is affected is 11.5.10.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle General Ledger accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0588</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-500V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-500V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="226" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0589</Title>
      <Notes>
         <Note Audience="All" Ordinal="226" Title="Details" Type="Details">Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Menu).   The supported version that is affected is 11.5.10.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Application Object Library accessible data as well as  read access to all Oracle Application Object Library accessible data.  CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0589</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-510V-11.5.10.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-510V-11.5.10.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="227" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0590</Title>
      <Notes>
         <Note Audience="All" Ordinal="227" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise SCM Order Management component of Oracle PeopleSoft Products (subcomponent: Security).  Supported versions that are affected are 9.1 and  9.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some PeopleSoft Enterprise SCM Order Management accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0590</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5127V-9.1</ProductID>
            <ProductID>P-5127V-9.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-5127V-9.1</ProductID>
            <ProductID>P-5127V-9.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="228" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0591</Title>
      <Notes>
         <Note Audience="All" Ordinal="228" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise SCM Purchasing component of Oracle PeopleSoft Products (subcomponent: Supplier Change).  Supported versions that are affected are 9.1 and  9.2. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some PeopleSoft Enterprise SCM Purchasing accessible data as well as  read access to a subset of PeopleSoft Enterprise SCM Purchasing accessible data.  CVSS Base Score 5.5 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0591</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5133V-9.1</ProductID>
            <ProductID>P-5133V-9.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-5133V-9.1</ProductID>
            <ProductID>P-5133V-9.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="229" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0592</Title>
      <Notes>
         <Note Audience="All" Ordinal="229" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core).  Supported versions that are affected are VirtualBox prior to 4.3.36 and  prior to 5.0.14. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox.  CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0592</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-VirtualBox prior to 4.3.36</ProductID>
            <ProductID>P-8370V-prior to 5.0.14</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8370V-VirtualBox prior to 4.3.36</ProductID>
            <ProductID>P-8370V-prior to 5.0.14</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="230" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0594</Title>
      <Notes>
         <Note Audience="All" Ordinal="230" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML).  Supported versions that are affected are 5.6.21 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0594</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.21 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8478V-5.6.21 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="231" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0595</Title>
      <Notes>
         <Note Audience="All" Ordinal="231" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML).  Supported versions that are affected are 5.6.27 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0595</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="232" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0596</Title>
      <Notes>
         <Note Audience="All" Ordinal="232" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML).  Supported versions that are affected are 5.5.46 and earlier and  5.6.27 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0596</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.46 and earlier</ProductID>
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8478V-5.5.46 and earlier</ProductID>
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="233" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0597</Title>
      <Notes>
         <Note Audience="All" Ordinal="233" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer).  Supported versions that are affected are 5.5.46 and earlier, 5.6.27 and earlier and  5.7.9. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0597</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.46 and earlier</ProductID>
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
            <ProductID>P-8478V-5.7.9</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8478V-5.5.46 and earlier</ProductID>
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
            <ProductID>P-8478V-5.7.9</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="234" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0598</Title>
      <Notes>
         <Note Audience="All" Ordinal="234" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML).  Supported versions that are affected are 5.5.46 and earlier, 5.6.27 and earlier and  
5.7.9. Difficult to exploit vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 3.5 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0598</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.46 and earlier</ProductID>
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
            <ProductID>P-8478V-5.7.9</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8478V-5.5.46 and earlier</ProductID>
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
            <ProductID>P-8478V-5.7.9</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="235" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0599</Title>
      <Notes>
         <Note Audience="All" Ordinal="235" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer).   The supported version that is affected is 5.7.9. Difficult to exploit vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 3.5 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0599</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.9</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8478V-5.7.9</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="236" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0600</Title>
      <Notes>
         <Note Audience="All" Ordinal="236" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB).  Supported versions that are affected are 5.5.46 and earlier, 5.6.27 and earlier and 
5.7.9. Difficult to exploit vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server.  CVSS Base Score 3.5 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0600</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.46 and earlier</ProductID>
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
            <ProductID>P-8478V-5.7.9</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8478V-5.5.46 and earlier</ProductID>
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
            <ProductID>P-8478V-5.7.9</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="237" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0601</Title>
      <Notes>
         <Note Audience="All" Ordinal="237" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Partition).   The supported version that is affected is 5.7.9. Difficult to exploit vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 3.5 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0601</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.9</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8478V-5.7.9</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="238" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0602</Title>
      <Notes>
         <Note Audience="All" Ordinal="238" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Windows Installer).   The supported version that is affected is VirtualBox prior to 5.0.14. Very difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.  CVSS Base Score 6.2 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:H/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:L/AC:H/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0602</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-VirtualBox prior to 5.0.14</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.2</BaseScore>
            <Vector>AV:L/AC:H/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8370V-VirtualBox prior to 5.0.14</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="239" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0605</Title>
      <Notes>
         <Note Audience="All" Ordinal="239" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: General).  Supported versions that are affected are 5.6.26 and earlier. Very difficult to exploit vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:H/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0605</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.26 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:N/AC:H/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8478V-5.6.26 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="240" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0606</Title>
      <Notes>
         <Note Audience="All" Ordinal="240" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encryption).  Supported versions that are affected are 5.5.46 and earlier, 5.6.27 and earlier and  
5.7.9. Difficult to exploit vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some MySQL Server accessible data.  CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0606</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.46 and earlier</ProductID>
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
            <ProductID>P-8478V-5.7.9</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8478V-5.5.46 and earlier</ProductID>
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
            <ProductID>P-8478V-5.7.9</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="241" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0607</Title>
      <Notes>
         <Note Audience="All" Ordinal="241" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication).  Supported versions that are affected are 5.6.27 and earlier and  5.7.9. Difficult to exploit vulnerability allows successful network attacks via multiple protocols, requiring multiple authentications.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 2.8 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:M/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:M/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0607</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
            <ProductID>P-8478V-5.7.9</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.8</BaseScore>
            <Vector>AV:N/AC:M/Au:M/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
            <ProductID>P-8478V-5.7.9</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="242" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0608</Title>
      <Notes>
         <Note Audience="All" Ordinal="242" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: UDF).  Supported versions that are affected are 5.5.46 and earlier, 5.6.27 and earlier and  
5.7.9. Difficult to exploit vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 3.5 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0608</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.46 and earlier</ProductID>
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
            <ProductID>P-8478V-5.7.9</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8478V-5.5.46 and earlier</ProductID>
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
            <ProductID>P-8478V-5.7.9</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="243" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0609</Title>
      <Notes>
         <Note Audience="All" Ordinal="243" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges).  Supported versions that are affected are 5.5.46 and earlier, 5.6.27 and earlier and  
5.7.9. Very difficult to exploit vulnerability allows successful network attacks via multiple protocols, requiring multiple authentications.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 1.7 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:M/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:H/Au:M/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0609</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.46 and earlier</ProductID>
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
            <ProductID>P-8478V-5.7.9</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>1.7</BaseScore>
            <Vector>AV:N/AC:H/Au:M/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8478V-5.5.46 and earlier</ProductID>
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
            <ProductID>P-8478V-5.7.9</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="244" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0610</Title>
      <Notes>
         <Note Audience="All" Ordinal="244" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB).  Supported versions that are affected are 5.6.27 and earlier. Difficult to exploit vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 3.5 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0610</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="245" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0611</Title>
      <Notes>
         <Note Audience="All" Ordinal="245" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer).  Supported versions that are affected are 5.6.27 and earlier and  5.7.9. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0611</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
            <ProductID>P-8478V-5.7.9</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8478V-5.6.27 and earlier</ProductID>
            <ProductID>P-8478V-5.7.9</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="246" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0614</Title>
      <Notes>
         <Note Audience="All" Ordinal="246" Title="Details" Type="Details">Vulnerability in the Oracle BI Publisher component of Oracle Fusion Middleware (subcomponent: Security).  Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0 and  12.2.1.0.0. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle BI Publisher accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0614</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1479V-11.1.1.7.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
            <ProductID>P-1479V-12.2.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-1479V-11.1.1.7.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
            <ProductID>P-1479V-12.2.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="247" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0616</Title>
      <Notes>
         <Note Audience="All" Ordinal="247" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer).  Supported versions that are affected are 5.5.46 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0616</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.46 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-8478V-5.5.46 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="248" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0618</Title>
      <Notes>
         <Note Audience="All" Ordinal="248" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Zones).   The supported version that is affected is 11. Easily exploitable vulnerability requiring logon to Operating System plus additional, multiple logins to components.  Successful attack of this vulnerability can escalate attacker privileges resulting in unauthorized  read access to a subset of Solaris accessible data.  CVSS Base Score 1.4 (Confidentiality impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:M/C:P/I:N/A:N).  Oracle Vector: (AV:L/AC:L/Au:M/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0618</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>1.4</BaseScore>
            <Vector>AV:L/AC:L/Au:M/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUJan2016</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpujan2016.html</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
</cvrf:cvrfdoc>
