<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet type="text/xsl" href="2967710.xsl"?>
<?xml-stylesheet type="text/css" href="2967708.css"?>
<cvrf:cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
   <DocumentTitle xml:lang="en">Oracle Critical Patch Update Advisory - January 2022 - Oracle CVRF</DocumentTitle>
   <DocumentType xml:lang="en">Oracle Critical Patch Update Advisory</DocumentType>
   <DocumentPublisher Type="Vendor"/>
   <DocumentTracking>
      <Identification>
         <ID>CPUJan2022</ID>
      </Identification>
      <Status>Final</Status>
      <Version>6</Version>
      <RevisionHistory>
         <Revision>
            <Number>6</Number>
            <Date>2022-03-14T13:00:00-07:00</Date>
            <Description>WLS Log4j CVE version and additional CVE update</Description>
         </Revision>
      </RevisionHistory>
      <InitialReleaseDate>2022-01-18T13:00:00-07:00</InitialReleaseDate>
      <CurrentReleaseDate>2022-03-14T13:00:00-07:00</CurrentReleaseDate>
   </DocumentTracking>
   <DocumentNotes>
      <Note Audience="All" Ordinal="1" Title="Summary" Type="Summary" xml:lang="en">This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document.</Note>
   </DocumentNotes>
   <DocumentDistribution>This document is published at: https://www.oracle.com/a/tech/docs/cpujan2022cvrf.xml</DocumentDistribution>
   <DocumentReferences>
      <Reference Type="External">
         <URL>https://www.oracle.com/security-alerts/cpujan2022.html</URL>
         <Description>URL to html version of Advisory</Description>
      </Reference>
   </DocumentReferences>
   <Acknowledgments>
      <Acknowledgment>
         <Name>Abdelrhman Yousri</Name>
         <Organization>Abdelrhman Yousri</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Abderrahmane Elghoul</Name>
         <Organization>Abderrahmane Elghoul</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Abilash V L</Name>
         <Organization>Abilash V L</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Abisheik M</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Adam Willard</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Aleena Avarachan</Name>
         <Organization>Aleena Avarachan</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Alexander Kornbrust</Name>
         <Organization>Red Database Security</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ali Alzahrani</Name>
         <Organization>Ali Alzahrani</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Andrej Simko</Name>
         <Organization>Accenture</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Aniket Nimkar</Name>
         <Organization>Aniket Nimkar</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Anonymous researcher working with Trend Micro's Zero Day Initiative</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Aobo Wang of Chaitin Security Research Lab</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ashik Kunjumon</Name>
         <Organization>Ashik Kunjumon</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Dan Rabe</Name>
         <Organization>Dan Rabe</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Dhanesh Sivasamy</Name>
         <Organization>Dhanesh Sivasamy</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Dinh Ho Anh Khoa</Name>
         <Organization>Viettel Cyber Security</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Dor Tumarkin, Principal Application Security Researcher at Checkmarx</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Truffle Security Co</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Fabian Meumertzheim</Name>
         <Organization>Code Intelligence</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Frederic Quenneville</Name>
         <Organization>videotron.com</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Gaurang Maheta</Name>
         <Organization>Gaurang Maheta</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>B.Dhiyaneshwaran aka (Geek Freak)</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Hamed Ashraf</Name>
         <Organization>Hamed Ashraf</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Hans Christian Woithe</Name>
         <Organization>Hans Christian Woithe</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Harold Siyu Zang of Trustwave</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Huixin Ma of Tencent.com</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jangggg of VNPT</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jeremy Nunn</Name>
         <Organization>Trustwave</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jie Liang</Name>
         <Organization>WingTecher Lab of Tsinghua University</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jingzhou Fu</Name>
         <Organization>WingTecher Lab of Tsinghua University</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jonah T</Name>
         <Organization>Jonah T</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jonni Passki of Apple Information Security</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Kishore Hariram</Name>
         <Organization>Kishore Hariram</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Kun Yang of Chaitin Security Research Lab</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Liboheng of Tophant Starlight laboratory</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>thiscodecc of MoyunSec V-Lab</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Lidor Ben Shitrit from Orca Security</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Liying Wang</Name>
         <Organization>Liying Wang</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Lokesh Rulz</Name>
         <Organization>Lokesh Rulz</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Longofo</Name>
         <Organization>Knownsec 404 Team</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Lucas Leong (wmliang) of Trend Micro Zero Day Initiative</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Malicious.Group</Name>
         <Organization>Malicious.Group</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Markus Loewe</Name>
         <Organization>Markus Loewe</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Matei "Mal" Badanoiu</Name>
         <Organization>Matei "Mal" Badanoiu</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Mohit Ahir</Name>
         <Organization>Mohit Ahir</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>N3td1v3r</Name>
         <Organization>N3td1v3r</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Patrick Star</Name>
         <Organization>BMH Security Team</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Quan Doan of R&amp;D Center - VinCSS LLC (a member of Vingroup)</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>RE:HACK</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Rahul PS</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Reno Robert working with Trend Micro Zero Day Initiative</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Rob Evans</Name>
         <Organization>Fortinet, Inc.</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Robin Textor</Name>
         <Organization>Robin Textor</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Rounak Sharma</Name>
         <Organization>Rounak Sharma</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ryota Shiga (Ga_ryo_) of Flatt Security working with Trend Micro Zero Day Initiative</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Sakhare Vinayak</Name>
         <Organization>Sakhare Vinayak</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Samprit Das (sampritdas8)</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Sander Meijering</Name>
         <Organization>HackDefense</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Saptak Saha</Name>
         <Organization>Saptak Saha</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Sergey Temnikov</Name>
         <Organization>Amazon Web Services IT Security</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Shubham Choudhery</Name>
         <Organization>Shubham Choudhery</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Shuvam Adhikari</Name>
         <Organization>Shuvam Adhikari</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Srikar V - exp1o1t9r</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Thijmen Kooy</Name>
         <Organization>HackDefense</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Victor Rodriguez</Name>
         <Organization>Victor Rodriguez</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Yaoguang Chen</Name>
         <Organization>Ant Security Light-Year Lab</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Yeswanth Reddy</Name>
         <Organization>Yeswanth Reddy</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>osword from SGLAB of Legendsec at Qi'anxin Group</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Zhiqiang Zang of University of Texas at Austin</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Zhiyong Wu</Name>
         <Organization>WingTecher Lab of Tsinghua University</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>peterjson  - Security Engineering - VNG Corporation</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>pinkflower</Name>
         <Organization>pinkflower</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>r00t4dm</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Nightwatch Cybersecurity Research</Name>
         <Organization></Organization>
      </Acknowledgment>
   </Acknowledgments>
   <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
      <Branch Name="Oracle" Type="Vendor">
         <Branch Name="Oracle Airlines Data Model" Type="Product Family">
            <Branch Name="Airlines Data Model" Type="Product Name">
               <Branch Name="12.1.1.0.0" Type="Product Version">
                  <FullProductName ProductID="P-9587V-12.1.1.0.0">Airlines Data Model Version 12.1.1.0.0</FullProductName>
               </Branch>
               <Branch Name="12.2.0.1.0" Type="Product Version">
                  <FullProductName ProductID="P-9587V-12.2.0.1.0">Airlines Data Model Version 12.2.0.1.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Big Data Graph" Type="Product Family">
            <Branch Name="Big Data Spatial and Graph" Type="Product Name">
               <Branch Name="Prior to 23.1" Type="Product Version">
                  <FullProductName ProductID="P-11528V-Prior to 23.1">Big Data Spatial and Graph Version Prior to 23.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Commerce" Type="Product Family">
            <Branch Name="Commerce Platform" Type="Product Name">
               <Branch Name="11.3.0" Type="Product Version">
                  <FullProductName ProductID="P-9348V-11.3.0">Commerce Platform Version 11.3.0</FullProductName>
               </Branch>
               <Branch Name="11.3.1" Type="Product Version">
                  <FullProductName ProductID="P-9348V-11.3.1">Commerce Platform Version 11.3.1</FullProductName>
               </Branch>
               <Branch Name="11.3.2" Type="Product Version">
                  <FullProductName ProductID="P-9348V-11.3.2">Commerce Platform Version 11.3.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Commerce Guided Search / Oracle Commerce Experience Manager" Type="Product Name">
               <Branch Name="11.3.2" Type="Product Version">
                  <FullProductName ProductID="P-9633V-11.3.2">Commerce Guided Search / Oracle Commerce Experience Manager Version 11.3.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Communications" Type="Product Family">
            <Branch Name="Communications Services Gatekeeper" Type="Product Name">
               <Branch Name="7.0" Type="Product Version">
                  <FullProductName ProductID="P-5381V-7.0">Communications Services Gatekeeper Version 7.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Service Broker" Type="Product Name">
               <Branch Name="6.2" Type="Product Version">
                  <FullProductName ProductID="P-8565V-6.2">Communications Service Broker Version 6.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Session Border Controller" Type="Product Name">
               <Branch Name="8.2" Type="Product Version">
                  <FullProductName ProductID="P-10750V-8.2">Communications Session Border Controller Version 8.2</FullProductName>
               </Branch>
               <Branch Name="8.3" Type="Product Version">
                  <FullProductName ProductID="P-10750V-8.3">Communications Session Border Controller Version 8.3</FullProductName>
               </Branch>
               <Branch Name="8.4" Type="Product Version">
                  <FullProductName ProductID="P-10750V-8.4">Communications Session Border Controller Version 8.4</FullProductName>
               </Branch>
               <Branch Name="9.0" Type="Product Version">
                  <FullProductName ProductID="P-10750V-9.0">Communications Session Border Controller Version 9.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Enterprise Session Border Controller" Type="Product Name">
               <Branch Name="8.4" Type="Product Version">
                  <FullProductName ProductID="P-10757V-8.4">Enterprise Session Border Controller Version 8.4</FullProductName>
               </Branch>
               <Branch Name="9.0" Type="Product Version">
                  <FullProductName ProductID="P-10757V-9.0">Enterprise Session Border Controller Version 9.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Enterprise Communications Broker" Type="Product Name">
               <Branch Name="3.3" Type="Product Version">
                  <FullProductName ProductID="P-10758V-3.3">Enterprise Communications Broker Version 3.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Operations Monitor" Type="Product Name">
               <Branch Name="3.4" Type="Product Version">
                  <FullProductName ProductID="P-10761V-3.4">Communications Operations Monitor Version 3.4</FullProductName>
               </Branch>
               <Branch Name="4.2" Type="Product Version">
                  <FullProductName ProductID="P-10761V-4.2">Communications Operations Monitor Version 4.2</FullProductName>
               </Branch>
               <Branch Name="4.3" Type="Product Version">
                  <FullProductName ProductID="P-10761V-4.3">Communications Operations Monitor Version 4.3</FullProductName>
               </Branch>
               <Branch Name="4.4" Type="Product Version">
                  <FullProductName ProductID="P-10761V-4.4">Communications Operations Monitor Version 4.4</FullProductName>
               </Branch>
               <Branch Name="5.0" Type="Product Version">
                  <FullProductName ProductID="P-10761V-5.0">Communications Operations Monitor Version 5.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Interactive Session Recorder" Type="Product Name">
               <Branch Name="6.3" Type="Product Version">
                  <FullProductName ProductID="P-10765V-6.3">Communications Interactive Session Recorder Version 6.3</FullProductName>
               </Branch>
               <Branch Name="6.4" Type="Product Version">
                  <FullProductName ProductID="P-10765V-6.4">Communications Interactive Session Recorder Version 6.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications WebRTC Session Controller" Type="Product Name">
               <Branch Name="7.2.0" Type="Product Version">
                  <FullProductName ProductID="P-10811V-7.2.0">Communications WebRTC Session Controller Version 7.2.0</FullProductName>
               </Branch>
               <Branch Name="7.2.1" Type="Product Version">
                  <FullProductName ProductID="P-10811V-7.2.1">Communications WebRTC Session Controller Version 7.2.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Diameter Signaling Router (DSR)" Type="Product Name">
               <Branch Name="8.0.0.0-8.5.0.2" Type="Product Version">
                  <FullProductName ProductID="P-10899V-8.0.0.0-8.5.0.2">Communications Diameter Signaling Router (DSR) Version 8.0.0.0-8.5.0.2</FullProductName>
               </Branch>
               <Branch Name="8.3.0.0-8.5.1.0" Type="Product Version">
                  <FullProductName ProductID="P-10899V-8.3.0.0-8.5.1.0">Communications Diameter Signaling Router (DSR) Version 8.3.0.0-8.5.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications EAGLE Application Processor" Type="Product Name">
               <Branch Name="16.1-16.4" Type="Product Version">
                  <FullProductName ProductID="P-11122V-16.1-16.4">Communications EAGLE Application Processor Version 16.1-16.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="SD-WAN Edge" Type="Product Name">
               <Branch Name="9.0" Type="Product Version">
                  <FullProductName ProductID="P-13940V-9.0">SD-WAN Edge Version 9.0</FullProductName>
               </Branch>
               <Branch Name="9.1" Type="Product Version">
                  <FullProductName ProductID="P-13940V-9.1">SD-WAN Edge Version 9.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="SD-WAN Aware" Type="Product Name">
               <Branch Name="8.2" Type="Product Version">
                  <FullProductName ProductID="P-13941V-8.2">SD-WAN Aware Version 8.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Cloud Native Core Service Communication Proxy" Type="Product Name">
               <Branch Name="1.14.0" Type="Product Version">
                  <FullProductName ProductID="P-14117V-1.14.0">Communications Cloud Native Core Service Communication Proxy Version 1.14.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Cloud Native Core Network Repository Function" Type="Product Name">
               <Branch Name="1.14.0" Type="Product Version">
                  <FullProductName ProductID="P-14118V-1.14.0">Communications Cloud Native Core Network Repository Function Version 1.14.0</FullProductName>
               </Branch>
               <Branch Name="All Supported Versions" Type="Product Version">
                  <FullProductName ProductID="P-14118V-All Supported Versions">Communications Cloud Native Core Network Repository Function Version All Supported Versions</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Cloud Native Core Unified Data Repository" Type="Product Name">
               <Branch Name="1.14.0" Type="Product Version">
                  <FullProductName ProductID="P-14119V-1.14.0">Communications Cloud Native Core Unified Data Repository Version 1.14.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Cloud Native Core Binding Support Function" Type="Product Name">
               <Branch Name="1.10.0" Type="Product Version">
                  <FullProductName ProductID="P-14121V-1.10.0">Communications Cloud Native Core Binding Support Function Version 1.10.0</FullProductName>
               </Branch>
               <Branch Name="1.9.0" Type="Product Version">
                  <FullProductName ProductID="P-14121V-1.9.0">Communications Cloud Native Core Binding Support Function Version 1.9.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Cloud Native Core Security Edge Protection Proxy" Type="Product Name">
               <Branch Name="1.15.0" Type="Product Version">
                  <FullProductName ProductID="P-14123V-1.15.0">Communications Cloud Native Core Security Edge Protection Proxy Version 1.15.0</FullProductName>
               </Branch>
               <Branch Name="1.5.0" Type="Product Version">
                  <FullProductName ProductID="P-14123V-1.5.0">Communications Cloud Native Core Security Edge Protection Proxy Version 1.5.0</FullProductName>
               </Branch>
               <Branch Name="1.6.0" Type="Product Version">
                  <FullProductName ProductID="P-14123V-1.6.0">Communications Cloud Native Core Security Edge Protection Proxy Version 1.6.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Cloud Native Core Network Function Cloud Native Environment" Type="Product Name">
               <Branch Name="1.9.0" Type="Product Version">
                  <FullProductName ProductID="P-14125V-1.9.0">Communications Cloud Native Core Network Function Cloud Native Environment Version 1.9.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Cloud Native Core Console" Type="Product Name">
               <Branch Name="1.7.0" Type="Product Version">
                  <FullProductName ProductID="P-14250V-1.7.0">Communications Cloud Native Core Console Version 1.7.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Cloud Native Core Policy" Type="Product Name">
               <Branch Name="1.14.0" Type="Product Version">
                  <FullProductName ProductID="P-14277V-1.14.0">Communications Cloud Native Core Policy Version 1.14.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Cloud Native Core Automated Test Suite" Type="Product Name">
               <Branch Name="1.8.0" Type="Product Version">
                  <FullProductName ProductID="P-14488V-1.8.0">Communications Cloud Native Core Automated Test Suite Version 1.8.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Communications Applications" Type="Product Family">
            <Branch Name="Communications Billing and Revenue Management" Type="Product Name">
               <Branch Name="12.0.0.3" Type="Product Version">
                  <FullProductName ProductID="P-2136V-12.0.0.3">Communications Billing and Revenue Management Version 12.0.0.3</FullProductName>
               </Branch>
               <Branch Name="12.0.0.4" Type="Product Version">
                  <FullProductName ProductID="P-2136V-12.0.0.4">Communications Billing and Revenue Management Version 12.0.0.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Offline Mediation Controller" Type="Product Name">
               <Branch Name="12.0.0.3" Type="Product Version">
                  <FullProductName ProductID="P-2269V-12.0.0.3">Communications Offline Mediation Controller Version 12.0.0.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Design Studio" Type="Product Name">
               <Branch Name="7.3.4" Type="Product Version">
                  <FullProductName ProductID="P-2283V-7.3.4">Communications Design Studio Version 7.3.4</FullProductName>
               </Branch>
               <Branch Name="7.3.5" Type="Product Version">
                  <FullProductName ProductID="P-2283V-7.3.5">Communications Design Studio Version 7.3.5</FullProductName>
               </Branch>
               <Branch Name="7.4.0" Type="Product Version">
                  <FullProductName ProductID="P-2283V-7.4.0">Communications Design Studio Version 7.4.0</FullProductName>
               </Branch>
               <Branch Name="7.4.1" Type="Product Version">
                  <FullProductName ProductID="P-2283V-7.4.1">Communications Design Studio Version 7.4.1</FullProductName>
               </Branch>
               <Branch Name="7.4.2" Type="Product Version">
                  <FullProductName ProductID="P-2283V-7.4.2">Communications Design Studio Version 7.4.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Network Integrity" Type="Product Name">
               <Branch Name="7.3.5" Type="Product Version">
                  <FullProductName ProductID="P-4491V-7.3.5">Communications Network Integrity Version 7.3.5</FullProductName>
               </Branch>
               <Branch Name="7.3.6" Type="Product Version">
                  <FullProductName ProductID="P-4491V-7.3.6">Communications Network Integrity Version 7.3.6</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Unified Inventory Management" Type="Product Name">
               <Branch Name="7.3.0" Type="Product Version">
                  <FullProductName ProductID="P-4516V-7.3.0">Communications Unified Inventory Management Version 7.3.0</FullProductName>
               </Branch>
               <Branch Name="7.3.4" Type="Product Version">
                  <FullProductName ProductID="P-4516V-7.3.4">Communications Unified Inventory Management Version 7.3.4</FullProductName>
               </Branch>
               <Branch Name="7.3.5" Type="Product Version">
                  <FullProductName ProductID="P-4516V-7.3.5">Communications Unified Inventory Management Version 7.3.5</FullProductName>
               </Branch>
               <Branch Name="7.4.0" Type="Product Version">
                  <FullProductName ProductID="P-4516V-7.4.0">Communications Unified Inventory Management Version 7.4.0</FullProductName>
               </Branch>
               <Branch Name="7.4.1" Type="Product Version">
                  <FullProductName ProductID="P-4516V-7.4.1">Communications Unified Inventory Management Version 7.4.1</FullProductName>
               </Branch>
               <Branch Name="7.4.2" Type="Product Version">
                  <FullProductName ProductID="P-4516V-7.4.2">Communications Unified Inventory Management Version 7.4.2</FullProductName>
               </Branch>
               <Branch Name="7.5.0" Type="Product Version">
                  <FullProductName ProductID="P-4516V-7.5.0">Communications Unified Inventory Management Version 7.5.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Network Charging and Control" Type="Product Name">
               <Branch Name="12.0.1.0.0-12.0.4.0.0" Type="Product Version">
                  <FullProductName ProductID="P-4623V-12.0.1.0.0-12.0.4.0.0">Communications Network Charging and Control Version 12.0.1.0.0-12.0.4.0.0</FullProductName>
               </Branch>
               <Branch Name="6.0.1.0.0" Type="Product Version">
                  <FullProductName ProductID="P-4623V-6.0.1.0.0">Communications Network Charging and Control Version 6.0.1.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Calendar Server" Type="Product Name">
               <Branch Name="8.0.0.5.0" Type="Product Version">
                  <FullProductName ProductID="P-8494V-8.0.0.5.0">Communications Calendar Server Version 8.0.0.5.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Instant Messaging Server" Type="Product Name">
               <Branch Name="10.0.1.5.0" Type="Product Version">
                  <FullProductName ProductID="P-8495V-10.0.1.5.0">Communications Instant Messaging Server Version 10.0.1.5.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Messaging Server" Type="Product Name">
               <Branch Name="8.1" Type="Product Version">
                  <FullProductName ProductID="P-8496V-8.1">Communications Messaging Server Version 8.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Convergence" Type="Product Name">
               <Branch Name="3.0.2.2.0" Type="Product Version">
                  <FullProductName ProductID="P-8501V-3.0.2.2.0">Communications Convergence Version 3.0.2.2.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Pricing Design Center" Type="Product Name">
               <Branch Name="12.0.0.3.0" Type="Product Version">
                  <FullProductName ProductID="P-9437V-12.0.0.3.0">Communications Pricing Design Center Version 12.0.0.3.0</FullProductName>
               </Branch>
               <Branch Name="12.0.0.4.0" Type="Product Version">
                  <FullProductName ProductID="P-9437V-12.0.0.4.0">Communications Pricing Design Center Version 12.0.0.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications BRM - Elastic Charging Engine" Type="Product Name">
               <Branch Name="11.3" Type="Product Version">
                  <FullProductName ProductID="P-9742V-11.3">Communications BRM - Elastic Charging Engine Version 11.3</FullProductName>
               </Branch>
               <Branch Name="12.0" Type="Product Version">
                  <FullProductName ProductID="P-9742V-12.0">Communications BRM - Elastic Charging Engine Version 12.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Contacts Server" Type="Product Name">
               <Branch Name="8.0.0.3.0" Type="Product Version">
                  <FullProductName ProductID="P-10696V-8.0.0.3.0">Communications Contacts Server Version 8.0.0.3.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Convergent Charging Controller" Type="Product Name">
               <Branch Name="12.0.1.0.0-12.0.4.0.0" Type="Product Version">
                  <FullProductName ProductID="P-12985V-12.0.1.0.0-12.0.4.0.0">Communications Convergent Charging Controller Version 12.0.1.0.0-12.0.4.0.0</FullProductName>
               </Branch>
               <Branch Name="6.0.1.0.0" Type="Product Version">
                  <FullProductName ProductID="P-12985V-6.0.1.0.0">Communications Convergent Charging Controller Version 6.0.1.0.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Communications Data Model" Type="Product Family">
            <Branch Name="Communications Data Model" Type="Product Name">
               <Branch Name="11.3.2.1.0" Type="Product Version">
                  <FullProductName ProductID="P-4671V-11.3.2.1.0">Communications Data Model Version 11.3.2.1.0</FullProductName>
               </Branch>
               <Branch Name="11.3.2.2.0" Type="Product Version">
                  <FullProductName ProductID="P-4671V-11.3.2.2.0">Communications Data Model Version 11.3.2.2.0</FullProductName>
               </Branch>
               <Branch Name="11.3.2.3.0" Type="Product Version">
                  <FullProductName ProductID="P-4671V-11.3.2.3.0">Communications Data Model Version 11.3.2.3.0</FullProductName>
               </Branch>
               <Branch Name="12.1.0.1.0" Type="Product Version">
                  <FullProductName ProductID="P-4671V-12.1.0.1.0">Communications Data Model Version 12.1.0.1.0</FullProductName>
               </Branch>
               <Branch Name="12.1.2.0.0" Type="Product Version">
                  <FullProductName ProductID="P-4671V-12.1.2.0.0">Communications Data Model Version 12.1.2.0.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Construction and Engineering" Type="Product Family">
            <Branch Name="Primavera P6 Enterprise Project Portfolio Management" Type="Product Name">
               <Branch Name="17.12.0.0-17.12.20.0" Type="Product Version">
                  <FullProductName ProductID="P-5579V-17.12.0.0-17.12.20.0">Primavera P6 Enterprise Project Portfolio Management Version 17.12.0.0-17.12.20.0</FullProductName>
               </Branch>
               <Branch Name="18.8.0.0-18.8.24.0" Type="Product Version">
                  <FullProductName ProductID="P-5579V-18.8.0.0-18.8.24.0">Primavera P6 Enterprise Project Portfolio Management Version 18.8.0.0-18.8.24.0</FullProductName>
               </Branch>
               <Branch Name="19.12.0.0-19.12.17.0" Type="Product Version">
                  <FullProductName ProductID="P-5579V-19.12.0.0-19.12.17.0">Primavera P6 Enterprise Project Portfolio Management Version 19.12.0.0-19.12.17.0</FullProductName>
               </Branch>
               <Branch Name="19.12.0.0-19.12.18.0" Type="Product Version">
                  <FullProductName ProductID="P-5579V-19.12.0.0-19.12.18.0">Primavera P6 Enterprise Project Portfolio Management Version 19.12.0.0-19.12.18.0</FullProductName>
               </Branch>
               <Branch Name="20.12.0.0-20.12.12.0" Type="Product Version">
                  <FullProductName ProductID="P-5579V-20.12.0.0-20.12.12.0">Primavera P6 Enterprise Project Portfolio Management Version 20.12.0.0-20.12.12.0</FullProductName>
               </Branch>
               <Branch Name="20.12.0.0-20.12.9.0" Type="Product Version">
                  <FullProductName ProductID="P-5579V-20.12.0.0-20.12.9.0">Primavera P6 Enterprise Project Portfolio Management Version 20.12.0.0-20.12.9.0</FullProductName>
               </Branch>
               <Branch Name="21.12.0.0" Type="Product Version">
                  <FullProductName ProductID="P-5579V-21.12.0.0">Primavera P6 Enterprise Project Portfolio Management Version 21.12.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Primavera P6 Professional Project Management" Type="Product Name">
               <Branch Name="17.12.0.0-17.12.20.0" Type="Product Version">
                  <FullProductName ProductID="P-5580V-17.12.0.0-17.12.20.0">Primavera P6 Professional Project Management Version 17.12.0.0-17.12.20.0</FullProductName>
               </Branch>
               <Branch Name="18.8.0.0-18.8.24.0" Type="Product Version">
                  <FullProductName ProductID="P-5580V-18.8.0.0-18.8.24.0">Primavera P6 Professional Project Management Version 18.8.0.0-18.8.24.0</FullProductName>
               </Branch>
               <Branch Name="19.12.0.0-19.12.17.0" Type="Product Version">
                  <FullProductName ProductID="P-5580V-19.12.0.0-19.12.17.0">Primavera P6 Professional Project Management Version 19.12.0.0-19.12.17.0</FullProductName>
               </Branch>
               <Branch Name="20.12.0.0-20.12.9.0" Type="Product Version">
                  <FullProductName ProductID="P-5580V-20.12.0.0-20.12.9.0">Primavera P6 Professional Project Management Version 20.12.0.0-20.12.9.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Primavera Portfolio Management" Type="Product Name">
               <Branch Name="18.0.0.0-18.0.3.0" Type="Product Version">
                  <FullProductName ProductID="P-5584V-18.0.0.0-18.0.3.0">Primavera Portfolio Management Version 18.0.0.0-18.0.3.0</FullProductName>
               </Branch>
               <Branch Name="19.0.0.0-19.0.1.2" Type="Product Version">
                  <FullProductName ProductID="P-5584V-19.0.0.0-19.0.1.2">Primavera Portfolio Management Version 19.0.0.0-19.0.1.2</FullProductName>
               </Branch>
               <Branch Name="20.0.0.0" Type="Product Version">
                  <FullProductName ProductID="P-5584V-20.0.0.0">Primavera Portfolio Management Version 20.0.0.0</FullProductName>
               </Branch>
               <Branch Name="20.0.0.1" Type="Product Version">
                  <FullProductName ProductID="P-5584V-20.0.0.1">Primavera Portfolio Management Version 20.0.0.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Primavera Data Warehouse" Type="Product Name">
               <Branch Name="18.8.3.3" Type="Product Version">
                  <FullProductName ProductID="P-5585V-18.8.3.3">Primavera Data Warehouse Version 18.8.3.3</FullProductName>
               </Branch>
               <Branch Name="19.12.11.1" Type="Product Version">
                  <FullProductName ProductID="P-5585V-19.12.11.1">Primavera Data Warehouse Version 19.12.11.1</FullProductName>
               </Branch>
               <Branch Name="20.12.12.0" Type="Product Version">
                  <FullProductName ProductID="P-5585V-20.12.12.0">Primavera Data Warehouse Version 20.12.12.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Primavera Analytics" Type="Product Name">
               <Branch Name="18.8.3.3" Type="Product Version">
                  <FullProductName ProductID="P-8577V-18.8.3.3">Primavera Analytics Version 18.8.3.3</FullProductName>
               </Branch>
               <Branch Name="19.12.11.1" Type="Product Version">
                  <FullProductName ProductID="P-8577V-19.12.11.1">Primavera Analytics Version 19.12.11.1</FullProductName>
               </Branch>
               <Branch Name="20.12.12.0" Type="Product Version">
                  <FullProductName ProductID="P-8577V-20.12.12.0">Primavera Analytics Version 20.12.12.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Primavera Unifier" Type="Product Name">
               <Branch Name="17.7-17.12" Type="Product Version">
                  <FullProductName ProductID="P-10354V-17.7-17.12">Primavera Unifier Version 17.7-17.12</FullProductName>
               </Branch>
               <Branch Name="18.8" Type="Product Version">
                  <FullProductName ProductID="P-10354V-18.8">Primavera Unifier Version 18.8</FullProductName>
               </Branch>
               <Branch Name="19.12" Type="Product Version">
                  <FullProductName ProductID="P-10354V-19.12">Primavera Unifier Version 19.12</FullProductName>
               </Branch>
               <Branch Name="20.12" Type="Product Version">
                  <FullProductName ProductID="P-10354V-20.12">Primavera Unifier Version 20.12</FullProductName>
               </Branch>
               <Branch Name="21.12" Type="Product Version">
                  <FullProductName ProductID="P-10354V-21.12">Primavera Unifier Version 21.12</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Instantis EnterpriseTrack" Type="Product Name">
               <Branch Name="17.1" Type="Product Version">
                  <FullProductName ProductID="P-10563V-17.1">Instantis EnterpriseTrack Version 17.1</FullProductName>
               </Branch>
               <Branch Name="17.2" Type="Product Version">
                  <FullProductName ProductID="P-10563V-17.2">Instantis EnterpriseTrack Version 17.2</FullProductName>
               </Branch>
               <Branch Name="17.3" Type="Product Version">
                  <FullProductName ProductID="P-10563V-17.3">Instantis EnterpriseTrack Version 17.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Primavera Gateway" Type="Product Name">
               <Branch Name="17.12.0-17.12.11" Type="Product Version">
                  <FullProductName ProductID="P-10605V-17.12.0-17.12.11">Primavera Gateway Version 17.12.0-17.12.11</FullProductName>
               </Branch>
               <Branch Name="18.8.0-18.8.13" Type="Product Version">
                  <FullProductName ProductID="P-10605V-18.8.0-18.8.13">Primavera Gateway Version 18.8.0-18.8.13</FullProductName>
               </Branch>
               <Branch Name="19.12.0-19.12.12" Type="Product Version">
                  <FullProductName ProductID="P-10605V-19.12.0-19.12.12">Primavera Gateway Version 19.12.0-19.12.12</FullProductName>
               </Branch>
               <Branch Name="20.12.0-20.12.7" Type="Product Version">
                  <FullProductName ProductID="P-10605V-20.12.0-20.12.7">Primavera Gateway Version 20.12.0-20.12.7</FullProductName>
               </Branch>
               <Branch Name="21.12.0" Type="Product Version">
                  <FullProductName ProductID="P-10605V-21.12.0">Primavera Gateway Version 21.12.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Database Server" Type="Product Family">
            <Branch Name="Database - Enterprise Edition" Type="Product Name">
               <Branch Name="12.1.0.2" Type="Product Version">
                  <FullProductName ProductID="P-5V-12.1.0.2">Database - Enterprise Edition Version 12.1.0.2</FullProductName>
               </Branch>
               <Branch Name="12.2.0.1" Type="Product Version">
                  <FullProductName ProductID="P-5V-12.2.0.1">Database - Enterprise Edition Version 12.2.0.1</FullProductName>
               </Branch>
               <Branch Name="19c" Type="Product Version">
                  <FullProductName ProductID="P-5V-19c">Database - Enterprise Edition Version 19c</FullProductName>
               </Branch>
               <Branch Name="21c" Type="Product Version">
                  <FullProductName ProductID="P-5V-21c">Database - Enterprise Edition Version 21c</FullProductName>
               </Branch>
               <Branch Name="All Supported Versions" Type="Product Version">
                  <FullProductName ProductID="P-5V-All Supported Versions">Database - Enterprise Edition Version All Supported Versions</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Database Configuration Assistant" Type="Product Name">
               <Branch Name="All Supported Versions" Type="Product Version">
                  <FullProductName ProductID="P-383V-All Supported Versions">Database Configuration Assistant Version All Supported Versions</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Spatial and Graph" Type="Product Name">
               <Branch Name="All Supported Versions" Type="Product Version">
                  <FullProductName ProductID="P-619V-All Supported Versions">Spatial and Graph Version All Supported Versions</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Application Express (APEX)" Type="Product Name">
               <Branch Name="Prior to 21.1.4" Type="Product Version">
                  <FullProductName ProductID="P-1348V-Prior to 21.1.4">Application Express (APEX) Version Prior to 21.1.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Engineered Systems Utilities" Type="Product Name">
               <Branch Name="All Supported Versions" Type="Product Version">
                  <FullProductName ProductID="P-10655V-All Supported Versions">Engineered Systems Utilities Version All Supported Versions</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle E-Business Suite" Type="Product Family">
            <Branch Name="Configurator" Type="Product Name">
               <Branch Name="12.2.3-12.2.11" Type="Product Version">
                  <FullProductName ProductID="P-31V-12.2.3-12.2.11">Configurator Version 12.2.3-12.2.11</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Time and Labor" Type="Product Name">
               <Branch Name="12.2.6-12.2.11" Type="Product Version">
                  <FullProductName ProductID="P-311V-12.2.6-12.2.11">Time and Labor Version 12.2.6-12.2.11</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="iStore" Type="Product Name">
               <Branch Name="12.2.3-12.2.11" Type="Product Version">
                  <FullProductName ProductID="P-384V-12.2.3-12.2.11">iStore Version 12.2.3-12.2.11</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Trade Management" Type="Product Name">
               <Branch Name="12.2.3-12.2.11" Type="Product Version">
                  <FullProductName ProductID="P-765V-12.2.3-12.2.11">Trade Management Version 12.2.3-12.2.11</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Partner Management" Type="Product Name">
               <Branch Name="12.2.3-12.2.11" Type="Product Version">
                  <FullProductName ProductID="P-1065V-12.2.3-12.2.11">Partner Management Version 12.2.3-12.2.11</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Installed Base" Type="Product Name">
               <Branch Name="12.2.3-12.2.11" Type="Product Version">
                  <FullProductName ProductID="P-1118V-12.2.3-12.2.11">Installed Base Version 12.2.3-12.2.11</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Sourcing" Type="Product Name">
               <Branch Name="12.2.3-12.2.11" Type="Product Version">
                  <FullProductName ProductID="P-1273V-12.2.3-12.2.11">Sourcing Version 12.2.3-12.2.11</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Project Costing" Type="Product Name">
               <Branch Name="12.2.3-12.2.11" Type="Product Version">
                  <FullProductName ProductID="P-1287V-12.2.3-12.2.11">Project Costing Version 12.2.3-12.2.11</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Enterprise Manager" Type="Product Family">
            <Branch Name="Enterprise Manager Base Platform" Type="Product Name">
               <Branch Name="13.4.0.0" Type="Product Version">
                  <FullProductName ProductID="P-1370V-13.4.0.0">Enterprise Manager Base Platform Version 13.4.0.0</FullProductName>
               </Branch>
               <Branch Name="13.5.0.0" Type="Product Version">
                  <FullProductName ProductID="P-1370V-13.5.0.0">Enterprise Manager Base Platform Version 13.5.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Application Testing Suite" Type="Product Name">
               <Branch Name="13.3.0.1" Type="Product Version">
                  <FullProductName ProductID="P-4622V-13.3.0.1">Application Testing Suite Version 13.3.0.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="APM - Application Performance Management" Type="Product Name">
               <Branch Name="13.4.1.0" Type="Product Version">
                  <FullProductName ProductID="P-9572V-13.4.1.0">APM - Application Performance Management Version 13.4.1.0</FullProductName>
               </Branch>
               <Branch Name="13.5.1.0" Type="Product Version">
                  <FullProductName ProductID="P-9572V-13.5.1.0">APM - Application Performance Management Version 13.5.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Enterprise Manager Ops Center" Type="Product Name">
               <Branch Name="12.4.0.0" Type="Product Version">
                  <FullProductName ProductID="P-9835V-12.4.0.0">Enterprise Manager Ops Center Version 12.4.0.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Essbase" Type="Product Family">
            <Branch Name="Hyperion Essbase" Type="Product Name">
               <Branch Name="All Supported Versions" Type="Product Version">
                  <FullProductName ProductID="P-4379V-All Supported Versions">Hyperion Essbase Version All Supported Versions</FullProductName>
               </Branch>
               <Branch Name="Prior to 11.1.2.4.047" Type="Product Version">
                  <FullProductName ProductID="P-4379V-Prior to 11.1.2.4.047">Hyperion Essbase Version Prior to 11.1.2.4.047</FullProductName>
               </Branch>
               <Branch Name="Prior to 21.3" Type="Product Version">
                  <FullProductName ProductID="P-4379V-Prior to 21.3">Hyperion Essbase Version Prior to 21.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Hyperion Essbase Administration Services" Type="Product Name">
               <Branch Name="Prior to 11.1.2.4.047" Type="Product Version">
                  <FullProductName ProductID="P-4380V-Prior to 11.1.2.4.047">Hyperion Essbase Administration Services Version Prior to 11.1.2.4.047</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Financial Services Applications" Type="Product Family">
            <Branch Name="Financial Services Analytical Applications Infrastructure" Type="Product Name">
               <Branch Name="8.0.7-8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-5680V-8.0.7-8.1.1">Financial Services Analytical Applications Infrastructure Version 8.0.7-8.1.1</FullProductName>
               </Branch>
               <Branch Name="8.0.8-8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-5680V-8.0.8-8.1.1">Financial Services Analytical Applications Infrastructure Version 8.0.8-8.1.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="FLEXCUBE Investor Servicing" Type="Product Name">
               <Branch Name="12.0.4" Type="Product Version">
                  <FullProductName ProductID="P-9099V-12.0.4">FLEXCUBE Investor Servicing Version 12.0.4</FullProductName>
               </Branch>
               <Branch Name="12.1.0" Type="Product Version">
                  <FullProductName ProductID="P-9099V-12.1.0">FLEXCUBE Investor Servicing Version 12.1.0</FullProductName>
               </Branch>
               <Branch Name="12.3.0" Type="Product Version">
                  <FullProductName ProductID="P-9099V-12.3.0">FLEXCUBE Investor Servicing Version 12.3.0</FullProductName>
               </Branch>
               <Branch Name="12.4.0" Type="Product Version">
                  <FullProductName ProductID="P-9099V-12.4.0">FLEXCUBE Investor Servicing Version 12.4.0</FullProductName>
               </Branch>
               <Branch Name="14.4.0" Type="Product Version">
                  <FullProductName ProductID="P-9099V-14.4.0">FLEXCUBE Investor Servicing Version 14.4.0</FullProductName>
               </Branch>
               <Branch Name="14.5.0" Type="Product Version">
                  <FullProductName ProductID="P-9099V-14.5.0">FLEXCUBE Investor Servicing Version 14.5.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="FLEXCUBE Private Banking" Type="Product Name">
               <Branch Name="12.0.0" Type="Product Version">
                  <FullProductName ProductID="P-9110V-12.0.0">FLEXCUBE Private Banking Version 12.0.0</FullProductName>
               </Branch>
               <Branch Name="12.1.0" Type="Product Version">
                  <FullProductName ProductID="P-9110V-12.1.0">FLEXCUBE Private Banking Version 12.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Banking Platform" Type="Product Name">
               <Branch Name="2.3.0-2.4.1" Type="Product Version">
                  <FullProductName ProductID="P-9178V-2.3.0-2.4.1">Banking Platform Version 2.3.0-2.4.1</FullProductName>
               </Branch>
               <Branch Name="2.6.2" Type="Product Version">
                  <FullProductName ProductID="P-9178V-2.6.2">Banking Platform Version 2.6.2</FullProductName>
               </Branch>
               <Branch Name="2.7.0" Type="Product Version">
                  <FullProductName ProductID="P-9178V-2.7.0">Banking Platform Version 2.7.0</FullProductName>
               </Branch>
               <Branch Name="2.7.1" Type="Product Version">
                  <FullProductName ProductID="P-9178V-2.7.1">Banking Platform Version 2.7.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Behavior Detection Platform" Type="Product Name">
               <Branch Name="8.0.7" Type="Product Version">
                  <FullProductName ProductID="P-9190V-8.0.7">Financial Services Behavior Detection Platform Version 8.0.7</FullProductName>
               </Branch>
               <Branch Name="8.0.8" Type="Product Version">
                  <FullProductName ProductID="P-9190V-8.0.8">Financial Services Behavior Detection Platform Version 8.0.8</FullProductName>
               </Branch>
               <Branch Name="8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-9190V-8.1.1">Financial Services Behavior Detection Platform Version 8.1.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Foreign Account Tax Compliance Act Management" Type="Product Name">
               <Branch Name="8.0.7" Type="Product Version">
                  <FullProductName ProductID="P-10308V-8.0.7">Financial Services Foreign Account Tax Compliance Act Management Version 8.0.7</FullProductName>
               </Branch>
               <Branch Name="8.0.8" Type="Product Version">
                  <FullProductName ProductID="P-10308V-8.0.8">Financial Services Foreign Account Tax Compliance Act Management Version 8.0.8</FullProductName>
               </Branch>
               <Branch Name="8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-10308V-8.1.1">Financial Services Foreign Account Tax Compliance Act Management Version 8.1.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Banking Digital Experience" Type="Product Name">
               <Branch Name="17.2" Type="Product Version">
                  <FullProductName ProductID="P-12605V-17.2">Banking Digital Experience Version 17.2</FullProductName>
               </Branch>
               <Branch Name="18.1-18.3" Type="Product Version">
                  <FullProductName ProductID="P-12605V-18.1-18.3">Banking Digital Experience Version 18.1-18.3</FullProductName>
               </Branch>
               <Branch Name="18.3" Type="Product Version">
                  <FullProductName ProductID="P-12605V-18.3">Banking Digital Experience Version 18.3</FullProductName>
               </Branch>
               <Branch Name="19.1" Type="Product Version">
                  <FullProductName ProductID="P-12605V-19.1">Banking Digital Experience Version 19.1</FullProductName>
               </Branch>
               <Branch Name="19.2" Type="Product Version">
                  <FullProductName ProductID="P-12605V-19.2">Banking Digital Experience Version 19.2</FullProductName>
               </Branch>
               <Branch Name="20.1" Type="Product Version">
                  <FullProductName ProductID="P-12605V-20.1">Banking Digital Experience Version 20.1</FullProductName>
               </Branch>
               <Branch Name="21.1" Type="Product Version">
                  <FullProductName ProductID="P-12605V-21.1">Banking Digital Experience Version 21.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Banking Enterprise Default Management" Type="Product Name">
               <Branch Name="2.10.0" Type="Product Version">
                  <FullProductName ProductID="P-13390V-2.10.0">Banking Enterprise Default Management Version 2.10.0</FullProductName>
               </Branch>
               <Branch Name="2.12.0" Type="Product Version">
                  <FullProductName ProductID="P-13390V-2.12.0">Banking Enterprise Default Management Version 2.12.0</FullProductName>
               </Branch>
               <Branch Name="2.3.0-2.4.1" Type="Product Version">
                  <FullProductName ProductID="P-13390V-2.3.0-2.4.1">Banking Enterprise Default Management Version 2.3.0-2.4.1</FullProductName>
               </Branch>
               <Branch Name="2.6.2" Type="Product Version">
                  <FullProductName ProductID="P-13390V-2.6.2">Banking Enterprise Default Management Version 2.6.2</FullProductName>
               </Branch>
               <Branch Name="2.7.0" Type="Product Version">
                  <FullProductName ProductID="P-13390V-2.7.0">Banking Enterprise Default Management Version 2.7.0</FullProductName>
               </Branch>
               <Branch Name="2.7.1" Type="Product Version">
                  <FullProductName ProductID="P-13390V-2.7.1">Banking Enterprise Default Management Version 2.7.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Enterprise Case Management" Type="Product Name">
               <Branch Name="8.0.7" Type="Product Version">
                  <FullProductName ProductID="P-13545V-8.0.7">Financial Services Enterprise Case Management Version 8.0.7</FullProductName>
               </Branch>
               <Branch Name="8.0.8" Type="Product Version">
                  <FullProductName ProductID="P-13545V-8.0.8">Financial Services Enterprise Case Management Version 8.0.8</FullProductName>
               </Branch>
               <Branch Name="8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-13545V-8.1.1">Financial Services Enterprise Case Management Version 8.1.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Banking APIs" Type="Product Name">
               <Branch Name="18.1-18.3" Type="Product Version">
                  <FullProductName ProductID="P-13676V-18.1-18.3">Banking APIs Version 18.1-18.3</FullProductName>
               </Branch>
               <Branch Name="18.3" Type="Product Version">
                  <FullProductName ProductID="P-13676V-18.3">Banking APIs Version 18.3</FullProductName>
               </Branch>
               <Branch Name="19.1" Type="Product Version">
                  <FullProductName ProductID="P-13676V-19.1">Banking APIs Version 19.1</FullProductName>
               </Branch>
               <Branch Name="19.2" Type="Product Version">
                  <FullProductName ProductID="P-13676V-19.2">Banking APIs Version 19.2</FullProductName>
               </Branch>
               <Branch Name="20.1" Type="Product Version">
                  <FullProductName ProductID="P-13676V-20.1">Banking APIs Version 20.1</FullProductName>
               </Branch>
               <Branch Name="21.1" Type="Product Version">
                  <FullProductName ProductID="P-13676V-21.1">Banking APIs Version 21.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Trade-Based Anti Money Laundering Enterprise Edition" Type="Product Name">
               <Branch Name="8.0.7" Type="Product Version">
                  <FullProductName ProductID="P-13789V-8.0.7">Financial Services Trade-Based Anti Money Laundering Enterprise Edition Version 8.0.7</FullProductName>
               </Branch>
               <Branch Name="8.0.8" Type="Product Version">
                  <FullProductName ProductID="P-13789V-8.0.8">Financial Services Trade-Based Anti Money Laundering Enterprise Edition Version 8.0.8</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Banking Loans Servicing" Type="Product Name">
               <Branch Name="2.12.0" Type="Product Version">
                  <FullProductName ProductID="P-13927V-2.12.0">Banking Loans Servicing Version 2.12.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Banking Deposits and Lines of Credit Servicing" Type="Product Name">
               <Branch Name="2.12.0" Type="Product Version">
                  <FullProductName ProductID="P-13928V-2.12.0">Banking Deposits and Lines of Credit Servicing Version 2.12.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Banking Party Management" Type="Product Name">
               <Branch Name="2.7.0" Type="Product Version">
                  <FullProductName ProductID="P-13929V-2.7.0">Banking Party Management Version 2.7.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Model Management and Governance" Type="Product Name">
               <Branch Name="8.0.8" Type="Product Version">
                  <FullProductName ProductID="P-14276V-8.0.8">Financial Services Model Management and Governance Version 8.0.8</FullProductName>
               </Branch>
               <Branch Name="8.0.8-8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-14276V-8.0.8-8.1.1">Financial Services Model Management and Governance Version 8.0.8-8.1.1</FullProductName>
               </Branch>
               <Branch Name="8.1.0" Type="Product Version">
                  <FullProductName ProductID="P-14276V-8.1.0">Financial Services Model Management and Governance Version 8.1.0</FullProductName>
               </Branch>
               <Branch Name="8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-14276V-8.1.1">Financial Services Model Management and Governance Version 8.1.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Food and Beverage Applications" Type="Product Family">
            <Branch Name="Hospitality Reporting and Analytics" Type="Product Name">
               <Branch Name="9.1.0" Type="Product Version">
                  <FullProductName ProductID="P-11599V-9.1.0">Hospitality Reporting and Analytics Version 9.1.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Fusion Middleware" Type="Product Family">
            <Branch Name="Fusion Middleware" Type="Product Name">
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1032V-12.2.1.3.0">Fusion Middleware Version 12.2.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-1032V-12.2.1.4.0">Fusion Middleware Version 12.2.1.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="HTTP Server" Type="Product Name">
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1042V-12.2.1.3.0">HTTP Server Version 12.2.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-1042V-12.2.1.4.0">HTTP Server Version 12.2.1.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Fusion Middleware MapViewer" Type="Product Name">
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-1215V-12.2.1.4.0">Fusion Middleware MapViewer Version 12.2.1.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="BI Publisher (formerly XML Publisher)" Type="Product Name">
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1479V-12.2.1.3.0">BI Publisher (formerly XML Publisher) Version 12.2.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-1479V-12.2.1.4.0">BI Publisher (formerly XML Publisher) Version 12.2.1.4.0</FullProductName>
               </Branch>
               <Branch Name="5.5.0.0.0" Type="Product Version">
                  <FullProductName ProductID="P-1479V-5.5.0.0.0">BI Publisher (formerly XML Publisher) Version 5.5.0.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="BAM (Business Activity Monitoring)" Type="Product Name">
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-1675V-12.2.1.4.0">BAM (Business Activity Monitoring) Version 12.2.1.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="WebCenter Portal" Type="Product Name">
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1696V-12.2.1.3.0">WebCenter Portal Version 12.2.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-1696V-12.2.1.4.0">WebCenter Portal Version 12.2.1.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Business Intelligence Enterprise Edition" Type="Product Name">
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-2025V-12.2.1.3.0">Business Intelligence Enterprise Edition Version 12.2.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-2025V-12.2.1.4.0">Business Intelligence Enterprise Edition Version 12.2.1.4.0</FullProductName>
               </Branch>
               <Branch Name="5.5.0.0.0" Type="Product Version">
                  <FullProductName ProductID="P-2025V-5.5.0.0.0">Business Intelligence Enterprise Edition Version 5.5.0.0.0</FullProductName>
               </Branch>
               <Branch Name="5.9.0.0.0" Type="Product Version">
                  <FullProductName ProductID="P-2025V-5.9.0.0.0">Business Intelligence Enterprise Edition Version 5.9.0.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Data Integrator" Type="Product Name">
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-2196V-12.2.1.3.0">Data Integrator Version 12.2.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-2196V-12.2.1.4.0">Data Integrator Version 12.2.1.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="WebLogic Server" Type="Product Name">
               <Branch Name="12.1.3.0.0" Type="Product Version">
                  <FullProductName ProductID="P-5242V-12.1.3.0.0">WebLogic Server Version 12.1.3.0.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-5242V-12.2.1.3.0">WebLogic Server Version 12.2.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-5242V-12.2.1.4.0">WebLogic Server Version 12.2.1.4.0</FullProductName>
               </Branch>
               <Branch Name="14.1.1.0.0" Type="Product Version">
                  <FullProductName ProductID="P-5242V-14.1.1.0.0">WebLogic Server Version 14.1.1.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Business Process Management Suite" Type="Product Name">
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-5325V-12.2.1.3.0">Business Process Management Suite Version 12.2.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-5325V-12.2.1.4.0">Business Process Management Suite Version 12.2.1.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Access Manager" Type="Product Name">
               <Branch Name="11.1.2.3.0" Type="Product Version">
                  <FullProductName ProductID="P-5565V-11.1.2.3.0">Access Manager Version 11.1.2.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-5565V-12.2.1.3.0">Access Manager Version 12.2.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-5565V-12.2.1.4.0">Access Manager Version 12.2.1.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Enterprise Data Quality" Type="Product Name">
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-9464V-12.2.1.3.0">Enterprise Data Quality Version 12.2.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-9464V-12.2.1.4.0">Enterprise Data Quality Version 12.2.1.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Managed File Transfer" Type="Product Name">
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-10198V-12.2.1.3.0">Managed File Transfer Version 12.2.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-10198V-12.2.1.4.0">Managed File Transfer Version 12.2.1.4.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle GoldenGate" Type="Product Family">
            <Branch Name="GoldenGate" Type="Product Name">
               <Branch Name="Prior to 12.3.0.1" Type="Product Version">
                  <FullProductName ProductID="P-5757V-Prior to 12.3.0.1">GoldenGate Version Prior to 12.3.0.1</FullProductName>
               </Branch>
               <Branch Name="Prior to 19.1.0.0.220118" Type="Product Version">
                  <FullProductName ProductID="P-5757V-Prior to 19.1.0.0.220118">GoldenGate Version Prior to 19.1.0.0.220118</FullProductName>
               </Branch>
               <Branch Name="Prior to 21.4.0.0.0" Type="Product Version">
                  <FullProductName ProductID="P-5757V-Prior to 21.4.0.0.0">GoldenGate Version Prior to 21.4.0.0.0</FullProductName>
               </Branch>
               <Branch Name="Prior to 21.5.0.0.220118" Type="Product Version">
                  <FullProductName ProductID="P-5757V-Prior to 21.5.0.0.220118">GoldenGate Version Prior to 21.5.0.0.220118</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Graph Server and Client" Type="Product Family">
            <Branch Name="Graph Server and Client" Type="Product Name">
               <Branch Name="All Supported Versions" Type="Product Version">
                  <FullProductName ProductID="P-14069V-All Supported Versions">Graph Server and Client Version All Supported Versions</FullProductName>
               </Branch>
               <Branch Name="Prior to 21.4" Type="Product Version">
                  <FullProductName ProductID="P-14069V-Prior to 21.4">Graph Server and Client Version Prior to 21.4</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Health Sciences Applications" Type="Product Family">
            <Branch Name="Thesaurus Management System" Type="Product Name">
               <Branch Name="5.2.3" Type="Product Version">
                  <FullProductName ProductID="P-192V-5.2.3">Thesaurus Management System Version 5.2.3</FullProductName>
               </Branch>
               <Branch Name="5.3.0" Type="Product Version">
                  <FullProductName ProductID="P-192V-5.3.0">Thesaurus Management System Version 5.3.0</FullProductName>
               </Branch>
               <Branch Name="5.3.1" Type="Product Version">
                  <FullProductName ProductID="P-192V-5.3.1">Thesaurus Management System Version 5.3.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Clinical" Type="Product Name">
               <Branch Name="5.2.1" Type="Product Version">
                  <FullProductName ProductID="P-801V-5.2.1">Clinical Version 5.2.1</FullProductName>
               </Branch>
               <Branch Name="5.2.2" Type="Product Version">
                  <FullProductName ProductID="P-801V-5.2.2">Clinical Version 5.2.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Health Sciences Clinical Development Analytics" Type="Product Name">
               <Branch Name="4.0.1" Type="Product Version">
                  <FullProductName ProductID="P-5563V-4.0.1">Health Sciences Clinical Development Analytics Version 4.0.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Argus Safety" Type="Product Name">
               <Branch Name="8.2.1" Type="Product Version">
                  <FullProductName ProductID="P-5710V-8.2.1">Argus Safety Version 8.2.1</FullProductName>
               </Branch>
               <Branch Name="8.2.2" Type="Product Version">
                  <FullProductName ProductID="P-5710V-8.2.2">Argus Safety Version 8.2.2</FullProductName>
               </Branch>
               <Branch Name="8.2.3" Type="Product Version">
                  <FullProductName ProductID="P-5710V-8.2.3">Argus Safety Version 8.2.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Argus Insight" Type="Product Name">
               <Branch Name="8.2.1" Type="Product Version">
                  <FullProductName ProductID="P-5717V-8.2.1">Argus Insight Version 8.2.1</FullProductName>
               </Branch>
               <Branch Name="8.2.2" Type="Product Version">
                  <FullProductName ProductID="P-5717V-8.2.2">Argus Insight Version 8.2.2</FullProductName>
               </Branch>
               <Branch Name="8.2.3" Type="Product Version">
                  <FullProductName ProductID="P-5717V-8.2.3">Argus Insight Version 8.2.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Argus Analytics" Type="Product Name">
               <Branch Name="8.2.1" Type="Product Version">
                  <FullProductName ProductID="P-9171V-8.2.1">Argus Analytics Version 8.2.1</FullProductName>
               </Branch>
               <Branch Name="8.2.2" Type="Product Version">
                  <FullProductName ProductID="P-9171V-8.2.2">Argus Analytics Version 8.2.2</FullProductName>
               </Branch>
               <Branch Name="8.2.3" Type="Product Version">
                  <FullProductName ProductID="P-9171V-8.2.3">Argus Analytics Version 8.2.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Health Sciences InForm CRF Submit" Type="Product Name">
               <Branch Name="6.2.1" Type="Product Version">
                  <FullProductName ProductID="P-9641V-6.2.1">Health Sciences InForm CRF Submit Version 6.2.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Argus Mart" Type="Product Name">
               <Branch Name="8.2.1" Type="Product Version">
                  <FullProductName ProductID="P-10383V-8.2.1">Argus Mart Version 8.2.1</FullProductName>
               </Branch>
               <Branch Name="8.2.2" Type="Product Version">
                  <FullProductName ProductID="P-10383V-8.2.2">Argus Mart Version 8.2.2</FullProductName>
               </Branch>
               <Branch Name="8.2.3" Type="Product Version">
                  <FullProductName ProductID="P-10383V-8.2.3">Argus Mart Version 8.2.3</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle HealthCare Applications" Type="Product Family">
            <Branch Name="Healthcare Data Repository" Type="Product Name">
               <Branch Name="7.0.2" Type="Product Version">
                  <FullProductName ProductID="P-9161V-7.0.2">Healthcare Data Repository Version 7.0.2</FullProductName>
               </Branch>
               <Branch Name="8.1.0" Type="Product Version">
                  <FullProductName ProductID="P-9161V-8.1.0">Healthcare Data Repository Version 8.1.0</FullProductName>
               </Branch>
               <Branch Name="8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-9161V-8.1.1">Healthcare Data Repository Version 8.1.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Health Sciences Information Manager" Type="Product Name">
               <Branch Name="3.0.2" Type="Product Version">
                  <FullProductName ProductID="P-9177V-3.0.2">Health Sciences Information Manager Version 3.0.2</FullProductName>
               </Branch>
               <Branch Name="3.0.3" Type="Product Version">
                  <FullProductName ProductID="P-9177V-3.0.3">Health Sciences Information Manager Version 3.0.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Healthcare Translational Research" Type="Product Name">
               <Branch Name="4.1.0" Type="Product Version">
                  <FullProductName ProductID="P-9427V-4.1.0">Healthcare Translational Research Version 4.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Healthcare Foundation" Type="Product Name">
               <Branch Name="7.3.0.0-7.3.0.2" Type="Product Version">
                  <FullProductName ProductID="P-12950V-7.3.0.0-7.3.0.2">Healthcare Foundation Version 7.3.0.0-7.3.0.2</FullProductName>
               </Branch>
               <Branch Name="8.0.0-8.0.2" Type="Product Version">
                  <FullProductName ProductID="P-12950V-8.0.0-8.0.2">Healthcare Foundation Version 8.0.0-8.0.2</FullProductName>
               </Branch>
               <Branch Name="8.1.0-8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-12950V-8.1.0-8.1.1">Healthcare Foundation Version 8.1.0-8.1.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Hospitality Applications" Type="Product Family">
            <Branch Name="Hospitality OPERA 5 Property Services" Type="Product Name">
               <Branch Name="5.6" Type="Product Version">
                  <FullProductName ProductID="P-11580V-5.6">Hospitality OPERA 5 Property Services Version 5.6</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Hospitality Cruise Shipboard Property Management System" Type="Product Name">
               <Branch Name="20.1.0" Type="Product Version">
                  <FullProductName ProductID="P-11607V-20.1.0">Hospitality Cruise Shipboard Property Management System Version 20.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Hospitality Suite8" Type="Product Name">
               <Branch Name="8.10.2" Type="Product Version">
                  <FullProductName ProductID="P-12619V-8.10.2">Hospitality Suite8 Version 8.10.2</FullProductName>
               </Branch>
               <Branch Name="8.11.0" Type="Product Version">
                  <FullProductName ProductID="P-12619V-8.11.0">Hospitality Suite8 Version 8.11.0</FullProductName>
               </Branch>
               <Branch Name="8.12.0" Type="Product Version">
                  <FullProductName ProductID="P-12619V-8.12.0">Hospitality Suite8 Version 8.12.0</FullProductName>
               </Branch>
               <Branch Name="8.13.0" Type="Product Version">
                  <FullProductName ProductID="P-12619V-8.13.0">Hospitality Suite8 Version 8.13.0</FullProductName>
               </Branch>
               <Branch Name="8.14.0" Type="Product Version">
                  <FullProductName ProductID="P-12619V-8.14.0">Hospitality Suite8 Version 8.14.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Hyperion" Type="Product Family">
            <Branch Name="Hyperion Infrastructure Technology" Type="Product Name">
               <Branch Name="11.2.7.0" Type="Product Version">
                  <FullProductName ProductID="P-4392V-11.2.7.0">Hyperion Infrastructure Technology Version 11.2.7.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Insurance Applications" Type="Product Family">
            <Branch Name="Insurance Policy Administration J2EE" Type="Product Name">
               <Branch Name="10.2.0" Type="Product Version">
                  <FullProductName ProductID="P-5279V-10.2.0">Insurance Policy Administration J2EE Version 10.2.0</FullProductName>
               </Branch>
               <Branch Name="10.2.4" Type="Product Version">
                  <FullProductName ProductID="P-5279V-10.2.4">Insurance Policy Administration J2EE Version 10.2.4</FullProductName>
               </Branch>
               <Branch Name="11.0.2" Type="Product Version">
                  <FullProductName ProductID="P-5279V-11.0.2">Insurance Policy Administration J2EE Version 11.0.2</FullProductName>
               </Branch>
               <Branch Name="11.1.0" Type="Product Version">
                  <FullProductName ProductID="P-5279V-11.1.0">Insurance Policy Administration J2EE Version 11.1.0</FullProductName>
               </Branch>
               <Branch Name="11.1.0-11.3.0" Type="Product Version">
                  <FullProductName ProductID="P-5279V-11.1.0-11.3.0">Insurance Policy Administration J2EE Version 11.1.0-11.3.0</FullProductName>
               </Branch>
               <Branch Name="11.2.7" Type="Product Version">
                  <FullProductName ProductID="P-5279V-11.2.7">Insurance Policy Administration J2EE Version 11.2.7</FullProductName>
               </Branch>
               <Branch Name="11.3.0" Type="Product Version">
                  <FullProductName ProductID="P-5279V-11.3.0">Insurance Policy Administration J2EE Version 11.3.0</FullProductName>
               </Branch>
               <Branch Name="11.3.1" Type="Product Version">
                  <FullProductName ProductID="P-5279V-11.3.1">Insurance Policy Administration J2EE Version 11.3.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Insurance Rules Palette" Type="Product Name">
               <Branch Name="10.2.0" Type="Product Version">
                  <FullProductName ProductID="P-5288V-10.2.0">Insurance Rules Palette Version 10.2.0</FullProductName>
               </Branch>
               <Branch Name="10.2.4" Type="Product Version">
                  <FullProductName ProductID="P-5288V-10.2.4">Insurance Rules Palette Version 10.2.4</FullProductName>
               </Branch>
               <Branch Name="11.0.2" Type="Product Version">
                  <FullProductName ProductID="P-5288V-11.0.2">Insurance Rules Palette Version 11.0.2</FullProductName>
               </Branch>
               <Branch Name="11.1.0" Type="Product Version">
                  <FullProductName ProductID="P-5288V-11.1.0">Insurance Rules Palette Version 11.1.0</FullProductName>
               </Branch>
               <Branch Name="11.1.0-11.3.0" Type="Product Version">
                  <FullProductName ProductID="P-5288V-11.1.0-11.3.0">Insurance Rules Palette Version 11.1.0-11.3.0</FullProductName>
               </Branch>
               <Branch Name="11.2.7" Type="Product Version">
                  <FullProductName ProductID="P-5288V-11.2.7">Insurance Rules Palette Version 11.2.7</FullProductName>
               </Branch>
               <Branch Name="11.3.0" Type="Product Version">
                  <FullProductName ProductID="P-5288V-11.3.0">Insurance Rules Palette Version 11.3.0</FullProductName>
               </Branch>
               <Branch Name="11.3.1" Type="Product Version">
                  <FullProductName ProductID="P-5288V-11.3.1">Insurance Rules Palette Version 11.3.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Insurance Insbridge Rating and Underwriting" Type="Product Name">
               <Branch Name="5.2.0" Type="Product Version">
                  <FullProductName ProductID="P-5484V-5.2.0">Insurance Insbridge Rating and Underwriting Version 5.2.0</FullProductName>
               </Branch>
               <Branch Name="5.4.0-5.6.0" Type="Product Version">
                  <FullProductName ProductID="P-5484V-5.4.0-5.6.0">Insurance Insbridge Rating and Underwriting Version 5.4.0-5.6.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Insurance Data Gateway" Type="Product Name">
               <Branch Name="11.0.2" Type="Product Version">
                  <FullProductName ProductID="P-13628V-11.0.2">Insurance Data Gateway Version 11.0.2</FullProductName>
               </Branch>
               <Branch Name="11.1.0" Type="Product Version">
                  <FullProductName ProductID="P-13628V-11.1.0">Insurance Data Gateway Version 11.1.0</FullProductName>
               </Branch>
               <Branch Name="11.2.7" Type="Product Version">
                  <FullProductName ProductID="P-13628V-11.2.7">Insurance Data Gateway Version 11.2.7</FullProductName>
               </Branch>
               <Branch Name="11.3.0" Type="Product Version">
                  <FullProductName ProductID="P-13628V-11.3.0">Insurance Data Gateway Version 11.3.0</FullProductName>
               </Branch>
               <Branch Name="11.3.1" Type="Product Version">
                  <FullProductName ProductID="P-13628V-11.3.1">Insurance Data Gateway Version 11.3.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle JD Edwards" Type="Product Family">
            <Branch Name="JD Edwards EnterpriseOne Tools" Type="Product Name">
               <Branch Name="Prior to 9.2.6.1" Type="Product Version">
                  <FullProductName ProductID="P-4781V-Prior to 9.2.6.1">JD Edwards EnterpriseOne Tools Version Prior to 9.2.6.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Java SE" Type="Product Family">
            <Branch Name="Java SE JDK and JRE" Type="Product Name">
               <Branch Name="Oracle GraalVM Enterprise Edition:20.3.4" Type="Product Version">
                  <FullProductName ProductID="P-14564V-Oracle GraalVM Enterprise Edition:20.3.4">Java SE JDK and JRE Version Oracle GraalVM Enterprise Edition:20.3.4</FullProductName>
               </Branch>
               <Branch Name="Oracle GraalVM Enterprise Edition:21.3.0" Type="Product Version">
                  <FullProductName ProductID="P-14564V-Oracle GraalVM Enterprise Edition:21.3.0">Java SE JDK and JRE Version Oracle GraalVM Enterprise Edition:21.3.0</FullProductName>
               </Branch>
               <Branch Name="Oracle Java SE:11.0.13" Type="Product Version">
                  <FullProductName ProductID="P-856V-Oracle Java SE:11.0.13">Java SE JDK and JRE Version Oracle Java SE:11.0.13</FullProductName>
               </Branch>
               <Branch Name="Oracle Java SE:17.01" Type="Product Version">
                  <FullProductName ProductID="P-856V-Oracle Java SE:17.01">Java SE JDK and JRE Version Oracle Java SE:17.01</FullProductName>
               </Branch>
               <Branch Name="Oracle Java SE:7u321" Type="Product Version">
                  <FullProductName ProductID="P-856V-Oracle Java SE:7u321">Java SE JDK and JRE Version Oracle Java SE:7u321</FullProductName>
               </Branch>
               <Branch Name="Oracle Java SE:8u311" Type="Product Version">
                  <FullProductName ProductID="P-856V-Oracle Java SE:8u311">Java SE JDK and JRE Version Oracle Java SE:8u311</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="GraalVM Enterprise Edition" Type="Product Name">
               <Branch Name="Oracle GraalVM Enterprise Edition:20.3.4" Type="Product Version">
                  <FullProductName ProductID="P-14564V-Oracle GraalVM Enterprise Edition:20.3.4">GraalVM Enterprise Edition Version Oracle GraalVM Enterprise Edition:20.3.4</FullProductName>
               </Branch>
               <Branch Name="Oracle GraalVM Enterprise Edition:21.3.0" Type="Product Version">
                  <FullProductName ProductID="P-14564V-Oracle GraalVM Enterprise Edition:21.3.0">GraalVM Enterprise Edition Version Oracle GraalVM Enterprise Edition:21.3.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle MySQL" Type="Product Family">
            <Branch Name="MySQL Workbench" Type="Product Name">
               <Branch Name="8.0.27 and prior" Type="Product Version">
                  <FullProductName ProductID="P-4627V-8.0.27 and prior">MySQL Workbench Version 8.0.27 and prior</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="MySQL Server" Type="Product Name">
               <Branch Name="5.7.36 and prior" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.7.36 and prior">MySQL Server Version 5.7.36 and prior</FullProductName>
               </Branch>
               <Branch Name="8.0.26 and prior" Type="Product Version">
                  <FullProductName ProductID="P-8478V-8.0.26 and prior">MySQL Server Version 8.0.26 and prior</FullProductName>
               </Branch>
               <Branch Name="8.0.27 and prior" Type="Product Version">
                  <FullProductName ProductID="P-8478V-8.0.27 and prior">MySQL Server Version 8.0.27 and prior</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="MySQL Cluster" Type="Product Name">
               <Branch Name="7.4.34 and prior" Type="Product Version">
                  <FullProductName ProductID="P-8479V-7.4.34 and prior">MySQL Cluster Version 7.4.34 and prior</FullProductName>
               </Branch>
               <Branch Name="7.5.24 and prior" Type="Product Version">
                  <FullProductName ProductID="P-8479V-7.5.24 and prior">MySQL Cluster Version 7.5.24 and prior</FullProductName>
               </Branch>
               <Branch Name="7.6.20 and prior" Type="Product Version">
                  <FullProductName ProductID="P-8479V-7.6.20 and prior">MySQL Cluster Version 7.6.20 and prior</FullProductName>
               </Branch>
               <Branch Name="8.0.27 and prior" Type="Product Version">
                  <FullProductName ProductID="P-8479V-8.0.27 and prior">MySQL Cluster Version 8.0.27 and prior</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="MySQL Connectors" Type="Product Name">
               <Branch Name="8.0.27 and prior" Type="Product Version">
                  <FullProductName ProductID="P-8576V-8.0.27 and prior">MySQL Connectors Version 8.0.27 and prior</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle NoSQL Database" Type="Product Family">
            <Branch Name="NoSQL Database" Type="Product Name">
               <Branch Name="Prior to 21.1.12" Type="Product Version">
                  <FullProductName ProductID="P-13373V-Prior to 21.1.12">NoSQL Database Version Prior to 21.1.12</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle PeopleSoft" Type="Product Family">
            <Branch Name="PeopleSoft Enterprise PT PeopleTools" Type="Product Name">
               <Branch Name="8.57" Type="Product Version">
                  <FullProductName ProductID="P-5085V-8.57">PeopleSoft Enterprise PT PeopleTools Version 8.57</FullProductName>
               </Branch>
               <Branch Name="8.58" Type="Product Version">
                  <FullProductName ProductID="P-5085V-8.58">PeopleSoft Enterprise PT PeopleTools Version 8.58</FullProductName>
               </Branch>
               <Branch Name="8.59" Type="Product Version">
                  <FullProductName ProductID="P-5085V-8.59">PeopleSoft Enterprise PT PeopleTools Version 8.59</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="PeopleSoft Enterprise CS SA Integration Pack" Type="Product Name">
               <Branch Name="9.0" Type="Product Version">
                  <FullProductName ProductID="P-5107V-9.0">PeopleSoft Enterprise CS SA Integration Pack Version 9.0</FullProductName>
               </Branch>
               <Branch Name="9.2" Type="Product Version">
                  <FullProductName ProductID="P-5107V-9.2">PeopleSoft Enterprise CS SA Integration Pack Version 9.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Policy Automation" Type="Product Family">
            <Branch Name="Policy Automation" Type="Product Name">
               <Branch Name="12.2.0-12.2.24" Type="Product Version">
                  <FullProductName ProductID="P-5624V-12.2.0-12.2.24">Policy Automation Version 12.2.0-12.2.24</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle REST Data Services" Type="Product Family">
            <Branch Name="REST Data Services" Type="Product Name">
               <Branch Name="Prior to 21.2.0" Type="Product Version">
                  <FullProductName ProductID="P-9456V-Prior to 21.2.0">REST Data Services Version Prior to 21.2.0</FullProductName>
               </Branch>
               <Branch Name="Prior to 21.2.4" Type="Product Version">
                  <FullProductName ProductID="P-9456V-Prior to 21.2.4">REST Data Services Version Prior to 21.2.4</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Retail Applications" Type="Product Family">
            <Branch Name="Retail Allocation" Type="Product Name">
               <Branch Name="14.1.3.2" Type="Product Version">
                  <FullProductName ProductID="P-1786V-14.1.3.2">Retail Allocation Version 14.1.3.2</FullProductName>
               </Branch>
               <Branch Name="15.0.3.1" Type="Product Version">
                  <FullProductName ProductID="P-1786V-15.0.3.1">Retail Allocation Version 15.0.3.1</FullProductName>
               </Branch>
               <Branch Name="16.0.3" Type="Product Version">
                  <FullProductName ProductID="P-1786V-16.0.3">Retail Allocation Version 16.0.3</FullProductName>
               </Branch>
               <Branch Name="19.0.1" Type="Product Version">
                  <FullProductName ProductID="P-1786V-19.0.1">Retail Allocation Version 19.0.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Assortment Planning" Type="Product Name">
               <Branch Name="16.0.3" Type="Product Version">
                  <FullProductName ProductID="P-1788V-16.0.3">Retail Assortment Planning Version 16.0.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Extract Tranform and Load" Type="Product Name">
               <Branch Name="13.2.8" Type="Product Version">
                  <FullProductName ProductID="P-1803V-13.2.8">Retail Extract Tranform and Load Version 13.2.8</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Integration Bus" Type="Product Name">
               <Branch Name="14.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1807V-14.1.3.0">Retail Integration Bus Version 14.1.3.0</FullProductName>
               </Branch>
               <Branch Name="14.1.3.2" Type="Product Version">
                  <FullProductName ProductID="P-1807V-14.1.3.2">Retail Integration Bus Version 14.1.3.2</FullProductName>
               </Branch>
               <Branch Name="15.0.3.1" Type="Product Version">
                  <FullProductName ProductID="P-1807V-15.0.3.1">Retail Integration Bus Version 15.0.3.1</FullProductName>
               </Branch>
               <Branch Name="16.0.1-16.0.3" Type="Product Version">
                  <FullProductName ProductID="P-1807V-16.0.1-16.0.3">Retail Integration Bus Version 16.0.1-16.0.3</FullProductName>
               </Branch>
               <Branch Name="16.0.3" Type="Product Version">
                  <FullProductName ProductID="P-1807V-16.0.3">Retail Integration Bus Version 16.0.3</FullProductName>
               </Branch>
               <Branch Name="19.0.0" Type="Product Version">
                  <FullProductName ProductID="P-1807V-19.0.0">Retail Integration Bus Version 19.0.0</FullProductName>
               </Branch>
               <Branch Name="19.0.1" Type="Product Version">
                  <FullProductName ProductID="P-1807V-19.0.1">Retail Integration Bus Version 19.0.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Invoice Matching" Type="Product Name">
               <Branch Name="15.0.3" Type="Product Version">
                  <FullProductName ProductID="P-1810V-15.0.3">Retail Invoice Matching Version 15.0.3</FullProductName>
               </Branch>
               <Branch Name="16.0.3" Type="Product Version">
                  <FullProductName ProductID="P-1810V-16.0.3">Retail Invoice Matching Version 16.0.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Merchandising System" Type="Product Name">
               <Branch Name="19.0.1" Type="Product Version">
                  <FullProductName ProductID="P-1816V-19.0.1">Retail Merchandising System Version 19.0.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Predictive Application Server" Type="Product Name">
               <Branch Name="14.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1823V-14.1.3">Retail Predictive Application Server Version 14.1.3</FullProductName>
               </Branch>
               <Branch Name="14.1.3.46" Type="Product Version">
                  <FullProductName ProductID="P-1823V-14.1.3.46">Retail Predictive Application Server Version 14.1.3.46</FullProductName>
               </Branch>
               <Branch Name="15.0.3" Type="Product Version">
                  <FullProductName ProductID="P-1823V-15.0.3">Retail Predictive Application Server Version 15.0.3</FullProductName>
               </Branch>
               <Branch Name="15.0.3.115" Type="Product Version">
                  <FullProductName ProductID="P-1823V-15.0.3.115">Retail Predictive Application Server Version 15.0.3.115</FullProductName>
               </Branch>
               <Branch Name="16.0.3" Type="Product Version">
                  <FullProductName ProductID="P-1823V-16.0.3">Retail Predictive Application Server Version 16.0.3</FullProductName>
               </Branch>
               <Branch Name="16.0.3.240" Type="Product Version">
                  <FullProductName ProductID="P-1823V-16.0.3.240">Retail Predictive Application Server Version 16.0.3.240</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Price Management" Type="Product Name">
               <Branch Name="13.2" Type="Product Version">
                  <FullProductName ProductID="P-1824V-13.2">Retail Price Management Version 13.2</FullProductName>
               </Branch>
               <Branch Name="14.0.4" Type="Product Version">
                  <FullProductName ProductID="P-1824V-14.0.4">Retail Price Management Version 14.0.4</FullProductName>
               </Branch>
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-1824V-14.1">Retail Price Management Version 14.1</FullProductName>
               </Branch>
               <Branch Name="14.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1824V-14.1.3">Retail Price Management Version 14.1.3</FullProductName>
               </Branch>
               <Branch Name="15" Type="Product Version">
                  <FullProductName ProductID="P-1824V-15">Retail Price Management Version 15</FullProductName>
               </Branch>
               <Branch Name="15.0.3" Type="Product Version">
                  <FullProductName ProductID="P-1824V-15.0.3">Retail Price Management Version 15.0.3</FullProductName>
               </Branch>
               <Branch Name="16" Type="Product Version">
                  <FullProductName ProductID="P-1824V-16">Retail Price Management Version 16</FullProductName>
               </Branch>
               <Branch Name="16.0.3" Type="Product Version">
                  <FullProductName ProductID="P-1824V-16.0.3">Retail Price Management Version 16.0.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Back Office" Type="Product Name">
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-2013V-14.1">Retail Back Office Version 14.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Central Office" Type="Product Name">
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-2016V-14.1">Retail Central Office Version 14.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Point-of-Service" Type="Product Name">
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-2017V-14.1">Retail Point-of-Service Version 14.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Returns Management" Type="Product Name">
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-2020V-14.1">Retail Returns Management Version 14.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Size Profile Optimization" Type="Product Name">
               <Branch Name="16.0.3" Type="Product Version">
                  <FullProductName ProductID="P-4670V-16.0.3">Retail Size Profile Optimization Version 16.0.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Fiscal Management" Type="Product Name">
               <Branch Name="14.2" Type="Product Version">
                  <FullProductName ProductID="P-9038V-14.2">Retail Fiscal Management Version 14.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Analytics" Type="Product Name">
               <Branch Name="16.0.0-16.0.2" Type="Product Version">
                  <FullProductName ProductID="P-9346V-16.0.0-16.0.2">Retail Analytics Version 16.0.0-16.0.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Customer Insights" Type="Product Name">
               <Branch Name="16.0.0-16.0.2" Type="Product Version">
                  <FullProductName ProductID="P-10263V-16.0.0-16.0.2">Retail Customer Insights Version 16.0.0-16.0.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Financial Integration" Type="Product Name">
               <Branch Name="14.1.3.2" Type="Product Version">
                  <FullProductName ProductID="P-10722V-14.1.3.2">Retail Financial Integration Version 14.1.3.2</FullProductName>
               </Branch>
               <Branch Name="15.0.3.1" Type="Product Version">
                  <FullProductName ProductID="P-10722V-15.0.3.1">Retail Financial Integration Version 15.0.3.1</FullProductName>
               </Branch>
               <Branch Name="16.0.3" Type="Product Version">
                  <FullProductName ProductID="P-10722V-16.0.3">Retail Financial Integration Version 16.0.3</FullProductName>
               </Branch>
               <Branch Name="19.0.1" Type="Product Version">
                  <FullProductName ProductID="P-10722V-19.0.1">Retail Financial Integration Version 19.0.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Service Backbone" Type="Product Name">
               <Branch Name="14.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-10867V-14.1.3.0">Retail Service Backbone Version 14.1.3.0</FullProductName>
               </Branch>
               <Branch Name="14.1.3.2" Type="Product Version">
                  <FullProductName ProductID="P-10867V-14.1.3.2">Retail Service Backbone Version 14.1.3.2</FullProductName>
               </Branch>
               <Branch Name="15.0.3.1" Type="Product Version">
                  <FullProductName ProductID="P-10867V-15.0.3.1">Retail Service Backbone Version 15.0.3.1</FullProductName>
               </Branch>
               <Branch Name="16.0.1-16.0.3" Type="Product Version">
                  <FullProductName ProductID="P-10867V-16.0.1-16.0.3">Retail Service Backbone Version 16.0.1-16.0.3</FullProductName>
               </Branch>
               <Branch Name="16.0.3" Type="Product Version">
                  <FullProductName ProductID="P-10867V-16.0.3">Retail Service Backbone Version 16.0.3</FullProductName>
               </Branch>
               <Branch Name="19.0.0" Type="Product Version">
                  <FullProductName ProductID="P-10867V-19.0.0">Retail Service Backbone Version 19.0.0</FullProductName>
               </Branch>
               <Branch Name="19.0.1" Type="Product Version">
                  <FullProductName ProductID="P-10867V-19.0.1">Retail Service Backbone Version 19.0.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Xstore Point of Service" Type="Product Name">
               <Branch Name="17.0.4" Type="Product Version">
                  <FullProductName ProductID="P-11513V-17.0.4">Retail Xstore Point of Service Version 17.0.4</FullProductName>
               </Branch>
               <Branch Name="18.0.3" Type="Product Version">
                  <FullProductName ProductID="P-11513V-18.0.3">Retail Xstore Point of Service Version 18.0.3</FullProductName>
               </Branch>
               <Branch Name="19.0.2" Type="Product Version">
                  <FullProductName ProductID="P-11513V-19.0.2">Retail Xstore Point of Service Version 19.0.2</FullProductName>
               </Branch>
               <Branch Name="20.0.1" Type="Product Version">
                  <FullProductName ProductID="P-11513V-20.0.1">Retail Xstore Point of Service Version 20.0.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail EFTLink" Type="Product Name">
               <Branch Name="16.0.3" Type="Product Version">
                  <FullProductName ProductID="P-11516V-16.0.3">Retail EFTLink Version 16.0.3</FullProductName>
               </Branch>
               <Branch Name="17.0.2" Type="Product Version">
                  <FullProductName ProductID="P-11516V-17.0.2">Retail EFTLink Version 17.0.2</FullProductName>
               </Branch>
               <Branch Name="18.0.1" Type="Product Version">
                  <FullProductName ProductID="P-11516V-18.0.1">Retail EFTLink Version 18.0.1</FullProductName>
               </Branch>
               <Branch Name="19.0.1" Type="Product Version">
                  <FullProductName ProductID="P-11516V-19.0.1">Retail EFTLink Version 19.0.1</FullProductName>
               </Branch>
               <Branch Name="20.0.1" Type="Product Version">
                  <FullProductName ProductID="P-11516V-20.0.1">Retail EFTLink Version 20.0.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Order Management System Cloud Service" Type="Product Name">
               <Branch Name="19.5" Type="Product Version">
                  <FullProductName ProductID="P-11519V-19.5">Retail Order Management System Cloud Service Version 19.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Order Broker Cloud Service" Type="Product Name">
               <Branch Name="16.0" Type="Product Version">
                  <FullProductName ProductID="P-11520V-16.0">Retail Order Broker Cloud Service Version 16.0</FullProductName>
               </Branch>
               <Branch Name="18.0" Type="Product Version">
                  <FullProductName ProductID="P-11520V-18.0">Retail Order Broker Cloud Service Version 18.0</FullProductName>
               </Branch>
               <Branch Name="19.1" Type="Product Version">
                  <FullProductName ProductID="P-11520V-19.1">Retail Order Broker Cloud Service Version 19.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Customer Management and Segmentation Foundation" Type="Product Name">
               <Branch Name="16.0-19.0" Type="Product Version">
                  <FullProductName ProductID="P-13388V-16.0-19.0">Retail Customer Management and Segmentation Foundation Version 16.0-19.0</FullProductName>
               </Branch>
               <Branch Name="18.1" Type="Product Version">
                  <FullProductName ProductID="P-13388V-18.1">Retail Customer Management and Segmentation Foundation Version 18.1</FullProductName>
               </Branch>
               <Branch Name="19.0" Type="Product Version">
                  <FullProductName ProductID="P-13388V-19.0">Retail Customer Management and Segmentation Foundation Version 19.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Secure Backup" Type="Product Family">
            <Branch Name="Secure Backup" Type="Product Name">
               <Branch Name="Prior to 18.1.0.1.0" Type="Product Version">
                  <FullProductName ProductID="P-1522V-Prior to 18.1.0.1.0">Secure Backup Version Prior to 18.1.0.1.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Siebel CRM" Type="Product Family">
            <Branch Name="Siebel UI Framework" Type="Product Name">
               <Branch Name="21.12 and prior" Type="Product Version">
                  <FullProductName ProductID="P-9011V-21.12 and prior">Siebel UI Framework Version 21.12 and prior</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Spatial Studio" Type="Product Family">
            <Branch Name="Spatial Studio" Type="Product Name">
               <Branch Name="Prior to 21.2.1" Type="Product Version">
                  <FullProductName ProductID="P-13600V-Prior to 21.2.1">Spatial Studio Version Prior to 21.2.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Supply Chain" Type="Product Family">
            <Branch Name="Demantra Demand Management" Type="Product Name">
               <Branch Name="12.2.6-12.2.11" Type="Product Version">
                  <FullProductName ProductID="P-2100V-12.2.6-12.2.11">Demantra Demand Management Version 12.2.6-12.2.11</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Agile Engineering Data Management" Type="Product Name">
               <Branch Name="6.2.1.0" Type="Product Version">
                  <FullProductName ProductID="P-4436V-6.2.1.0">Agile Engineering Data Management Version 6.2.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Agile PLM MCAD Connector" Type="Product Name">
               <Branch Name="3.4" Type="Product Version">
                  <FullProductName ProductID="P-4440V-3.4">Agile PLM MCAD Connector Version 3.4</FullProductName>
               </Branch>
               <Branch Name="3.6" Type="Product Version">
                  <FullProductName ProductID="P-4440V-3.6">Agile PLM MCAD Connector Version 3.6</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Agile PLM Framework" Type="Product Name">
               <Branch Name="9.3.3" Type="Product Version">
                  <FullProductName ProductID="P-4461V-9.3.3">Agile PLM Framework Version 9.3.3</FullProductName>
               </Branch>
               <Branch Name="9.3.6" Type="Product Version">
                  <FullProductName ProductID="P-4461V-9.3.6">Agile PLM Framework Version 9.3.6</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Agile Product Lifecycle Management Integration Pack for Oracle E-Business Suite" Type="Product Name">
               <Branch Name="3.6" Type="Product Version">
                  <FullProductName ProductID="P-4589V-3.6">Agile Product Lifecycle Management Integration Pack for Oracle E-Business Suite Version 3.6</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Rapid Planning" Type="Product Name">
               <Branch Name="12.2.6-12.2.11" Type="Product Version">
                  <FullProductName ProductID="P-5235V-12.2.6-12.2.11">Rapid Planning Version 12.2.6-12.2.11</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Product Lifecycle Analytics" Type="Product Name">
               <Branch Name="3.6.1" Type="Product Version">
                  <FullProductName ProductID="P-9387V-3.6.1">Product Lifecycle Analytics Version 3.6.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Support Tools" Type="Product Family">
            <Branch Name="OSS Support Tools" Type="Product Name">
               <Branch Name="Prior to 2.12.42" Type="Product Version">
                  <FullProductName ProductID="P-1330V-Prior to 2.12.42">OSS Support Tools Version Prior to 2.12.42</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Systems" Type="Product Family">
            <Branch Name="Solaris Operating System" Type="Product Name">
               <Branch Name="10" Type="Product Version">
                  <FullProductName ProductID="P-10006V-10">Solaris Operating System Version 10</FullProductName>
               </Branch>
               <Branch Name="11" Type="Product Version">
                  <FullProductName ProductID="P-10006V-11">Solaris Operating System Version 11</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Sun ZFS Storage Appliance Kit (AK) Software" Type="Product Name">
               <Branch Name="8.8" Type="Product Version">
                  <FullProductName ProductID="P-10026V-8.8">Sun ZFS Storage Appliance Kit (AK) Software Version 8.8</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Sun ZFS Storage Application Integration Engineering Software" Type="Product Name">
               <Branch Name="1.3.3" Type="Product Version">
                  <FullProductName ProductID="P-10027V-1.3.3">Sun ZFS Storage Application Integration Engineering Software Version 1.3.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Fujitsu SPARC Servers Firmware" Type="Product Name">
               <Branch Name="Prior to XCP2410" Type="Product Version">
                  <FullProductName ProductID="P-10656V-Prior to XCP2410">Fujitsu SPARC Servers Firmware Version Prior to XCP2410</FullProductName>
               </Branch>
               <Branch Name="prior to XCP3110" Type="Product Version">
                  <FullProductName ProductID="P-10656V-prior to XCP3110">Fujitsu SPARC Servers Firmware Version prior to XCP3110</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle TimesTen In-Memory Database" Type="Product Family">
            <Branch Name="TimesTen In-Memory Database" Type="Product Name">
               <Branch Name="Prior to 11.2.2.8.27" Type="Product Version">
                  <FullProductName ProductID="P-1870V-Prior to 11.2.2.8.27">TimesTen In-Memory Database Version Prior to 11.2.2.8.27</FullProductName>
               </Branch>
               <Branch Name="Prior to 21.1.1.1.0" Type="Product Version">
                  <FullProductName ProductID="P-1870V-Prior to 21.1.1.1.0">TimesTen In-Memory Database Version Prior to 21.1.1.1.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Utilities Applications" Type="Product Family">
            <Branch Name="Utilities Framework" Type="Product Name">
               <Branch Name="4.2.0.2.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-4.2.0.2.0">Utilities Framework Version 4.2.0.2.0</FullProductName>
               </Branch>
               <Branch Name="4.2.0.3.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-4.2.0.3.0">Utilities Framework Version 4.2.0.3.0</FullProductName>
               </Branch>
               <Branch Name="4.3.0.1.0-4.3.0.6.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-4.3.0.1.0-4.3.0.6.0">Utilities Framework Version 4.3.0.1.0-4.3.0.6.0</FullProductName>
               </Branch>
               <Branch Name="4.4.0.0.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-4.4.0.0.0">Utilities Framework Version 4.4.0.0.0</FullProductName>
               </Branch>
               <Branch Name="4.4.0.2.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-4.4.0.2.0">Utilities Framework Version 4.4.0.2.0</FullProductName>
               </Branch>
               <Branch Name="4.4.0.3.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-4.4.0.3.0">Utilities Framework Version 4.4.0.3.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Utilities Testing Accelerator" Type="Product Name">
               <Branch Name="6.0.0.1.1" Type="Product Version">
                  <FullProductName ProductID="P-13784V-6.0.0.1.1">Utilities Testing Accelerator Version 6.0.0.1.1</FullProductName>
               </Branch>
               <Branch Name="6.0.0.2.2" Type="Product Version">
                  <FullProductName ProductID="P-13784V-6.0.0.2.2">Utilities Testing Accelerator Version 6.0.0.2.2</FullProductName>
               </Branch>
               <Branch Name="6.0.0.3.1" Type="Product Version">
                  <FullProductName ProductID="P-13784V-6.0.0.3.1">Utilities Testing Accelerator Version 6.0.0.3.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Virtualization" Type="Product Family">
            <Branch Name="VM VirtualBox" Type="Product Name">
               <Branch Name="Prior to 6.1.32" Type="Product Version">
                  <FullProductName ProductID="P-8370V-Prior to 6.1.32">VM VirtualBox Version Prior to 6.1.32</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle iLearning" Type="Product Family">
            <Branch Name="iLearning" Type="Product Name">
               <Branch Name="6.2" Type="Product Version">
                  <FullProductName ProductID="P-902V-6.2">iLearning Version 6.2</FullProductName>
               </Branch>
               <Branch Name="6.3" Type="Product Version">
                  <FullProductName ProductID="P-902V-6.3">iLearning Version 6.3</FullProductName>
               </Branch>
            </Branch>
         </Branch>
      </Branch>
   </ProductTree>
   <Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-7103</Title>
      <Notes>
         <Note Audience="All" Ordinal="1" Title="Details" Type="Details">Vulnerability in the OSS Support Tools product of Oracle Support Tools (component: Diagnostic Assistant (jQuery UI)).   The supported version that is affected is Prior to 2.12.42. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise OSS Support Tools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in OSS Support Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of OSS Support Tools accessible data as well as  unauthorized read access to a subset of OSS Support Tools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-7103</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1330V-Prior to 2.12.42</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>OSS Support Tools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833277.1</URL>
            <ProductID>P-1330V-Prior to 2.12.42</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2018-1311</Title>
      <Notes>
         <Note Audience="All" Ordinal="2" Title="Details" Type="Details">Vulnerability in Oracle GoldenGate (component: Build Request (Apache Xerces-C++)).   The supported version that is affected is Prior to 21.4.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GoldenGate.  Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2018-1311</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5757V-Prior to 21.4.0.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>GoldenGate</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5757V-Prior to 21.4.0.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="3" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2018-1324</Title>
      <Notes>
         <Note Audience="All" Ordinal="3" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLST (Apache Commons Compress)).   The supported version that is affected is 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle WebLogic Server executes to compromise Oracle WebLogic Server.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2018-1324</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="4" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-10086</Title>
      <Notes>
         <Note Audience="All" Ordinal="4" Title="Details" Type="Details">Vulnerability in the Oracle Communications Convergence product of Oracle Communications Applications (component: Message Store (Apache Commons BeanUtils)).   The supported version that is affected is 3.0.2.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Convergence.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Convergence accessible data as well as  unauthorized read access to a subset of Oracle Communications Convergence accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Convergence. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-10086</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8501V-3.0.2.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Convergence</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831902.1</URL>
            <ProductID>P-8501V-3.0.2.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="5" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-10086</Title>
      <Notes>
         <Note Audience="All" Ordinal="5" Title="Details" Type="Details">Vulnerability in the Oracle Communications Design Studio product of Oracle Communications Applications (component: Inventory (Apache Commons BeanUtils)).  Supported versions that are affected are 7.3.4, 7.3.5 and  7.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Design Studio.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Design Studio accessible data as well as  unauthorized read access to a subset of Oracle Communications Design Studio accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Design Studio. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-10086</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2283V-7.3.4</ProductID>
            <ProductID>P-2283V-7.3.5</ProductID>
            <ProductID>P-2283V-7.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Design Studio</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831888.1</URL>
            <ProductID>P-2283V-7.3.4</ProductID>
            <ProductID>P-2283V-7.3.5</ProductID>
            <ProductID>P-2283V-7.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="6" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-10086</Title>
      <Notes>
         <Note Audience="All" Ordinal="6" Title="Details" Type="Details">Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (component: Reporting (Apache Commons BeanUtils)).   The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Reporting and Analytics.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Hospitality Reporting and Analytics accessible data as well as  unauthorized read access to a subset of Oracle Hospitality Reporting and Analytics accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hospitality Reporting and Analytics. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-10086</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11599V-9.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Hospitality Reporting and Analytics</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2825723.1</URL>
            <ProductID>P-11599V-9.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="7" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-10086</Title>
      <Notes>
         <Note Audience="All" Ordinal="7" Title="Details" Type="Details">Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Timecard (Apache Commons Beanutils)).  Supported versions that are affected are 12.2.6-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Time and Labor.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Time and Labor accessible data as well as  unauthorized read access to a subset of Oracle Time and Labor accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Time and Labor. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-10086</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-311V-12.2.6-12.2.11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Time and Labor</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2484000.1</URL>
            <ProductID>P-311V-12.2.6-12.2.11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="8" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-10219</Title>
      <Notes>
         <Note Audience="All" Ordinal="8" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services  (JBoss Enterprise Application Platform)).  Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as  unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-10219</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="9" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-13734</Title>
      <Notes>
         <Note Audience="All" Ordinal="9" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: NRF (SQLite)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-13734</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14118V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Network Repository Function</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833598.1</URL>
            <ProductID>P-14118V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="10" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17495</Title>
      <Notes>
         <Note Audience="All" Ordinal="10" Title="Details" Type="Details">Vulnerability in the Oracle Banking APIs product of Oracle Financial Services Applications (component: Framework (Swagger UI)).  Supported versions that are affected are 18.1-18.3, 19.1, 19.2, 20.1 and  21.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking APIs.  Successful attacks of this vulnerability can result in takeover of Oracle Banking APIs. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17495</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13676V-18.1-18.3</ProductID>
            <ProductID>P-13676V-19.1</ProductID>
            <ProductID>P-13676V-19.2</ProductID>
            <ProductID>P-13676V-20.1</ProductID>
            <ProductID>P-13676V-21.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking APIs</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-13676V-18.1-18.3</ProductID>
            <ProductID>P-13676V-19.1</ProductID>
            <ProductID>P-13676V-19.2</ProductID>
            <ProductID>P-13676V-20.1</ProductID>
            <ProductID>P-13676V-21.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="11" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17495</Title>
      <Notes>
         <Note Audience="All" Ordinal="11" Title="Details" Type="Details">Vulnerability in the Oracle Banking Digital Experience product of Oracle Financial Services Applications (component: Framework (Swagger UI)).  Supported versions that are affected are 18.1-18.3, 19.1, 19.2, 20.1 and  21.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Digital Experience.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Digital Experience. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17495</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12605V-18.1-18.3</ProductID>
            <ProductID>P-12605V-19.1</ProductID>
            <ProductID>P-12605V-19.2</ProductID>
            <ProductID>P-12605V-20.1</ProductID>
            <ProductID>P-12605V-21.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Digital Experience</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-12605V-18.1-18.3</ProductID>
            <ProductID>P-12605V-19.1</ProductID>
            <ProductID>P-12605V-19.2</ProductID>
            <ProductID>P-12605V-20.1</ProductID>
            <ProductID>P-12605V-21.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="12" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17566</Title>
      <Notes>
         <Note Audience="All" Ordinal="12" Title="Details" Type="Details">Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web Answers (Apache Batik)).  Supported versions that are affected are 5.5.0.0.0, 5.9.0.0.0, 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17566</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2025V-5.5.0.0.0</ProductID>
            <ProductID>P-2025V-5.9.0.0.0</ProductID>
            <ProductID>P-2025V-12.2.1.3.0</ProductID>
            <ProductID>P-2025V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Business Intelligence Enterprise Edition</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-2025V-5.5.0.0.0</ProductID>
            <ProductID>P-2025V-5.9.0.0.0</ProductID>
            <ProductID>P-2025V-12.2.1.3.0</ProductID>
            <ProductID>P-2025V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="13" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-10683</Title>
      <Notes>
         <Note Audience="All" Ordinal="13" Title="Details" Type="Details">Vulnerability in the Oracle Insurance Policy Administration J2EE product of Oracle Insurance Applications (component: Architecture (dom4j)).  Supported versions that are affected are 10.2.0, 10.2.4, 11.0.2 and  11.1.0-11.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration J2EE.  Successful attacks of this vulnerability can result in takeover of Oracle Insurance Policy Administration J2EE. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-10683</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5279V-10.2.0</ProductID>
            <ProductID>P-5279V-10.2.4</ProductID>
            <ProductID>P-5279V-11.0.2</ProductID>
            <ProductID>P-5279V-11.1.0-11.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Insurance Policy Administration J2EE</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832476.1</URL>
            <ProductID>P-5279V-10.2.0</ProductID>
            <ProductID>P-5279V-10.2.4</ProductID>
            <ProductID>P-5279V-11.0.2</ProductID>
            <ProductID>P-5279V-11.1.0-11.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="14" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-10683</Title>
      <Notes>
         <Note Audience="All" Ordinal="14" Title="Details" Type="Details">Vulnerability in the Oracle Insurance Rules Palette product of Oracle Insurance Applications (component: Architecture (dom4j)).  Supported versions that are affected are 10.2.0, 10.2.4, 11.0.2 and  11.1.0-11.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Rules Palette.  Successful attacks of this vulnerability can result in takeover of Oracle Insurance Rules Palette. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-10683</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5288V-10.2.0</ProductID>
            <ProductID>P-5288V-10.2.4</ProductID>
            <ProductID>P-5288V-11.0.2</ProductID>
            <ProductID>P-5288V-11.1.0-11.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Insurance Rules Palette</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832476.1</URL>
            <ProductID>P-5288V-10.2.0</ProductID>
            <ProductID>P-5288V-10.2.4</ProductID>
            <ProductID>P-5288V-11.0.2</ProductID>
            <ProductID>P-5288V-11.1.0-11.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="15" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-10878</Title>
      <Notes>
         <Note Audience="All" Ordinal="15" Title="Details" Type="Details">Vulnerability in the Oracle Communications EAGLE Application Processor product of Oracle Communications (component: Platform (Perl)).  Supported versions that are affected are 16.1-16.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Application Processor.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications EAGLE Application Processor as well as  unauthorized update, insert or delete access to some of Oracle Communications EAGLE Application Processor accessible data and  unauthorized read access to a subset of Oracle Communications EAGLE Application Processor accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-10878</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11122V-16.1-16.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications EAGLE Application Processor</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833619.1</URL>
            <ProductID>P-11122V-16.1-16.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="16" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="16" Title="Details" Type="Details">Vulnerability in the Oracle Communications EAGLE Application Processor product of Oracle Communications (component: Platform (jQuery)).  Supported versions that are affected are 16.1-16.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Application Processor.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications EAGLE Application Processor, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications EAGLE Application Processor accessible data as well as  unauthorized read access to a subset of Oracle Communications EAGLE Application Processor accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11122V-16.1-16.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications EAGLE Application Processor</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833619.1</URL>
            <ProductID>P-11122V-16.1-16.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="17" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="17" Title="Details" Type="Details">Vulnerability in the Oracle Communications Services Gatekeeper product of Oracle Communications (component: API Portal (jQuery)).   The supported version that is affected is 7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Services Gatekeeper.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Services Gatekeeper, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Services Gatekeeper accessible data as well as  unauthorized read access to a subset of Oracle Communications Services Gatekeeper accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5381V-7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Services Gatekeeper</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833211.1</URL>
            <ProductID>P-5381V-7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="18" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11023</Title>
      <Notes>
         <Note Audience="All" Ordinal="18" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Sample apps  (jQuery)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as  unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11023</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="19" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11979</Title>
      <Notes>
         <Note Audience="All" Ordinal="19" Title="Details" Type="Details">Vulnerability in Oracle TimesTen In-Memory Database (component: Install (Apache Ant)).   The supported version that is affected is Prior to 11.2.2.8.27. Easily exploitable vulnerability allows low privileged attacker with network access via Local Logon to compromise Oracle TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle TimesTen In-Memory Database accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11979</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1870V-Prior to 11.2.2.8.27</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>TimesTen In-Memory Database</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-1870V-Prior to 11.2.2.8.27</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="20" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11987</Title>
      <Notes>
         <Note Audience="All" Ordinal="20" Title="Details" Type="Details">Vulnerability in the Oracle Banking APIs product of Oracle Financial Services Applications (component: Framework (Apache Batik)).  Supported versions that are affected are 18.3, 19.1, 19.2, 20.1 and  21.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking APIs.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Banking APIs accessible data as well as  unauthorized update, insert or delete access to some of Oracle Banking APIs accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11987</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13676V-18.3</ProductID>
            <ProductID>P-13676V-19.1</ProductID>
            <ProductID>P-13676V-19.2</ProductID>
            <ProductID>P-13676V-20.1</ProductID>
            <ProductID>P-13676V-21.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking APIs</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-13676V-18.3</ProductID>
            <ProductID>P-13676V-19.1</ProductID>
            <ProductID>P-13676V-19.2</ProductID>
            <ProductID>P-13676V-20.1</ProductID>
            <ProductID>P-13676V-21.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="21" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11987</Title>
      <Notes>
         <Note Audience="All" Ordinal="21" Title="Details" Type="Details">Vulnerability in the Oracle Banking Digital Experience product of Oracle Financial Services Applications (component: Framework (Apache Batik)).  Supported versions that are affected are 18.3, 19.1, 19.2, 20.1 and  21.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Digital Experience.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Banking Digital Experience accessible data as well as  unauthorized update, insert or delete access to some of Oracle Banking Digital Experience accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11987</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12605V-18.3</ProductID>
            <ProductID>P-12605V-19.1</ProductID>
            <ProductID>P-12605V-19.2</ProductID>
            <ProductID>P-12605V-20.1</ProductID>
            <ProductID>P-12605V-21.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Digital Experience</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-12605V-18.3</ProductID>
            <ProductID>P-12605V-19.1</ProductID>
            <ProductID>P-12605V-19.2</ProductID>
            <ProductID>P-12605V-20.1</ProductID>
            <ProductID>P-12605V-21.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="22" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-13817</Title>
      <Notes>
         <Note Audience="All" Ordinal="22" Title="Details" Type="Details">Vulnerability in the Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers product of Oracle Systems (component: XCP Firmware (NTP)).  Supported versions that are affected are Prior to XCP2410 and  prior to XCP3110. Difficult to exploit vulnerability allows unauthenticated attacker with network access via NTP to compromise Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers. CVSS 3.1 Base Score 7.4 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-13817</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10656V-Prior to XCP2410</ProductID>
            <ProductID>P-10656V-prior to XCP3110</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.4</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Fujitsu SPARC Servers Firmware</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832878.1</URL>
            <ProductID>P-10656V-Prior to XCP2410</ProductID>
            <ProductID>P-10656V-prior to XCP3110</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="23" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-13935</Title>
      <Notes>
         <Note Audience="All" Ordinal="23" Title="Details" Type="Details">Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Endeca Application Controller (Apache Tomcat)).   The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-13935</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9633V-11.3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Commerce Guided Search / Oracle Commerce Experience Manager</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832419.1</URL>
            <ProductID>P-9633V-11.3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="24" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-13936</Title>
      <Notes>
         <Note Audience="All" Ordinal="24" Title="Details" Type="Details">Vulnerability in the Oracle Banking Deposits and Lines of Credit Servicing product of Oracle Financial Services Applications (component: Web UI (Apache Velocity Engine)).   The supported version that is affected is 2.12.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Deposits and Lines of Credit Servicing.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Deposits and Lines of Credit Servicing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-13936</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13928V-2.12.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Deposits and Lines of Credit Servicing</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-13928V-2.12.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="25" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-13936</Title>
      <Notes>
         <Note Audience="All" Ordinal="25" Title="Details" Type="Details">Vulnerability in the Oracle Banking Enterprise Default Management product of Oracle Financial Services Applications (component: Collections (Apache Velocity Engine)).  Supported versions that are affected are 2.3.0-2.4.1, 2.6.2, 2.7.1,  2.10.0 and  2.12.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Enterprise Default Management.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Enterprise Default Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-13936</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13390V-2.3.0-2.4.1</ProductID>
            <ProductID>P-13390V-2.6.2</ProductID>
            <ProductID>P-13390V-2.7.1</ProductID>
            <ProductID>P-13390V-2.10.0</ProductID>
            <ProductID>P-13390V-2.12.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Enterprise Default Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2827842.1</URL>
            <ProductID>P-13390V-2.3.0-2.4.1</ProductID>
            <ProductID>P-13390V-2.6.2</ProductID>
            <ProductID>P-13390V-2.7.1</ProductID>
            <ProductID>P-13390V-2.10.0</ProductID>
            <ProductID>P-13390V-2.12.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="26" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-13936</Title>
      <Notes>
         <Note Audience="All" Ordinal="26" Title="Details" Type="Details">Vulnerability in the Oracle Banking Loans Servicing product of Oracle Financial Services Applications (component: Web UI (Apache Velocity Engine)).   The supported version that is affected is 2.12.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Loans Servicing.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Loans Servicing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-13936</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13927V-2.12.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Loans Servicing</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-13927V-2.12.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="27" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-13936</Title>
      <Notes>
         <Note Audience="All" Ordinal="27" Title="Details" Type="Details">Vulnerability in the Oracle Banking Party Management product of Oracle Financial Services Applications (component: Web UI (Apache Velocity Engine)).   The supported version that is affected is 2.7.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Party Management.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Party Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-13936</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13929V-2.7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Party Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2827842.1</URL>
            <ProductID>P-13929V-2.7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="28" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-13936</Title>
      <Notes>
         <Note Audience="All" Ordinal="28" Title="Details" Type="Details">Vulnerability in the Oracle Banking Platform product of Oracle Financial Services Applications (component: Security (Apache Velocity Engine)).  Supported versions that are affected are 2.3.0-2.4.1, 2.6.2 and  2.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-13936</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9178V-2.3.0-2.4.1</ProductID>
            <ProductID>P-9178V-2.6.2</ProductID>
            <ProductID>P-9178V-2.7.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Platform</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2827842.1</URL>
            <ProductID>P-9178V-2.3.0-2.4.1</ProductID>
            <ProductID>P-9178V-2.6.2</ProductID>
            <ProductID>P-9178V-2.7.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="29" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-13936</Title>
      <Notes>
         <Note Audience="All" Ordinal="29" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy  (Apache Velocity Engine)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-13936</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14277V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Policy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833602.1</URL>
            <ProductID>P-14277V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="30" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-13936</Title>
      <Notes>
         <Note Audience="All" Ordinal="30" Title="Details" Type="Details">Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Apache Velocity Engine)).   The supported version that is affected is 19.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-13936</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1807V-19.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Integration Bus</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-1807V-19.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="31" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-13936</Title>
      <Notes>
         <Note Audience="All" Ordinal="31" Title="Details" Type="Details">Vulnerability in the Oracle Retail Order Broker product of Oracle Retail Applications (component: Order Broker Foundation (Apache Velocity Engine)).   The supported version that is affected is 16.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Order Broker.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Order Broker. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-13936</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11520V-16.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Order Broker Cloud Service</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-11520V-16.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="32" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-13936</Title>
      <Notes>
         <Note Audience="All" Ordinal="32" Title="Details" Type="Details">Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB kernel (Apache Velocity Engine)).   The supported version that is affected is 19.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Service Backbone. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-13936</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10867V-19.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Service Backbone</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-10867V-19.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="33" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-13936</Title>
      <Notes>
         <Note Audience="All" Ordinal="33" Title="Details" Type="Details">Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Apache Velocity Engine)).  Supported versions that are affected are 6.0.0.1.1, 6.0.0.2.2 and  6.0.0.3.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Testing Accelerator. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-13936</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13784V-6.0.0.1.1</ProductID>
            <ProductID>P-13784V-6.0.0.2.2</ProductID>
            <ProductID>P-13784V-6.0.0.3.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Utilities Testing Accelerator</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832617.1</URL>
            <ProductID>P-13784V-6.0.0.1.1</ProductID>
            <ProductID>P-13784V-6.0.0.2.2</ProductID>
            <ProductID>P-13784V-6.0.0.3.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="34" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-13949</Title>
      <Notes>
         <Note Audience="All" Ordinal="34" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (Apache Thrift)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-13949</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14277V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Policy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833602.1</URL>
            <ProductID>P-14277V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="35" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-13956</Title>
      <Notes>
         <Note Audience="All" Ordinal="35" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: SCP (Apache HttpClient)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Service Communication Proxy accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-13956</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14117V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Service Communication Proxy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833601.1</URL>
            <ProductID>P-14117V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="36" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-13956</Title>
      <Notes>
         <Note Audience="All" Ordinal="36" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples (Apache HttpClient)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-13956</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="37" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14340</Title>
      <Notes>
         <Note Audience="All" Ordinal="37" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Network Repository Function (XNIO)).   The supported version that is affected is 1.14.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14340</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14118V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Network Repository Function</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833598.1</URL>
            <ProductID>P-14118V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="38" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14340</Title>
      <Notes>
         <Note Audience="All" Ordinal="38" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (XNIO)).   The supported version that is affected is 1.15.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14340</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14123V-1.15.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Security Edge Protection Proxy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833594.1</URL>
            <ProductID>P-14123V-1.15.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="39" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14340</Title>
      <Notes>
         <Note Audience="All" Ordinal="39" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: SCP (XNIO)).   The supported version that is affected is 1.14.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14340</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14117V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Service Communication Proxy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833601.1</URL>
            <ProductID>P-14117V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="40" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14340</Title>
      <Notes>
         <Note Audience="All" Ordinal="40" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: UDR (XNIO)).   The supported version that is affected is 1.14.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14340</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14119V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Unified Data Repository</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833596.1</URL>
            <ProductID>P-14119V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="41" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14756</Title>
      <Notes>
         <Note Audience="All" Ordinal="41" Title="Details" Type="Details">Vulnerability in the Oracle Utilities Framework product of Oracle Utilities Applications (component: General (Oracle Coherence)).  Supported versions that are affected are 4.2.0.2.0, 4.2.0.3.0, 4.3.0.1.0-4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0 and  4.4.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Framework. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14756</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2245V-4.2.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.3.0</ProductID>
            <ProductID>P-2245V-4.3.0.1.0-4.3.0.6.0</ProductID>
            <ProductID>P-2245V-4.4.0.0.0</ProductID>
            <ProductID>P-2245V-4.4.0.2.0</ProductID>
            <ProductID>P-2245V-4.4.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Utilities Framework</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832617.1</URL>
            <ProductID>P-2245V-4.2.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.3.0</ProductID>
            <ProductID>P-2245V-4.3.0.1.0-4.3.0.6.0</ProductID>
            <ProductID>P-2245V-4.4.0.0.0</ProductID>
            <ProductID>P-2245V-4.4.0.2.0</ProductID>
            <ProductID>P-2245V-4.4.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="42" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-15824</Title>
      <Notes>
         <Note Audience="All" Ordinal="42" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (Kotlin)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-15824</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14277V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Policy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833602.1</URL>
            <ProductID>P-14277V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="43" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-17521</Title>
      <Notes>
         <Note Audience="All" Ordinal="43" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client (Apache Groovy)).  Supported versions that are affected are 3.6 and  3.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-17521</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4440V-3.6</ProductID>
            <ProductID>P-4440V-3.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Agile PLM MCAD Connector</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832006.1</URL>
            <ProductID>P-4440V-3.6</ProductID>
            <ProductID>P-4440V-3.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="44" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-17527</Title>
      <Notes>
         <Note Audience="All" Ordinal="44" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Binding Support Function (Apache Tomcat)).   The supported version that is affected is 1.10.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Binding Support Function accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-17527</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14121V-1.10.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Binding Support Function</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833618.1</URL>
            <ProductID>P-14121V-1.10.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="45" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-17527</Title>
      <Notes>
         <Note Audience="All" Ordinal="45" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (Apache Tomcat)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-17527</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14277V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Policy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833602.1</URL>
            <ProductID>P-14277V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="46" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-17530</Title>
      <Notes>
         <Note Audience="All" Ordinal="46" Title="Details" Type="Details">Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation (Apache Struts2)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-17530</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2025V-12.2.1.3.0</ProductID>
            <ProductID>P-2025V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Business Intelligence Enterprise Edition</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-2025V-12.2.1.3.0</ProductID>
            <ProductID>P-2025V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="47" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-24750</Title>
      <Notes>
         <Note Audience="All" Ordinal="47" Title="Details" Type="Details">Vulnerability in the Oracle Communications Instant Messaging Server product of Oracle Communications Applications (component: PresenceApi (jackson-databind)).   The supported version that is affected is 10.0.1.5.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Instant Messaging Server.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Instant Messaging Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-24750</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8495V-10.0.1.5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Instant Messaging Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831902.1</URL>
            <ProductID>P-8495V-10.0.1.5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="48" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-24750</Title>
      <Notes>
         <Note Audience="All" Ordinal="48" Title="Details" Type="Details">Vulnerability in the Oracle Communications Offline Mediation Controller product of Oracle Communications Applications (component: Installer (jackson-databind)).   The supported version that is affected is 12.0.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Offline Mediation Controller.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Offline Mediation Controller. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-24750</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2269V-12.0.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Offline Mediation Controller</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831903.1</URL>
            <ProductID>P-2269V-12.0.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="49" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-24750</Title>
      <Notes>
         <Note Audience="All" Ordinal="49" Title="Details" Type="Details">Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications Applications (component: Installation (jackson-databind)).   The supported version that is affected is 12.0.0.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Pricing Design Center.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Pricing Design Center. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-24750</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9437V-12.0.0.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Pricing Design Center</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831903.1</URL>
            <ProductID>P-9437V-12.0.0.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="50" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-25649</Title>
      <Notes>
         <Note Audience="All" Ordinal="50" Title="Details" Type="Details">Vulnerability in the Agile Product Lifecycle Management Integration Pack for Oracle E-Business Suite product of Oracle Supply Chain (component: Installation Issues (jackson-databind)).   The supported version that is affected is 3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Agile Product Lifecycle Management Integration Pack for Oracle E-Business Suite.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Agile Product Lifecycle Management Integration Pack for Oracle E-Business Suite accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-25649</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4589V-3.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Agile Product Lifecycle Management Integration Pack for Oracle E-Business Suite</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832006.1</URL>
            <ProductID>P-4589V-3.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="51" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-25649</Title>
      <Notes>
         <Note Audience="All" Ordinal="51" Title="Details" Type="Details">Vulnerability in the Oracle Banking APIs product of Oracle Financial Services Applications (component: Framework (jackson-databind)).  Supported versions that are affected are 18.1-18.3, 19.1, 19.2, 20.1 and  21.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking APIs.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking APIs accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-25649</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13676V-18.1-18.3</ProductID>
            <ProductID>P-13676V-19.1</ProductID>
            <ProductID>P-13676V-19.2</ProductID>
            <ProductID>P-13676V-20.1</ProductID>
            <ProductID>P-13676V-21.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking APIs</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-13676V-18.1-18.3</ProductID>
            <ProductID>P-13676V-19.1</ProductID>
            <ProductID>P-13676V-19.2</ProductID>
            <ProductID>P-13676V-20.1</ProductID>
            <ProductID>P-13676V-21.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="52" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-27618</Title>
      <Notes>
         <Note Audience="All" Ordinal="52" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: SCP (glibc)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Service Communication Proxy executes to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-27618</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14117V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Service Communication Proxy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833601.1</URL>
            <ProductID>P-14117V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="53" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-28052</Title>
      <Notes>
         <Note Audience="All" Ordinal="53" Title="Details" Type="Details">Vulnerability in the Oracle Communications Convergence product of Oracle Communications Applications (component: Messaging (Bouncy Castle Java Library)).   The supported version that is affected is 3.0.2.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via S/MIME to compromise Oracle Communications Convergence.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Convergence. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-28052</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8501V-3.0.2.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Convergence</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831902.1</URL>
            <ProductID>P-8501V-3.0.2.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="54" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-28469</Title>
      <Notes>
         <Note Audience="All" Ordinal="54" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (glob-parent)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-28469</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14277V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Policy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833602.1</URL>
            <ProductID>P-14277V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="55" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-2934</Title>
      <Notes>
         <Note Audience="All" Ordinal="55" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Datasource (MySQL Connector)).  Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SQL to compromise Oracle WebLogic Server.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as  unauthorized read access to a subset of Oracle WebLogic Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-2934</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="56" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-29582</Title>
      <Notes>
         <Note Audience="All" Ordinal="56" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: SCP (Kotlin)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Cloud Native Core Service Communication Proxy accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-29582</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14117V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Service Communication Proxy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833601.1</URL>
            <ProductID>P-14117V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="57" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-36189</Title>
      <Notes>
         <Note Audience="All" Ordinal="57" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy  (jackson-databind)).   The supported version that is affected is 1.14.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-36189</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14277V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Policy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833602.1</URL>
            <ProductID>P-14277V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="58" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-5258</Title>
      <Notes>
         <Note Audience="All" Ordinal="58" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples (dojo)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-5258</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="59" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-5421</Title>
      <Notes>
         <Note Audience="All" Ordinal="59" Title="Details" Type="Details">Vulnerability in the Oracle Communications Design Studio product of Oracle Communications Applications (component: Inventory (Spring Framework)).  Supported versions that are affected are 7.3.4, 7.3.5 and  7.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Design Studio.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Design Studio, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Design Studio accessible data as well as  unauthorized read access to a subset of Oracle Communications Design Studio accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-5421</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2283V-7.3.4</ProductID>
            <ProductID>P-2283V-7.3.5</ProductID>
            <ProductID>P-2283V-7.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Design Studio</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831888.1</URL>
            <ProductID>P-2283V-7.3.4</ProductID>
            <ProductID>P-2283V-7.3.5</ProductID>
            <ProductID>P-2283V-7.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="60" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-6950</Title>
      <Notes>
         <Note Audience="All" Ordinal="60" Title="Details" Type="Details">Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Timecard (Eclipse Mojarra)).  Supported versions that are affected are 12.2.6-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Time and Labor.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Time and Labor accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-6950</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-311V-12.2.6-12.2.11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Time and Labor</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2484000.1</URL>
            <ProductID>P-311V-12.2.6-12.2.11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="61" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-7712</Title>
      <Notes>
         <Note Audience="All" Ordinal="61" Title="Details" Type="Details">Vulnerability in Oracle TimesTen In-Memory Database (component: TimesTen Infrastructure (Apache ZooKeeper)).   The supported version that is affected is Prior to 21.1.1.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in takeover of Oracle TimesTen In-Memory Database. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-7712</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1870V-Prior to 21.1.1.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.2</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>TimesTen In-Memory Database</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-1870V-Prior to 21.1.1.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="62" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-8285</Title>
      <Notes>
         <Note Audience="All" Ordinal="62" Title="Details" Type="Details">Vulnerability in the Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers product of Oracle Systems (component: XCP Firmware (cURL)).  Supported versions that are affected are Prior to XCP2410 and  prior to XCP3110. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-8285</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10656V-Prior to XCP2410</ProductID>
            <ProductID>P-10656V-prior to XCP3110</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Fujitsu SPARC Servers Firmware</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832878.1</URL>
            <ProductID>P-10656V-Prior to XCP2410</ProductID>
            <ProductID>P-10656V-prior to XCP3110</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="63" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-8554</Title>
      <Notes>
         <Note Audience="All" Ordinal="63" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: SCP (Kubernetes API)).   The supported version that is affected is 1.14.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Service Communication Proxy accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Service Communication Proxy accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 5.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-8554</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14117V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.0</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Service Communication Proxy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833601.1</URL>
            <ProductID>P-14117V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="64" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-8554</Title>
      <Notes>
         <Note Audience="All" Ordinal="64" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: UDR (Kubernetes API)).   The supported version that is affected is 1.14.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Unified Data Repository accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Unified Data Repository accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 5.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-8554</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14119V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.0</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Unified Data Repository</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833596.1</URL>
            <ProductID>P-14119V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="65" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-8908</Title>
      <Notes>
         <Note Audience="All" Ordinal="65" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: UDR (Guava)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Unified Data Repository executes to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Cloud Native Core Unified Data Repository accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-8908</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14119V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.3</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Unified Data Repository</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833596.1</URL>
            <ProductID>P-14119V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="66" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-8908</Title>
      <Notes>
         <Note Audience="All" Ordinal="66" Title="Details" Type="Details">Security-in-Depth issue in the Workload Manager (Guava) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-8908</CVE>
      <ProductStatuses>
         <Status Type="Known Not Affected">
            <ProductID>P-5V-All Supported Versions</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Database - Enterprise Edition</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5V-All Supported Versions</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="67" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-8908</Title>
      <Notes>
         <Note Audience="All" Ordinal="67" Title="Details" Type="Details">Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Data Service (Guava)).  Supported versions that are affected are 17.7-17.12, 18.8, 19.12, 20.12 and  21.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Primavera Unifier executes to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Primavera Unifier accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-8908</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10354V-17.7-17.12</ProductID>
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
            <ProductID>P-10354V-20.12</ProductID>
            <ProductID>P-10354V-21.12</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.3</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera Unifier</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2829871.1</URL>
            <ProductID>P-10354V-17.7-17.12</ProductID>
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
            <ProductID>P-10354V-20.12</ProductID>
            <ProductID>P-10354V-21.12</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="68" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9281</Title>
      <Notes>
         <Note Audience="All" Ordinal="68" Title="Details" Type="Details">Vulnerability in the Oracle Banking Enterprise Default Management product of Oracle Financial Services Applications (component: Collections (CKEditor)).   The supported version that is affected is 2.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Enterprise Default Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Enterprise Default Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Banking Enterprise Default Management accessible data as well as  unauthorized read access to a subset of Oracle Banking Enterprise Default Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9281</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13390V-2.7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Enterprise Default Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2827842.1</URL>
            <ProductID>P-13390V-2.7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="69" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-20718</Title>
      <Notes>
         <Note Audience="All" Ordinal="69" Title="Details" Type="Details">Vulnerability in Oracle Essbase (component: Infrastructure (mod_auth_openidc)).   The supported version that is affected is Prior to 21.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Essbase.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Essbase. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-20718</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4379V-Prior to 21.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Hyperion Essbase</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-4379V-Prior to 21.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="70" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-21409</Title>
      <Notes>
         <Note Audience="All" Ordinal="70" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Console (Netty)).   The supported version that is affected is 1.7.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Console accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-21409</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14250V-1.7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Console</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833832.1</URL>
            <ProductID>P-14250V-1.7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="71" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-21409</Title>
      <Notes>
         <Note Audience="All" Ordinal="71" Title="Details" Type="Details">Vulnerability in Oracle NoSQL Database (component: Administration (Netty)).   The supported version that is affected is Prior to 21.1.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle NoSQL Database executes to compromise Oracle NoSQL Database.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle NoSQL Database accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-21409</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13373V-Prior to 21.1.12</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>NoSQL Database</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-13373V-Prior to 21.1.12</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="72" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-21703</Title>
      <Notes>
         <Note Audience="All" Ordinal="72" Title="Details" Type="Details">Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Platform (PHP)).  Supported versions that are affected are 8.0.0.0-8.5.0.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Diameter Signaling Router executes to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-21703</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10899V-8.0.0.0-8.5.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.0</BaseScore>
            <Vector>AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Diameter Signaling Router (DSR)</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833215.1</URL>
            <ProductID>P-10899V-8.0.0.0-8.5.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="73" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-21705</Title>
      <Notes>
         <Note Audience="All" Ordinal="73" Title="Details" Type="Details">Vulnerability in the Oracle SD-WAN Aware product of Oracle Communications (component: Management (PHP)).   The supported version that is affected is 8.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SD-WAN Aware.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle SD-WAN Aware accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-21705</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13941V-8.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>SD-WAN Aware</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833597.1</URL>
            <ProductID>P-13941V-8.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="74" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-21783</Title>
      <Notes>
         <Note Audience="All" Ordinal="74" Title="Details" Type="Details">Vulnerability in the Oracle Communications EAGLE Application Processor product of Oracle Communications (component: Platform (gSOAP)).  Supported versions that are affected are 16.1-16.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Application Processor.  Successful attacks of this vulnerability can result in takeover of Oracle Communications EAGLE Application Processor. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-21783</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11122V-16.1-16.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications EAGLE Application Processor</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833619.1</URL>
            <ProductID>P-11122V-16.1-16.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="75" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-22118</Title>
      <Notes>
         <Note Audience="All" Ordinal="75" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Binding Support Function (Spring Framework)).   The supported version that is affected is 1.9.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Binding Support Function executes to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-22118</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14121V-1.9.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Binding Support Function</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833618.1</URL>
            <ProductID>P-14121V-1.9.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="76" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-22118</Title>
      <Notes>
         <Note Audience="All" Ordinal="76" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (Spring Framework)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Policy executes to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-22118</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14277V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Policy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833602.1</URL>
            <ProductID>P-14277V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="77" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-22118</Title>
      <Notes>
         <Note Audience="All" Ordinal="77" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (Spring Framework)).   The supported version that is affected is 1.6.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Security Edge Protection Proxy executes to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-22118</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14123V-1.6.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Security Edge Protection Proxy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833594.1</URL>
            <ProductID>P-14123V-1.6.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="78" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-22118</Title>
      <Notes>
         <Note Audience="All" Ordinal="78" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: SCP (Spring Framework)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Service Communication Proxy executes to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-22118</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14117V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Service Communication Proxy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833601.1</URL>
            <ProductID>P-14117V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="79" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-22118</Title>
      <Notes>
         <Note Audience="All" Ordinal="79" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: UDR (Spring Framework)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Unified Data Repository executes to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-22118</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14119V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Unified Data Repository</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833596.1</URL>
            <ProductID>P-14119V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="80" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-22118</Title>
      <Notes>
         <Note Audience="All" Ordinal="80" Title="Details" Type="Details">Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: TMF API (Spring Framework)).  Supported versions that are affected are 7.4.1, 7.4.2 and  7.5.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Unified Inventory Management executes to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-22118</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4516V-7.4.1</ProductID>
            <ProductID>P-4516V-7.4.2</ProductID>
            <ProductID>P-4516V-7.5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Unified Inventory Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831889.1</URL>
            <ProductID>P-4516V-7.4.1</ProductID>
            <ProductID>P-4516V-7.4.2</ProductID>
            <ProductID>P-4516V-7.5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="81" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-22118</Title>
      <Notes>
         <Note Audience="All" Ordinal="81" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Others (Spring Framework)).  Supported versions that are affected are 8.0.8-8.1.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Financial Services Analytical Applications Infrastructure executes to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Analytical Applications Infrastructure. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-22118</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5680V-8.0.8-8.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Financial Services Analytical Applications Infrastructure</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2825591.1</URL>
            <ProductID>P-5680V-8.0.8-8.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="82" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-22118</Title>
      <Notes>
         <Note Audience="All" Ordinal="82" Title="Details" Type="Details">Vulnerability in the Oracle Insurance Rules Palette product of Oracle Insurance Applications (component: Architecture (Spring Framework)).  Supported versions that are affected are 11.0.2, 11.1.0, 11.2.7, 11.3.0 and  11.3.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Insurance Rules Palette executes to compromise Oracle Insurance Rules Palette.  Successful attacks of this vulnerability can result in takeover of Oracle Insurance Rules Palette. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-22118</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5288V-11.0.2</ProductID>
            <ProductID>P-5288V-11.1.0</ProductID>
            <ProductID>P-5288V-11.2.7</ProductID>
            <ProductID>P-5288V-11.3.0</ProductID>
            <ProductID>P-5288V-11.3.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Insurance Rules Palette</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832476.1</URL>
            <ProductID>P-5288V-11.0.2</ProductID>
            <ProductID>P-5288V-11.1.0</ProductID>
            <ProductID>P-5288V-11.2.7</ProductID>
            <ProductID>P-5288V-11.3.0</ProductID>
            <ProductID>P-5288V-11.3.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="83" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-22118</Title>
      <Notes>
         <Note Audience="All" Ordinal="83" Title="Details" Type="Details">Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Deal (Spring Framework)).  Supported versions that are affected are 16.0-19.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Retail Customer Management and Segmentation Foundation executes to compromise Oracle Retail Customer Management and Segmentation Foundation.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Customer Management and Segmentation Foundation. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-22118</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13388V-16.0-19.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Customer Management and Segmentation Foundation</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-13388V-16.0-19.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="84" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-22118</Title>
      <Notes>
         <Note Audience="All" Ordinal="84" Title="Details" Type="Details">Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Spring Framework)).  Supported versions that are affected are 6.0.0.1.1, 6.0.0.2.2 and  6.0.0.3.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Utilities Testing Accelerator executes to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Testing Accelerator. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-22118</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13784V-6.0.0.1.1</ProductID>
            <ProductID>P-13784V-6.0.0.2.2</ProductID>
            <ProductID>P-13784V-6.0.0.3.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Utilities Testing Accelerator</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832617.1</URL>
            <ProductID>P-13784V-6.0.0.1.1</ProductID>
            <ProductID>P-13784V-6.0.0.2.2</ProductID>
            <ProductID>P-13784V-6.0.0.3.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="85" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-22119</Title>
      <Notes>
         <Note Audience="All" Ordinal="85" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (Spring Security)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-22119</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14277V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Policy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833602.1</URL>
            <ProductID>P-14277V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="86" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-22901</Title>
      <Notes>
         <Note Audience="All" Ordinal="86" Title="Details" Type="Details">Vulnerability in Oracle Essbase (component: Build (cURL)).  Supported versions that are affected are Prior to 11.1.2.4.047 and  Prior to 21.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Essbase.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Essbase. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-22901</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4379V-Prior to 11.1.2.4.047</ProductID>
            <ProductID>P-4379V-Prior to 21.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Hyperion Essbase</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-4379V-Prior to 11.1.2.4.047</ProductID>
            <ProductID>P-4379V-Prior to 21.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="87" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-22931</Title>
      <Notes>
         <Note Audience="All" Ordinal="87" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search (Node.js)).  Supported versions that are affected are 8.57, 8.58 and  8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-22931</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>PeopleSoft Enterprise PT PeopleTools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831970.1</URL>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="88" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-22946</Title>
      <Notes>
         <Note Audience="All" Ordinal="88" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Compiling (cURL)).  Supported versions that are affected are 5.7.36 and prior and  8.0.27 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-22946</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.36 and prior</ProductID>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-5.7.36 and prior</ProductID>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="89" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-22946</Title>
      <Notes>
         <Note Audience="All" Ordinal="89" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: File Processing  (cURL)).  Supported versions that are affected are 8.57, 8.58 and  8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-22946</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>PeopleSoft Enterprise PT PeopleTools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831970.1</URL>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="90" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-22959</Title>
      <Notes>
         <Note Audience="All" Ordinal="90" Title="Details" Type="Details">Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Node (Node.js)).  Supported versions that are affected are Oracle GraalVM Enterprise Edition: 20.3.4 and  21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle GraalVM Enterprise Edition accessible data as well as  unauthorized read access to a subset of Oracle GraalVM Enterprise Edition accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-22959</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>GraalVM Enterprise Edition</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2828114.1</URL>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="91" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-23017</Title>
      <Notes>
         <Note Audience="All" Ordinal="91" Title="Details" Type="Details">Vulnerability in the Oracle Communications Session Border Controller product of Oracle Communications (component: Routing (nginx)).  Supported versions that are affected are 8.4 and  9.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Session Border Controller.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Session Border Controller accessible data as well as  unauthorized read access to a subset of Oracle Communications Session Border Controller accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Session Border Controller. CVSS 3.1 Base Score 5.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-23017</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10750V-8.4</ProductID>
            <ProductID>P-10750V-9.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.6</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Session Border Controller</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833085.1</URL>
            <ProductID>P-10750V-8.4</ProductID>
            <ProductID>P-10750V-9.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="92" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-23017</Title>
      <Notes>
         <Note Audience="All" Ordinal="92" Title="Details" Type="Details">Vulnerability in the Oracle Enterprise Communications Broker product of Oracle Communications (component: Routing (nginx)).   The supported version that is affected is 3.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Communications Broker.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Enterprise Communications Broker accessible data as well as  unauthorized read access to a subset of Oracle Enterprise Communications Broker accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Communications Broker. CVSS 3.1 Base Score 5.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-23017</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10758V-3.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.6</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Enterprise Communications Broker</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833087.1</URL>
            <ProductID>P-10758V-3.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="93" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-23017</Title>
      <Notes>
         <Note Audience="All" Ordinal="93" Title="Details" Type="Details">Vulnerability in the Oracle Enterprise Session Border Controller product of Oracle Communications (component: Routing (nginx)).  Supported versions that are affected are 8.4 and  9.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Session Border Controller.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Enterprise Session Border Controller accessible data as well as  unauthorized read access to a subset of Oracle Enterprise Session Border Controller accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Session Border Controller. CVSS 3.1 Base Score 5.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-23017</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10757V-8.4</ProductID>
            <ProductID>P-10757V-9.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.6</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Enterprise Session Border Controller</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833085.1</URL>
            <ProductID>P-10757V-8.4</ProductID>
            <ProductID>P-10757V-9.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="94" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-23017</Title>
      <Notes>
         <Note Audience="All" Ordinal="94" Title="Details" Type="Details">Vulnerability in Oracle GoldenGate (component: GG Market Place for Support (nginx)).   The supported version that is affected is Prior to 21.4.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via UDP to compromise Oracle GoldenGate.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle GoldenGate accessible data as well as  unauthorized access to critical data or complete access to all Oracle GoldenGate accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GoldenGate. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-23017</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5757V-Prior to 21.4.0.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.4</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>GoldenGate</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5757V-Prior to 21.4.0.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="95" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-23337</Title>
      <Notes>
         <Note Audience="All" Ordinal="95" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Binding Support Function (Lodash)).   The supported version that is affected is 1.9.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-23337</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14121V-1.9.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.2</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Binding Support Function</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833618.1</URL>
            <ProductID>P-14121V-1.9.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="96" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-23337</Title>
      <Notes>
         <Note Audience="All" Ordinal="96" Title="Details" Type="Details">Vulnerability in the Oracle Communications Services Gatekeeper product of Oracle Communications (component: Policy service (Lodash)).   The supported version that is affected is 7.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Services Gatekeeper.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Services Gatekeeper. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-23337</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5381V-7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.2</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Services Gatekeeper</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833211.1</URL>
            <ProductID>P-5381V-7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="97" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-23337</Title>
      <Notes>
         <Note Audience="All" Ordinal="97" Title="Details" Type="Details">Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud (Lodash)).   The supported version that is affected is Prior to 9.2.6.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-23337</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4781V-Prior to 9.2.6.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.2</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>JD Edwards EnterpriseOne Tools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832004.1</URL>
            <ProductID>P-4781V-Prior to 9.2.6.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="98" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-23337</Title>
      <Notes>
         <Note Audience="All" Ordinal="98" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search (Lodash)).  Supported versions that are affected are 8.58 and  8.59. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-23337</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.2</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>PeopleSoft Enterprise PT PeopleTools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831970.1</URL>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="99" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-23337</Title>
      <Notes>
         <Note Audience="All" Ordinal="99" Title="Details" Type="Details">Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Security (Lodash)).   The supported version that is affected is 19.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Retail Customer Management and Segmentation Foundation.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Customer Management and Segmentation Foundation. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-23337</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13388V-19.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.2</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Customer Management and Segmentation Foundation</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-13388V-19.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="100" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-23440</Title>
      <Notes>
         <Note Audience="All" Ordinal="100" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (set-value)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-23440</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14277V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Policy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833602.1</URL>
            <ProductID>P-14277V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="101" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="101" Title="Details" Type="Details">Vulnerability in the Application Performance Management product of Oracle Enterprise Manager (component: End User Experience Management (JDBC)).  Supported versions that are affected are 13.4.1.0 and  13.5.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Application Performance Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Application Performance Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Application Performance Management. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9572V-13.4.1.0</ProductID>
            <ProductID>P-9572V-13.5.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>APM - Application Performance Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-9572V-13.4.1.0</ProductID>
            <ProductID>P-9572V-13.5.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="102" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="102" Title="Details" Type="Details">Vulnerability in the Oracle Real User Experience Insight product of Oracle Enterprise Manager (component: End User Experience Management (OCCI)).  Supported versions that are affected are 13.4.1.0 and  13.5.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Real User Experience Insight.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Real User Experience Insight, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Real User Experience Insight. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9572V-13.4.1.0</ProductID>
            <ProductID>P-9572V-13.5.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>APM - Application Performance Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-9572V-13.4.1.0</ProductID>
            <ProductID>P-9572V-13.5.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="103" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="103" Title="Details" Type="Details">Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Installation (JDBC)).   The supported version that is affected is 6.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Agile Engineering Data Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Agile Engineering Data Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4436V-6.2.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Agile Engineering Data Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832006.1</URL>
            <ProductID>P-4436V-6.2.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="104" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="104" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security (JDBC)).   The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Agile PLM.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Agile PLM Framework</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832006.1</URL>
            <ProductID>P-4461V-9.3.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="105" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="105" Title="Details" Type="Details">Vulnerability in Oracle Airlines Data Model (component: Installation (JDBC)).  Supported versions that are affected are 12.2.0.1.0 and  12.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Airlines Data Model.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Airlines Data Model, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Airlines Data Model. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9587V-12.2.0.1.0</ProductID>
            <ProductID>P-9587V-12.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Airlines Data Model</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833257.1</URL>
            <ProductID>P-9587V-12.2.0.1.0</ProductID>
            <ProductID>P-9587V-12.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="106" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="106" Title="Details" Type="Details">Vulnerability in the Oracle Application Testing Suite product of Oracle Enterprise Manager (component: Load Testing for Web Apps (JDBC, OCCI)).   The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Application Testing Suite.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Testing Suite, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4622V-13.3.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Application Testing Suite</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-4622V-13.3.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="107" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="107" Title="Details" Type="Details">Vulnerability in the Oracle Argus Analytics product of Oracle Health Sciences Applications (component: Schema Creation (JDBC)).  Supported versions that are affected are 8.2.1, 8.2.2 and  8.2.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Argus Analytics.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Argus Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Argus Analytics. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9171V-8.2.1</ProductID>
            <ProductID>P-9171V-8.2.2</ProductID>
            <ProductID>P-9171V-8.2.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Argus Analytics</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2827314.1</URL>
            <ProductID>P-9171V-8.2.1</ProductID>
            <ProductID>P-9171V-8.2.2</ProductID>
            <ProductID>P-9171V-8.2.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="108" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="108" Title="Details" Type="Details">Vulnerability in the Oracle Argus Insight product of Oracle Health Sciences Applications (component: Schema Creation (JDBC)).  Supported versions that are affected are 8.2.1, 8.2.2 and  8.2.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Argus Insight.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Argus Insight, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Argus Insight. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5717V-8.2.1</ProductID>
            <ProductID>P-5717V-8.2.2</ProductID>
            <ProductID>P-5717V-8.2.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Argus Insight</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2827314.1</URL>
            <ProductID>P-5717V-8.2.1</ProductID>
            <ProductID>P-5717V-8.2.2</ProductID>
            <ProductID>P-5717V-8.2.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="109" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="109" Title="Details" Type="Details">Vulnerability in the Oracle Argus Mart product of Oracle Health Sciences Applications (component: Schema Creation (JDBC)).  Supported versions that are affected are 8.2.1, 8.2.2 and  8.2.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Argus Mart.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Argus Mart, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Argus Mart. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10383V-8.2.1</ProductID>
            <ProductID>P-10383V-8.2.2</ProductID>
            <ProductID>P-10383V-8.2.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Argus Mart</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2827314.1</URL>
            <ProductID>P-10383V-8.2.1</ProductID>
            <ProductID>P-10383V-8.2.2</ProductID>
            <ProductID>P-10383V-8.2.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="110" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="110" Title="Details" Type="Details">Vulnerability in the Oracle Argus Safety product of Oracle Health Sciences Applications (component: Schema Creation (JDBC)).  Supported versions that are affected are 8.2.1, 8.2.2 and  8.2.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Argus Safety.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Argus Safety, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Argus Safety. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5710V-8.2.1</ProductID>
            <ProductID>P-5710V-8.2.2</ProductID>
            <ProductID>P-5710V-8.2.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Argus Safety</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2827314.1</URL>
            <ProductID>P-5710V-8.2.1</ProductID>
            <ProductID>P-5710V-8.2.2</ProductID>
            <ProductID>P-5710V-8.2.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="111" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="111" Title="Details" Type="Details">Vulnerability in the Oracle Banking APIs product of Oracle Financial Services Applications (component: Framework (JDBC)).  Supported versions that are affected are 18.1-18.3, 19.1, 19.2, 20.1 and  21.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Banking APIs.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking APIs, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Banking APIs. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13676V-18.1-18.3</ProductID>
            <ProductID>P-13676V-19.1</ProductID>
            <ProductID>P-13676V-19.2</ProductID>
            <ProductID>P-13676V-20.1</ProductID>
            <ProductID>P-13676V-21.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking APIs</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-13676V-18.1-18.3</ProductID>
            <ProductID>P-13676V-19.1</ProductID>
            <ProductID>P-13676V-19.2</ProductID>
            <ProductID>P-13676V-20.1</ProductID>
            <ProductID>P-13676V-21.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="112" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="112" Title="Details" Type="Details">Vulnerability in the Oracle Banking Digital Experience product of Oracle Financial Services Applications (component: Framework (JDBC)).  Supported versions that are affected are 17.2, 18.1-18.3, 19.1, 19.2, 20.1 and  21.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Banking Digital Experience.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Digital Experience, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Banking Digital Experience. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12605V-17.2</ProductID>
            <ProductID>P-12605V-18.1-18.3</ProductID>
            <ProductID>P-12605V-19.1</ProductID>
            <ProductID>P-12605V-19.2</ProductID>
            <ProductID>P-12605V-20.1</ProductID>
            <ProductID>P-12605V-21.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Digital Experience</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-12605V-17.2</ProductID>
            <ProductID>P-12605V-18.1-18.3</ProductID>
            <ProductID>P-12605V-19.1</ProductID>
            <ProductID>P-12605V-19.2</ProductID>
            <ProductID>P-12605V-20.1</ProductID>
            <ProductID>P-12605V-21.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="113" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="113" Title="Details" Type="Details">Vulnerability in the Big Data Spatial and Graph product of Oracle Big Data Graph (component: Big Data Graph (JDBC)).   The supported version that is affected is Prior to 23.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Big Data Spatial and Graph.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Big Data Spatial and Graph, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Big Data Spatial and Graph. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11528V-Prior to 23.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Big Data Spatial and Graph</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-11528V-Prior to 23.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="114" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="114" Title="Details" Type="Details">Vulnerability in the Oracle Clinical product of Oracle Health Sciences Applications (component: Schema Creation (JDBC)).  Supported versions that are affected are 5.2.1 and  5.2.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Clinical.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Clinical, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Clinical. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-801V-5.2.1</ProductID>
            <ProductID>P-801V-5.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Clinical</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2827314.1</URL>
            <ProductID>P-801V-5.2.1</ProductID>
            <ProductID>P-801V-5.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="115" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="115" Title="Details" Type="Details">Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework (JDBC)).  Supported versions that are affected are 11.3.0, 11.3.1 and  11.3.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Commerce Platform.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Commerce Platform. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9348V-11.3.0</ProductID>
            <ProductID>P-9348V-11.3.1</ProductID>
            <ProductID>P-9348V-11.3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Commerce Platform</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832419.1</URL>
            <ProductID>P-9348V-11.3.0</ProductID>
            <ProductID>P-9348V-11.3.1</ProductID>
            <ProductID>P-9348V-11.3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="116" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="116" Title="Details" Type="Details">Vulnerability in the Oracle Communications Calendar Server product of Oracle Communications Applications (component: Administration (JDBC)).   The supported version that is affected is 8.0.0.5.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Communications Calendar Server.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Calendar Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Calendar Server. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8494V-8.0.0.5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Calendar Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831902.1</URL>
            <ProductID>P-8494V-8.0.0.5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="117" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="117" Title="Details" Type="Details">Vulnerability in the Oracle Communications Contacts Server product of Oracle Communications Applications (component: Database (JDBC)).   The supported version that is affected is 8.0.0.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Communications Contacts Server.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Contacts Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Contacts Server. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10696V-8.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Contacts Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831902.1</URL>
            <ProductID>P-10696V-8.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="118" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="118" Title="Details" Type="Details">Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications Applications (component: ACS (JDBC)).  Supported versions that are affected are 6.0.1.0.0 and  12.0.1.0.0-12.0.4.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Communications Convergent Charging Controller.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Convergent Charging Controller, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Convergent Charging Controller. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12985V-6.0.1.0.0</ProductID>
            <ProductID>P-12985V-12.0.1.0.0-12.0.4.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Convergent Charging Controller</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831885.1</URL>
            <ProductID>P-12985V-6.0.1.0.0</ProductID>
            <ProductID>P-12985V-12.0.1.0.0-12.0.4.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="119" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="119" Title="Details" Type="Details">Vulnerability in Oracle Communications Data Model (component: Utilities (JDBC)).  Supported versions that are affected are 11.3.2.2.0, 12.1.2.0.0, 12.1.0.1.0, 11.3.2.3.0 and  11.3.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Communications Data Model.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Data Model, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Data Model. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4671V-11.3.2.2.0</ProductID>
            <ProductID>P-4671V-12.1.2.0.0</ProductID>
            <ProductID>P-4671V-12.1.0.1.0</ProductID>
            <ProductID>P-4671V-11.3.2.3.0</ProductID>
            <ProductID>P-4671V-11.3.2.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Data Model</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833265.1</URL>
            <ProductID>P-4671V-11.3.2.2.0</ProductID>
            <ProductID>P-4671V-12.1.2.0.0</ProductID>
            <ProductID>P-4671V-12.1.0.1.0</ProductID>
            <ProductID>P-4671V-11.3.2.3.0</ProductID>
            <ProductID>P-4671V-11.3.2.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="120" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="120" Title="Details" Type="Details">Vulnerability in the Oracle Communications Design Studio product of Oracle Communications Applications (component: OSM, NI Plugins (JDBC)).  Supported versions that are affected are 7.3.5, 7.4.0, 7.4.1 and  7.4.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Communications Design Studio.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Design Studio, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Design Studio. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2283V-7.3.5</ProductID>
            <ProductID>P-2283V-7.4.0</ProductID>
            <ProductID>P-2283V-7.4.1</ProductID>
            <ProductID>P-2283V-7.4.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Design Studio</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831888.1</URL>
            <ProductID>P-2283V-7.3.5</ProductID>
            <ProductID>P-2283V-7.4.0</ProductID>
            <ProductID>P-2283V-7.4.1</ProductID>
            <ProductID>P-2283V-7.4.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="121" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="121" Title="Details" Type="Details">Vulnerability in the Oracle Communications Network Charging and Control product of Oracle Communications Applications (component: ACS (JDBC)).  Supported versions that are affected are 6.0.1.0.0 and  12.0.1.0.0-12.0.4.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Communications Network Charging and Control.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Network Charging and Control, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Network Charging and Control. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4623V-6.0.1.0.0</ProductID>
            <ProductID>P-4623V-12.0.1.0.0-12.0.4.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Network Charging and Control</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831885.1</URL>
            <ProductID>P-4623V-6.0.1.0.0</ProductID>
            <ProductID>P-4623V-12.0.1.0.0-12.0.4.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="122" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="122" Title="Details" Type="Details">Vulnerability in the Oracle Communications Network Integrity product of Oracle Communications Applications (component: Installer (JDBC)).  Supported versions that are affected are 7.3.5 and  7.3.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Communications Network Integrity.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Network Integrity, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Network Integrity. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4491V-7.3.5</ProductID>
            <ProductID>P-4491V-7.3.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Network Integrity</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831886.1</URL>
            <ProductID>P-4491V-7.3.5</ProductID>
            <ProductID>P-4491V-7.3.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="123" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="123" Title="Details" Type="Details">Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Runtime Java agent for ODI (JDBC)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Data Integrator.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Data Integrator, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Data Integrator. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2196V-12.2.1.3.0</ProductID>
            <ProductID>P-2196V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Data Integrator</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-2196V-12.2.1.3.0</ProductID>
            <ProductID>P-2196V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="124" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="124" Title="Details" Type="Details">Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: Security (JDBC, OCCI)).  Supported versions that are affected are 12.2.6-12.2.11. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Demantra Demand Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Demantra Demand Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Demantra Demand Management. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2100V-12.2.6-12.2.11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Demantra Demand Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832006.1</URL>
            <ProductID>P-2100V-12.2.6-12.2.11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="125" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="125" Title="Details" Type="Details">Vulnerability in the Oracle Enterprise Data Quality product of Oracle Fusion Middleware (component: General (JDBC)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Enterprise Data Quality.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Enterprise Data Quality, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Data Quality. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9464V-12.2.1.3.0</ProductID>
            <ProductID>P-9464V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Enterprise Data Quality</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-9464V-12.2.1.3.0</ProductID>
            <ProductID>P-9464V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="126" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="126" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Manager Install (JDBC)).  Supported versions that are affected are 13.4.0.0 and  13.5.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Enterprise Manager Base Platform.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-13.4.0.0</ProductID>
            <ProductID>P-1370V-13.5.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Enterprise Manager Base Platform</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-1370V-13.4.0.0</ProductID>
            <ProductID>P-1370V-13.5.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="127" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="127" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Ops Center product of Oracle Enterprise Manager (component: Networking (JDBC)).   The supported version that is affected is 12.4.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Enterprise Manager Ops Center.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Enterprise Manager Ops Center, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Enterprise Manager Ops Center. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9835V-12.4.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Enterprise Manager Ops Center</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-9835V-12.4.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="128" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="128" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Infrastructure Code (JDBC)).  Supported versions that are affected are 12.0.4, 12.1.0, 12.3.0, 12.4.0, 14.4.0 and  14.5.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle FLEXCUBE Investor Servicing.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle FLEXCUBE Investor Servicing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle FLEXCUBE Investor Servicing. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9099V-12.0.4</ProductID>
            <ProductID>P-9099V-12.1.0</ProductID>
            <ProductID>P-9099V-12.3.0</ProductID>
            <ProductID>P-9099V-12.4.0</ProductID>
            <ProductID>P-9099V-14.4.0</ProductID>
            <ProductID>P-9099V-14.5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>FLEXCUBE Investor Servicing</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-9099V-12.0.4</ProductID>
            <ProductID>P-9099V-12.1.0</ProductID>
            <ProductID>P-9099V-12.3.0</ProductID>
            <ProductID>P-9099V-12.4.0</ProductID>
            <ProductID>P-9099V-14.4.0</ProductID>
            <ProductID>P-9099V-14.5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="129" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="129" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Private Banking product of Oracle Financial Services Applications (component: Miscellaneous (JDBC)).  Supported versions that are affected are 12.0.0 and  12.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle FLEXCUBE Private Banking.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle FLEXCUBE Private Banking, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle FLEXCUBE Private Banking. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9110V-12.0.0</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>FLEXCUBE Private Banking</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-9110V-12.0.0</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="130" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="130" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Rate Management (JDBC)).  Supported versions that are affected are 8.0.7-8.1.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Analytical Applications Infrastructure, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Analytical Applications Infrastructure. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5680V-8.0.7-8.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Financial Services Analytical Applications Infrastructure</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2825591.1</URL>
            <ProductID>P-5680V-8.0.7-8.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="131" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="131" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Third Party (JDBC)).  Supported versions that are affected are 8.0.7, 8.0.8 and  8.1.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Financial Services Behavior Detection Platform.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Behavior Detection Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Behavior Detection Platform. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9190V-8.0.7</ProductID>
            <ProductID>P-9190V-8.0.8</ProductID>
            <ProductID>P-9190V-8.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Financial Services Behavior Detection Platform</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832147.1</URL>
            <ProductID>P-9190V-8.0.7</ProductID>
            <ProductID>P-9190V-8.0.8</ProductID>
            <ProductID>P-9190V-8.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="132" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="132" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Financial Services Applications (component: Installers (JDBC)).  Supported versions that are affected are 8.0.7, 8.0.8 and  8.1.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Financial Services Enterprise Case Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Enterprise Case Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Enterprise Case Management. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13545V-8.0.7</ProductID>
            <ProductID>P-13545V-8.0.8</ProductID>
            <ProductID>P-13545V-8.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Financial Services Enterprise Case Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832152.1</URL>
            <ProductID>P-13545V-8.0.7</ProductID>
            <ProductID>P-13545V-8.0.8</ProductID>
            <ProductID>P-13545V-8.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="133" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="133" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Foreign Account Tax Compliance Act Management product of Oracle Financial Services Applications (component: Installation (JDBC)).  Supported versions that are affected are 8.0.7, 8.0.8 and  8.1.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Financial Services Foreign Account Tax Compliance Act Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Foreign Account Tax Compliance Act Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Foreign Account Tax Compliance Act Management. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10308V-8.0.7</ProductID>
            <ProductID>P-10308V-8.0.8</ProductID>
            <ProductID>P-10308V-8.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Financial Services Foreign Account Tax Compliance Act Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-10308V-8.0.7</ProductID>
            <ProductID>P-10308V-8.0.8</ProductID>
            <ProductID>P-10308V-8.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="134" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="134" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer &amp; Configuration (JDBC)).  Supported versions that are affected are 8.0.8-8.1.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Financial Services Model Management and Governance.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Model Management and Governance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Model Management and Governance. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14276V-8.0.8-8.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Financial Services Model Management and Governance</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2825611.1</URL>
            <ProductID>P-14276V-8.0.8-8.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="135" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="135" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition product of Oracle Financial Services Applications (component: User Interface (JDBC)).  Supported versions that are affected are 8.0.7 and  8.0.8. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13789V-8.0.7</ProductID>
            <ProductID>P-13789V-8.0.8</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Financial Services Trade-Based Anti Money Laundering Enterprise Edition</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833718.1</URL>
            <ProductID>P-13789V-8.0.7</ProductID>
            <ProductID>P-13789V-8.0.8</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="136" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="136" Title="Details" Type="Details">Vulnerability in Oracle Fusion Middleware (component: Centralized Third-party Jars (JDBC, OCCI, ODP for .NET)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Fusion Middleware.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Fusion Middleware, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Fusion Middleware. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1032V-12.2.1.3.0</ProductID>
            <ProductID>P-1032V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Fusion Middleware</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-1032V-12.2.1.3.0</ProductID>
            <ProductID>P-1032V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="137" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="137" Title="Details" Type="Details">Vulnerability in Oracle GoldenGate (component: Database (OCCI)).  Supported versions that are affected are Prior to 21.5.0.0.220118, Prior to 19.1.0.0.220118 and  Prior to 12.3.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle GoldenGate.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle GoldenGate, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5757V-Prior to 21.5.0.0.220118</ProductID>
            <ProductID>P-5757V-Prior to 19.1.0.0.220118</ProductID>
            <ProductID>P-5757V-Prior to 12.3.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>GoldenGate</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5757V-Prior to 21.5.0.0.220118</ProductID>
            <ProductID>P-5757V-Prior to 19.1.0.0.220118</ProductID>
            <ProductID>P-5757V-Prior to 12.3.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="138" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="138" Title="Details" Type="Details">Vulnerability in Oracle Graph Server and Client (component: Packaging/install issues (JDBC)).   The supported version that is affected is Prior to 21.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Graph Server and Client.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Graph Server and Client, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Graph Server and Client. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14069V-Prior to 21.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Graph Server and Client</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-14069V-Prior to 21.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="139" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="139" Title="Details" Type="Details">Vulnerability in the Oracle Health Sciences Clinical Development Analytics product of Oracle Health Sciences Applications (component: Installation (JDBC)).   The supported version that is affected is 4.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Health Sciences Clinical Development Analytics.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Health Sciences Clinical Development Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Health Sciences Clinical Development Analytics. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5563V-4.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Health Sciences Clinical Development Analytics</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2827314.1</URL>
            <ProductID>P-5563V-4.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="140" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="140" Title="Details" Type="Details">Vulnerability in the Oracle Health Sciences InForm CRF Submit product of Oracle Health Sciences Applications (component: Installation and Configuration (JDBC, ODP for .NET)).   The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Health Sciences InForm CRF Submit.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Health Sciences InForm CRF Submit, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Health Sciences InForm CRF Submit. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9641V-6.2.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Health Sciences InForm CRF Submit</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2827314.1</URL>
            <ProductID>P-9641V-6.2.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="141" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="141" Title="Details" Type="Details">Vulnerability in the Oracle Health Sciences Information Manager product of Oracle HealthCare Applications (component: Health Policy Engine (JDBC)).  Supported versions that are affected are 3.0.2 and  3.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Health Sciences Information Manager.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Health Sciences Information Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Health Sciences Information Manager. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9177V-3.0.2</ProductID>
            <ProductID>P-9177V-3.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Health Sciences Information Manager</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2827318.1</URL>
            <ProductID>P-9177V-3.0.2</ProductID>
            <ProductID>P-9177V-3.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="142" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="142" Title="Details" Type="Details">Vulnerability in the Oracle Healthcare Data Repository product of Oracle HealthCare Applications (component: Installation (JDBC)).  Supported versions that are affected are 7.0.2, 8.1.0 and  8.1.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Healthcare Data Repository.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Healthcare Data Repository, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Healthcare Data Repository. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9161V-7.0.2</ProductID>
            <ProductID>P-9161V-8.1.0</ProductID>
            <ProductID>P-9161V-8.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Healthcare Data Repository</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2827318.1</URL>
            <ProductID>P-9161V-7.0.2</ProductID>
            <ProductID>P-9161V-8.1.0</ProductID>
            <ProductID>P-9161V-8.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="143" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="143" Title="Details" Type="Details">Vulnerability in the Oracle Healthcare Foundation product of Oracle HealthCare Applications (component: Installation (JDBC)).  Supported versions that are affected are 7.3.0.0-7.3.0.2, 8.0.0-8.0.2 and  8.1.0-8.1.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Healthcare Foundation.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Healthcare Foundation, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Healthcare Foundation. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12950V-7.3.0.0-7.3.0.2</ProductID>
            <ProductID>P-12950V-8.0.0-8.0.2</ProductID>
            <ProductID>P-12950V-8.1.0-8.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Healthcare Foundation</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2827318.1</URL>
            <ProductID>P-12950V-7.3.0.0-7.3.0.2</ProductID>
            <ProductID>P-12950V-8.0.0-8.0.2</ProductID>
            <ProductID>P-12950V-8.1.0-8.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="144" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="144" Title="Details" Type="Details">Vulnerability in the Oracle Healthcare Translational Research product of Oracle HealthCare Applications (component: Installation (JDBC)).   The supported version that is affected is 4.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Healthcare Translational Research.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Healthcare Translational Research, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Healthcare Translational Research. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9427V-4.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Healthcare Translational Research</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2827318.1</URL>
            <ProductID>P-9427V-4.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="145" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="145" Title="Details" Type="Details">Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Integrations (JDBC, ODP for .NET)).   The supported version that is affected is 5.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Hospitality OPERA 5.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality OPERA 5, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hospitality OPERA 5. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11580V-5.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Hospitality OPERA 5 Property Services</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2824790.1</URL>
            <ProductID>P-11580V-5.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="146" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="146" Title="Details" Type="Details">Vulnerability in the Oracle Hospitality Suite8 product of Oracle Hospitality Applications (component: Rest API (ODP for .NET)).  Supported versions that are affected are 8.10.2, 8.11.0, 8.12.0, 8.13.0 and  8.14.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Hospitality Suite8.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality Suite8, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Suite8. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12619V-8.10.2</ProductID>
            <ProductID>P-12619V-8.11.0</ProductID>
            <ProductID>P-12619V-8.12.0</ProductID>
            <ProductID>P-12619V-8.13.0</ProductID>
            <ProductID>P-12619V-8.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Hospitality Suite8</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2824342.1</URL>
            <ProductID>P-12619V-8.10.2</ProductID>
            <ProductID>P-12619V-8.11.0</ProductID>
            <ProductID>P-12619V-8.12.0</ProductID>
            <ProductID>P-12619V-8.13.0</ProductID>
            <ProductID>P-12619V-8.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="147" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="147" Title="Details" Type="Details">Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration (JDBC, OCCI, ODP for .NET)).   The supported version that is affected is 11.2.7.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4392V-11.2.7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Hyperion Infrastructure Technology</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-4392V-11.2.7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="148" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="148" Title="Details" Type="Details">Vulnerability in the Oracle Insurance Data Gateway product of Oracle Insurance Applications (component: Security (JDBC)).  Supported versions that are affected are 11.0.2, 11.1.0, 11.2.7, 11.3.0 and  11.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Data Gateway.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Insurance Data Gateway, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Insurance Data Gateway. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13628V-11.0.2</ProductID>
            <ProductID>P-13628V-11.1.0</ProductID>
            <ProductID>P-13628V-11.2.7</ProductID>
            <ProductID>P-13628V-11.3.0</ProductID>
            <ProductID>P-13628V-11.3.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Insurance Data Gateway</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832476.1</URL>
            <ProductID>P-13628V-11.0.2</ProductID>
            <ProductID>P-13628V-11.1.0</ProductID>
            <ProductID>P-13628V-11.2.7</ProductID>
            <ProductID>P-13628V-11.3.0</ProductID>
            <ProductID>P-13628V-11.3.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="149" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="149" Title="Details" Type="Details">Vulnerability in the Oracle Insurance Insbridge Rating and Underwriting product of Oracle Insurance Applications (component: Framework Administrator IBFA (JDBC, ODP for .NET)).  Supported versions that are affected are 5.2.0 and  5.4.0-5.6.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Insurance Insbridge Rating and Underwriting.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Insurance Insbridge Rating and Underwriting, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Insurance Insbridge Rating and Underwriting. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5484V-5.2.0</ProductID>
            <ProductID>P-5484V-5.4.0-5.6.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Insurance Insbridge Rating and Underwriting</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832476.1</URL>
            <ProductID>P-5484V-5.2.0</ProductID>
            <ProductID>P-5484V-5.4.0-5.6.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="150" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="150" Title="Details" Type="Details">Vulnerability in the Oracle Insurance Policy Administration product of Oracle Insurance Applications (component: Architecture (JDBC)).  Supported versions that are affected are 11.0.2, 11.1.0, 11.2.7, 11.3.0 and  11.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Insurance Policy Administration.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Insurance Policy Administration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Insurance Policy Administration. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5279V-11.0.2</ProductID>
            <ProductID>P-5279V-11.1.0</ProductID>
            <ProductID>P-5279V-11.2.7</ProductID>
            <ProductID>P-5279V-11.3.0</ProductID>
            <ProductID>P-5279V-11.3.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Insurance Policy Administration J2EE</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832476.1</URL>
            <ProductID>P-5279V-11.0.2</ProductID>
            <ProductID>P-5279V-11.1.0</ProductID>
            <ProductID>P-5279V-11.2.7</ProductID>
            <ProductID>P-5279V-11.3.0</ProductID>
            <ProductID>P-5279V-11.3.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="151" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="151" Title="Details" Type="Details">Vulnerability in the Oracle Insurance Rules Palette product of Oracle Insurance Applications (component: Architecture (JDBC)).  Supported versions that are affected are 11.0.2, 11.1.0, 11.2.7, 11.3.0 and  11.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Insurance Rules Palette.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Insurance Rules Palette, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Insurance Rules Palette. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5288V-11.0.2</ProductID>
            <ProductID>P-5288V-11.1.0</ProductID>
            <ProductID>P-5288V-11.2.7</ProductID>
            <ProductID>P-5288V-11.3.0</ProductID>
            <ProductID>P-5288V-11.3.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Insurance Rules Palette</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832476.1</URL>
            <ProductID>P-5288V-11.0.2</ProductID>
            <ProductID>P-5288V-11.1.0</ProductID>
            <ProductID>P-5288V-11.2.7</ProductID>
            <ProductID>P-5288V-11.3.0</ProductID>
            <ProductID>P-5288V-11.3.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="152" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="152" Title="Details" Type="Details">Vulnerability in the OSS Support Tools product of Oracle Support Tools (component: Diagnostic Assistant (JDBC)).   The supported version that is affected is Prior to 2.12.42. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise OSS Support Tools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in OSS Support Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of OSS Support Tools. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1330V-Prior to 2.12.42</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>OSS Support Tools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833277.1</URL>
            <ProductID>P-1330V-Prior to 2.12.42</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="153" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="153" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Change Impact Analyzer (JDBC)).  Supported versions that are affected are 8.57, 8.58 and  8.59. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>PeopleSoft Enterprise PT PeopleTools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831970.1</URL>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="154" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="154" Title="Details" Type="Details">Vulnerability in Oracle Policy Automation (component: Determinations Engine (JDBC)).  Supported versions that are affected are 12.2.0-12.2.24. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Policy Automation.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Policy Automation, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Policy Automation. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5624V-12.2.0-12.2.24</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Policy Automation</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832841.1</URL>
            <ProductID>P-5624V-12.2.0-12.2.24</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="155" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="155" Title="Details" Type="Details">Vulnerability in the Primavera Analytics product of Oracle Construction and Engineering (component: ETL (JDBC)).  Supported versions that are affected are 18.8.3.3, 19.12.11.1 and  20.12.12.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Primavera Analytics.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Primavera Analytics. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8577V-18.8.3.3</ProductID>
            <ProductID>P-8577V-19.12.11.1</ProductID>
            <ProductID>P-8577V-20.12.12.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera Analytics</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2829871.1</URL>
            <ProductID>P-8577V-18.8.3.3</ProductID>
            <ProductID>P-8577V-19.12.11.1</ProductID>
            <ProductID>P-8577V-20.12.12.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="156" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="156" Title="Details" Type="Details">Vulnerability in the Primavera Data Warehouse product of Oracle Construction and Engineering (component: ETL (JDBC)).  Supported versions that are affected are 18.8.3.3, 19.12.11.1 and  20.12.12.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Primavera Data Warehouse.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera Data Warehouse, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Primavera Data Warehouse. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5585V-18.8.3.3</ProductID>
            <ProductID>P-5585V-19.12.11.1</ProductID>
            <ProductID>P-5585V-20.12.12.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera Data Warehouse</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2829871.1</URL>
            <ProductID>P-5585V-18.8.3.3</ProductID>
            <ProductID>P-5585V-19.12.11.1</ProductID>
            <ProductID>P-5585V-20.12.12.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="157" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="157" Title="Details" Type="Details">Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access (JDBC)).  Supported versions that are affected are 17.12.0.0-17.12.20.0, 18.8.0.0-18.8.24.0, 19.12.0.0-19.12.17.0 and  20.12.0.0-20.12.9.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Primavera P6 Enterprise Project Portfolio Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera P6 Enterprise Project Portfolio Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Primavera P6 Enterprise Project Portfolio Management. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5579V-17.12.0.0-17.12.20.0</ProductID>
            <ProductID>P-5579V-18.8.0.0-18.8.24.0</ProductID>
            <ProductID>P-5579V-19.12.0.0-19.12.17.0</ProductID>
            <ProductID>P-5579V-20.12.0.0-20.12.9.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera P6 Enterprise Project Portfolio Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2829871.1</URL>
            <ProductID>P-5579V-17.12.0.0-17.12.20.0</ProductID>
            <ProductID>P-5579V-18.8.0.0-18.8.24.0</ProductID>
            <ProductID>P-5579V-19.12.0.0-19.12.17.0</ProductID>
            <ProductID>P-5579V-20.12.0.0-20.12.9.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="158" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="158" Title="Details" Type="Details">Vulnerability in the Primavera P6 Professional Project Management product of Oracle Construction and Engineering (component: API component of P6 Pro (JDBC)).  Supported versions that are affected are 17.12.0.0-17.12.20.0, 18.8.0.0-18.8.24.0, 19.12.0.0-19.12.17.0 and  20.12.0.0-20.12.9.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Primavera P6 Professional Project Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera P6 Professional Project Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Primavera P6 Professional Project Management. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5580V-17.12.0.0-17.12.20.0</ProductID>
            <ProductID>P-5580V-18.8.0.0-18.8.24.0</ProductID>
            <ProductID>P-5580V-19.12.0.0-19.12.17.0</ProductID>
            <ProductID>P-5580V-20.12.0.0-20.12.9.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera P6 Professional Project Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2829871.1</URL>
            <ProductID>P-5580V-17.12.0.0-17.12.20.0</ProductID>
            <ProductID>P-5580V-18.8.0.0-18.8.24.0</ProductID>
            <ProductID>P-5580V-19.12.0.0-19.12.17.0</ProductID>
            <ProductID>P-5580V-20.12.0.0-20.12.9.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="159" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="159" Title="Details" Type="Details">Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform,Data Access,Data Persistence (JDBC)).  Supported versions that are affected are 17.7-17.12, 18.8, 19.12, 20.12 and  21.12. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Primavera Unifier.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera Unifier, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Primavera Unifier. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10354V-17.7-17.12</ProductID>
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
            <ProductID>P-10354V-20.12</ProductID>
            <ProductID>P-10354V-21.12</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera Unifier</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2829871.1</URL>
            <ProductID>P-10354V-17.7-17.12</ProductID>
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
            <ProductID>P-10354V-20.12</ProductID>
            <ProductID>P-10354V-21.12</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="160" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="160" Title="Details" Type="Details">Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation (JDBC)).   The supported version that is affected is 3.6.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Product Lifecycle Analytics.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9387V-3.6.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Product Lifecycle Analytics</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832006.1</URL>
            <ProductID>P-9387V-3.6.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="161" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="161" Title="Details" Type="Details">Vulnerability in the Oracle Rapid Planning product of Oracle Supply Chain (component: Middle Tier (JDBC, OCCI)).  Supported versions that are affected are 12.2.6-12.2.11. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Rapid Planning.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Rapid Planning, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Rapid Planning. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5235V-12.2.6-12.2.11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Rapid Planning</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832006.1</URL>
            <ProductID>P-5235V-12.2.6-12.2.11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="162" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="162" Title="Details" Type="Details">Vulnerability in the Oracle Retail Analytics product of Oracle Retail Applications (component: Other (JDBC)).  Supported versions that are affected are 16.0.0-16.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Analytics.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Retail Analytics. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9346V-16.0.0-16.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Analytics</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-9346V-16.0.0-16.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="163" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="163" Title="Details" Type="Details">Vulnerability in the Oracle Retail Assortment Planning product of Oracle Retail Applications (component: Application Core (JDBC)).   The supported version that is affected is 16.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Assortment Planning.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Assortment Planning, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Retail Assortment Planning. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1788V-16.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Assortment Planning</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-1788V-16.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="164" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="164" Title="Details" Type="Details">Vulnerability in the Oracle Retail Back Office product of Oracle Retail Applications (component: Security (JDBC)).   The supported version that is affected is 14.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Back Office.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Back Office, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Retail Back Office. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2013V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Back Office</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-2013V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="165" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="165" Title="Details" Type="Details">Vulnerability in the Oracle Retail Central Office product of Oracle Retail Applications (component: Security (JDBC)).   The supported version that is affected is 14.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Central Office.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Central Office, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Retail Central Office. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2016V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Central Office</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-2016V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="166" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="166" Title="Details" Type="Details">Vulnerability in the Oracle Retail Customer Insights product of Oracle Retail Applications (component: Other (JDBC)).  Supported versions that are affected are 16.0.0-16.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Customer Insights.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Customer Insights, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Retail Customer Insights. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10263V-16.0.0-16.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Customer Insights</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-10263V-16.0.0-16.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="167" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="167" Title="Details" Type="Details">Vulnerability in the Oracle Retail Extract Transform and Load product of Oracle Retail Applications (component: Mathematical Operators (JDBC)).   The supported version that is affected is 13.2.8. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Extract Transform and Load.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Extract Transform and Load, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Retail Extract Transform and Load. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1803V-13.2.8</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Extract Tranform and Load</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-1803V-13.2.8</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="168" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="168" Title="Details" Type="Details">Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration Bugs (JDBC)).  Supported versions that are affected are 14.1.3.2, 15.0.3.1, 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Financial Integration.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Financial Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Retail Financial Integration. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10722V-14.1.3.2</ProductID>
            <ProductID>P-10722V-15.0.3.1</ProductID>
            <ProductID>P-10722V-16.0.3</ProductID>
            <ProductID>P-10722V-19.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Financial Integration</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-10722V-14.1.3.2</ProductID>
            <ProductID>P-10722V-15.0.3.1</ProductID>
            <ProductID>P-10722V-16.0.3</ProductID>
            <ProductID>P-10722V-19.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="169" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="169" Title="Details" Type="Details">Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (JDBC)).  Supported versions that are affected are 14.1.3.2, 15.0.3.1, 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Integration Bus.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Integration Bus, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1807V-14.1.3.2</ProductID>
            <ProductID>P-1807V-15.0.3.1</ProductID>
            <ProductID>P-1807V-16.0.3</ProductID>
            <ProductID>P-1807V-19.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Integration Bus</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-1807V-14.1.3.2</ProductID>
            <ProductID>P-1807V-15.0.3.1</ProductID>
            <ProductID>P-1807V-16.0.3</ProductID>
            <ProductID>P-1807V-19.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="170" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="170" Title="Details" Type="Details">Vulnerability in the Oracle Retail Merchandising System product of Oracle Retail Applications (component: Foundation (JDBC)).   The supported version that is affected is 19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Merchandising System.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Merchandising System, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Retail Merchandising System. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1816V-19.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Merchandising System</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-1816V-19.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="171" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="171" Title="Details" Type="Details">Vulnerability in the Oracle Retail Order Broker product of Oracle Retail Applications (component: System Administration (JDBC)).  Supported versions that are affected are 16.0, 18.0 and  19.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Order Broker.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Order Broker, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Retail Order Broker. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11520V-16.0</ProductID>
            <ProductID>P-11520V-18.0</ProductID>
            <ProductID>P-11520V-19.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Order Broker Cloud Service</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-11520V-16.0</ProductID>
            <ProductID>P-11520V-18.0</ProductID>
            <ProductID>P-11520V-19.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="172" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="172" Title="Details" Type="Details">Vulnerability in the Oracle Retail Order Management System product of Oracle Retail Applications (component: Upgrade Install (JDBC)).   The supported version that is affected is 19.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Order Management System.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Order Management System, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Retail Order Management System. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11519V-19.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Order Management System Cloud Service</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-11519V-19.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="173" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="173" Title="Details" Type="Details">Vulnerability in the Oracle Retail Point-of-Service product of Oracle Retail Applications (component: Security (JDBC)).   The supported version that is affected is 14.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Point-of-Service.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Point-of-Service, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Retail Point-of-Service. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2017V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Point-of-Service</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-2017V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="174" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="174" Title="Details" Type="Details">Vulnerability in the Oracle Retail Predictive Application Server product of Oracle Retail Applications (component: RPAS Server (OCCI)).  Supported versions that are affected are 14.1.3, 15.0.3 and  16.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Predictive Application Server.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Predictive Application Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Retail Predictive Application Server. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1823V-14.1.3</ProductID>
            <ProductID>P-1823V-15.0.3</ProductID>
            <ProductID>P-1823V-16.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Predictive Application Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-1823V-14.1.3</ProductID>
            <ProductID>P-1823V-15.0.3</ProductID>
            <ProductID>P-1823V-16.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="175" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="175" Title="Details" Type="Details">Vulnerability in the Oracle Retail Price Management product of Oracle Retail Applications (component: Security (JDBC)).  Supported versions that are affected are 14.1, 15 and  16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Price Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Price Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Retail Price Management. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1824V-14.1</ProductID>
            <ProductID>P-1824V-15</ProductID>
            <ProductID>P-1824V-16</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Price Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-1824V-14.1</ProductID>
            <ProductID>P-1824V-15</ProductID>
            <ProductID>P-1824V-16</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="176" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="176" Title="Details" Type="Details">Vulnerability in the Oracle Retail Returns Management product of Oracle Retail Applications (component: Security (JDBC)).   The supported version that is affected is 14.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Returns Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Returns Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Retail Returns Management. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2020V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Returns Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-2020V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="177" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="177" Title="Details" Type="Details">Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (JDBC)).  Supported versions that are affected are 14.1.3.2, 15.0.3.1, 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Service Backbone.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Service Backbone, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Retail Service Backbone. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10867V-14.1.3.2</ProductID>
            <ProductID>P-10867V-15.0.3.1</ProductID>
            <ProductID>P-10867V-16.0.3</ProductID>
            <ProductID>P-10867V-19.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Service Backbone</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-10867V-14.1.3.2</ProductID>
            <ProductID>P-10867V-15.0.3.1</ProductID>
            <ProductID>P-10867V-16.0.3</ProductID>
            <ProductID>P-10867V-19.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="178" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="178" Title="Details" Type="Details">Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (JDBC)).  Supported versions that are affected are 17.0.4, 18.0.3, 19.0.2 and  20.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Xstore Point of Service.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Xstore Point of Service, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11513V-17.0.4</ProductID>
            <ProductID>P-11513V-18.0.3</ProductID>
            <ProductID>P-11513V-19.0.2</ProductID>
            <ProductID>P-11513V-20.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Xstore Point of Service</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-11513V-17.0.4</ProductID>
            <ProductID>P-11513V-18.0.3</ProductID>
            <ProductID>P-11513V-19.0.2</ProductID>
            <ProductID>P-11513V-20.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="179" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="179" Title="Details" Type="Details">Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: EAI (JDBC)).  Supported versions that are affected are 21.12 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Siebel UI Framework.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel UI Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel UI Framework. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9011V-21.12 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Siebel UI Framework</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832003.1</URL>
            <ProductID>P-9011V-21.12 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="180" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="180" Title="Details" Type="Details">Vulnerability in Oracle Spatial Studio (component: Install (JDBC)).   The supported version that is affected is Prior to 21.2.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Spatial Studio.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Spatial Studio, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Spatial Studio. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13600V-Prior to 21.2.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Spatial Studio</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-13600V-Prior to 21.2.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="181" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="181" Title="Details" Type="Details">Vulnerability in the Oracle ZFS Storage Application Integration Engineering Software product of Oracle Systems (component: Snap Management Utility (JDBC)).   The supported version that is affected is 1.3.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle ZFS Storage Application Integration Engineering Software.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle ZFS Storage Application Integration Engineering Software, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle ZFS Storage Application Integration Engineering Software. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10027V-1.3.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Sun ZFS Storage Application Integration Engineering Software</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832878.1</URL>
            <ProductID>P-10027V-1.3.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="182" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="182" Title="Details" Type="Details">Vulnerability in the Oracle Thesaurus Management System product of Oracle Health Sciences Applications (component: Report Generation (JDBC)).  Supported versions that are affected are 5.2.3, 5.3.0 and  5.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Thesaurus Management System.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Thesaurus Management System, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Thesaurus Management System. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-192V-5.2.3</ProductID>
            <ProductID>P-192V-5.3.0</ProductID>
            <ProductID>P-192V-5.3.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Thesaurus Management System</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2827314.1</URL>
            <ProductID>P-192V-5.2.3</ProductID>
            <ProductID>P-192V-5.3.0</ProductID>
            <ProductID>P-192V-5.3.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="183" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="183" Title="Details" Type="Details">Vulnerability in Oracle TimesTen In-Memory Database (component: EM TimesTen plug-in (JDBC,OCCI)).   The supported version that is affected is Prior to 21.1.1.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via OracleNet to compromise Oracle TimesTen In-Memory Database.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle TimesTen In-Memory Database, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle TimesTen In-Memory Database. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1870V-Prior to 21.1.1.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>TimesTen In-Memory Database</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-1870V-Prior to 21.1.1.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="184" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="184" Title="Details" Type="Details">Vulnerability in the Oracle Utilities Framework product of Oracle Utilities Applications (component: General (JDBC)).  Supported versions that are affected are 4.2.0.3.0, 4.3.0.1.0-4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0 and  4.4.0.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Framework.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Utilities Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Utilities Framework. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2245V-4.2.0.3.0</ProductID>
            <ProductID>P-2245V-4.3.0.1.0-4.3.0.6.0</ProductID>
            <ProductID>P-2245V-4.4.0.0.0</ProductID>
            <ProductID>P-2245V-4.4.0.2.0</ProductID>
            <ProductID>P-2245V-4.4.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Utilities Framework</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832617.1</URL>
            <ProductID>P-2245V-4.2.0.3.0</ProductID>
            <ProductID>P-2245V-4.3.0.1.0-4.3.0.6.0</ProductID>
            <ProductID>P-2245V-4.4.0.0.0</ProductID>
            <ProductID>P-2245V-4.4.0.2.0</ProductID>
            <ProductID>P-2245V-4.4.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="185" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="185" Title="Details" Type="Details">Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (JDBC)).  Supported versions that are affected are 6.0.0.1.1, 6.0.0.2.2 and  6.0.0.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Utilities Testing Accelerator.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Utilities Testing Accelerator, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Utilities Testing Accelerator. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13784V-6.0.0.1.1</ProductID>
            <ProductID>P-13784V-6.0.0.2.2</ProductID>
            <ProductID>P-13784V-6.0.0.3.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Utilities Testing Accelerator</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832617.1</URL>
            <ProductID>P-13784V-6.0.0.1.1</ProductID>
            <ProductID>P-13784V-6.0.0.2.2</ProductID>
            <ProductID>P-13784V-6.0.0.3.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="186" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="186" Title="Details" Type="Details">Vulnerability in Oracle iLearning (component: Installation (JDBC)).  Supported versions that are affected are 6.2 and  6.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle iLearning.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iLearning, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle iLearning. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-902V-6.2</ProductID>
            <ProductID>P-902V-6.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>iLearning</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2732007.1</URL>
            <ProductID>P-902V-6.2</ProductID>
            <ProductID>P-902V-6.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="187" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-23840</Title>
      <Notes>
         <Note Audience="All" Ordinal="187" Title="Details" Type="Details">Vulnerability in the Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers product of Oracle Systems (component: XCP Firmware (OpenSSL)).  Supported versions that are affected are Prior to XCP2410 and  prior to XCP3110. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-23840</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10656V-Prior to XCP2410</ProductID>
            <ProductID>P-10656V-prior to XCP3110</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Fujitsu SPARC Servers Firmware</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832878.1</URL>
            <ProductID>P-10656V-Prior to XCP2410</ProductID>
            <ProductID>P-10656V-prior to XCP3110</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="188" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-25122</Title>
      <Notes>
         <Note Audience="All" Ordinal="188" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (Apache Tomcat)).   The supported version that is affected is 1.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-25122</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14123V-1.6.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Security Edge Protection Proxy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833594.1</URL>
            <ProductID>P-14123V-1.6.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="189" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-25122</Title>
      <Notes>
         <Note Audience="All" Ordinal="189" Title="Details" Type="Details">Vulnerability in the Oracle Communications Instant Messaging Server product of Oracle Communications Applications (component: DBPlugin (Apache Tomcat)).   The supported version that is affected is 10.0.1.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via XMPP to compromise Oracle Communications Instant Messaging Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Instant Messaging Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-25122</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8495V-10.0.1.5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Instant Messaging Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831902.1</URL>
            <ProductID>P-8495V-10.0.1.5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="190" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-26691</Title>
      <Notes>
         <Note Audience="All" Ordinal="190" Title="Details" Type="Details">Vulnerability in Oracle Secure Backup (component: Oracle Secure Backup (Apache HTTP Server)).   The supported version that is affected is Prior to 18.1.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Secure Backup.  Successful attacks of this vulnerability can result in takeover of Oracle Secure Backup. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-26691</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1522V-Prior to 18.1.0.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Secure Backup</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-1522V-Prior to 18.1.0.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="191" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-27568</Title>
      <Notes>
         <Note Audience="All" Ordinal="191" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (netplex json-smart)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-27568</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14277V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Policy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833602.1</URL>
            <ProductID>P-14277V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="192" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-27568</Title>
      <Notes>
         <Note Audience="All" Ordinal="192" Title="Details" Type="Details">Vulnerability in the OSS Support Tools product of Oracle Support Tools (component: Diagnostic Assistant (json-smart)).   The supported version that is affected is Prior to 2.12.42. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise OSS Support Tools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all OSS Support Tools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of OSS Support Tools. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-27568</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1330V-Prior to 2.12.42</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>OSS Support Tools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833277.1</URL>
            <ProductID>P-1330V-Prior to 2.12.42</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="193" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-27568</Title>
      <Notes>
         <Note Audience="All" Ordinal="193" Title="Details" Type="Details">Vulnerability in the Oracle Utilities Framework product of Oracle Utilities Applications (component: Common (json-smart)).  Supported versions that are affected are 4.4.0.0.0, 4.4.0.2.0 and  4.4.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Framework.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Utilities Framework accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Framework. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-27568</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2245V-4.4.0.0.0</ProductID>
            <ProductID>P-2245V-4.4.0.2.0</ProductID>
            <ProductID>P-2245V-4.4.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Utilities Framework</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832617.1</URL>
            <ProductID>P-2245V-4.4.0.0.0</ProductID>
            <ProductID>P-2245V-4.4.0.2.0</ProductID>
            <ProductID>P-2245V-4.4.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="194" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-27568</Title>
      <Notes>
         <Note Audience="All" Ordinal="194" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services (json-smart)).  Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-27568</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="195" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-28164</Title>
      <Notes>
         <Note Audience="All" Ordinal="195" Title="Details" Type="Details">Vulnerability in the Oracle Banking APIs product of Oracle Financial Services Applications (component: Framework (Apache Ignite)).  Supported versions that are affected are 20.1 and  21.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking APIs.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Banking APIs accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-28164</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13676V-20.1</ProductID>
            <ProductID>P-13676V-21.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking APIs</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-13676V-20.1</ProductID>
            <ProductID>P-13676V-21.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="196" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-28164</Title>
      <Notes>
         <Note Audience="All" Ordinal="196" Title="Details" Type="Details">Vulnerability in the Oracle Banking Digital Experience product of Oracle Financial Services Applications (component: Framework (Apache Ignite)).  Supported versions that are affected are 20.1 and  21.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Digital Experience.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Banking Digital Experience accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-28164</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12605V-20.1</ProductID>
            <ProductID>P-12605V-21.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Digital Experience</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-12605V-20.1</ProductID>
            <ProductID>P-12605V-21.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="197" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-28165</Title>
      <Notes>
         <Note Audience="All" Ordinal="197" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (Eclipse Jetty)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-28165</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14277V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Policy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833602.1</URL>
            <ProductID>P-14277V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="198" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-28165</Title>
      <Notes>
         <Note Audience="All" Ordinal="198" Title="Details" Type="Details">Security-in-Depth issue in the Workload Manager (Jetty) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-28165</CVE>
      <ProductStatuses>
         <Status Type="Known Not Affected">
            <ProductID>P-5V-All Supported Versions</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Database - Enterprise Edition</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5V-All Supported Versions</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="199" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-28165</Title>
      <Notes>
         <Note Audience="All" Ordinal="199" Title="Details" Type="Details">Vulnerability in Oracle REST Data Services (component: General  (Eclipse Jetty)).   The supported version that is affected is Prior to 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle REST Data Services.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle REST Data Services. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-28165</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9456V-Prior to 21.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>REST Data Services</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-9456V-Prior to 21.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="200" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29425</Title>
      <Notes>
         <Note Audience="All" Ordinal="200" Title="Details" Type="Details">Vulnerability in the Oracle Banking APIs product of Oracle Financial Services Applications (component: Framework (Apache Commons IO)).  Supported versions that are affected are 18.1-18.3, 19.1, 19.2, 20.1 and  21.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking APIs.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Banking APIs accessible data as well as  unauthorized read access to a subset of Oracle Banking APIs accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29425</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13676V-18.1-18.3</ProductID>
            <ProductID>P-13676V-19.1</ProductID>
            <ProductID>P-13676V-19.2</ProductID>
            <ProductID>P-13676V-20.1</ProductID>
            <ProductID>P-13676V-21.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking APIs</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-13676V-18.1-18.3</ProductID>
            <ProductID>P-13676V-19.1</ProductID>
            <ProductID>P-13676V-19.2</ProductID>
            <ProductID>P-13676V-20.1</ProductID>
            <ProductID>P-13676V-21.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="201" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29425</Title>
      <Notes>
         <Note Audience="All" Ordinal="201" Title="Details" Type="Details">Vulnerability in the Oracle Banking Digital Experience product of Oracle Financial Services Applications (component: Framework (Apache Commons IO)).  Supported versions that are affected are 17.2, 18.1-18.3, 19.1, 19.2, 20.1 and  21.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Digital Experience.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Banking Digital Experience accessible data as well as  unauthorized read access to a subset of Oracle Banking Digital Experience accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29425</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12605V-17.2</ProductID>
            <ProductID>P-12605V-18.1-18.3</ProductID>
            <ProductID>P-12605V-19.1</ProductID>
            <ProductID>P-12605V-19.2</ProductID>
            <ProductID>P-12605V-20.1</ProductID>
            <ProductID>P-12605V-21.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Digital Experience</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-12605V-17.2</ProductID>
            <ProductID>P-12605V-18.1-18.3</ProductID>
            <ProductID>P-12605V-19.1</ProductID>
            <ProductID>P-12605V-19.2</ProductID>
            <ProductID>P-12605V-20.1</ProductID>
            <ProductID>P-12605V-21.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="202" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29425</Title>
      <Notes>
         <Note Audience="All" Ordinal="202" Title="Details" Type="Details">Vulnerability in the Oracle Banking Enterprise Default Management product of Oracle Financial Services Applications (component: Collections (Apache Commons IO)).  Supported versions that are affected are 2.3.0-2.4.1, 2.6.2, 2.7.1, 2.10.0 and  2.12.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Enterprise Default Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Banking Enterprise Default Management accessible data as well as  unauthorized read access to a subset of Oracle Banking Enterprise Default Management accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29425</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13390V-2.3.0-2.4.1</ProductID>
            <ProductID>P-13390V-2.6.2</ProductID>
            <ProductID>P-13390V-2.7.1</ProductID>
            <ProductID>P-13390V-2.10.0</ProductID>
            <ProductID>P-13390V-2.12.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Enterprise Default Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2827842.1</URL>
            <ProductID>P-13390V-2.3.0-2.4.1</ProductID>
            <ProductID>P-13390V-2.6.2</ProductID>
            <ProductID>P-13390V-2.7.1</ProductID>
            <ProductID>P-13390V-2.10.0</ProductID>
            <ProductID>P-13390V-2.12.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="203" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29425</Title>
      <Notes>
         <Note Audience="All" Ordinal="203" Title="Details" Type="Details">Vulnerability in the Oracle Banking Party Management product of Oracle Financial Services Applications (component: Web UI (Apache Commons IO)).   The supported version that is affected is 2.7.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Party Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Banking Party Management accessible data as well as  unauthorized read access to a subset of Oracle Banking Party Management accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29425</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13929V-2.7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Party Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2827842.1</URL>
            <ProductID>P-13929V-2.7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="204" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29425</Title>
      <Notes>
         <Note Audience="All" Ordinal="204" Title="Details" Type="Details">Vulnerability in the Oracle Banking Platform product of Oracle Financial Services Applications (component: Security (Apache Commons IO)).  Supported versions that are affected are 2.3.0-2.4.1, 2.6.2 and  2.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Platform.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Banking Platform accessible data as well as  unauthorized read access to a subset of Oracle Banking Platform accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29425</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9178V-2.3.0-2.4.1</ProductID>
            <ProductID>P-9178V-2.6.2</ProductID>
            <ProductID>P-9178V-2.7.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Platform</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2827842.1</URL>
            <ProductID>P-9178V-2.3.0-2.4.1</ProductID>
            <ProductID>P-9178V-2.6.2</ProductID>
            <ProductID>P-9178V-2.7.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="205" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29425</Title>
      <Notes>
         <Note Audience="All" Ordinal="205" Title="Details" Type="Details">Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (Apache Commons IO)).   The supported version that is affected is 11.3.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Commerce Guided Search accessible data as well as  unauthorized read access to a subset of Oracle Commerce Guided Search accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29425</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9633V-11.3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Commerce Guided Search / Oracle Commerce Experience Manager</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832419.1</URL>
            <ProductID>P-9633V-11.3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="206" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29425</Title>
      <Notes>
         <Note Audience="All" Ordinal="206" Title="Details" Type="Details">Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications Applications (component: Charging Controller (Apache Commons IO)).   The supported version that is affected is 12.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications BRM - Elastic Charging Engine accessible data as well as  unauthorized read access to a subset of Oracle Communications BRM - Elastic Charging Engine accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29425</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9742V-12.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications BRM - Elastic Charging Engine</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831903.1</URL>
            <ProductID>P-9742V-12.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="207" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29425</Title>
      <Notes>
         <Note Audience="All" Ordinal="207" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: NRF (Apache Commons IO)).   The supported version that is affected is 1.14.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Network Repository Function accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Network Repository Function accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29425</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14118V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Network Repository Function</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833598.1</URL>
            <ProductID>P-14118V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="208" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29425</Title>
      <Notes>
         <Note Audience="All" Ordinal="208" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: UDR (Apache Commons IO)).   The supported version that is affected is 1.14.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Unified Data Repository accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Unified Data Repository accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29425</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14119V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Unified Data Repository</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833596.1</URL>
            <ProductID>P-14119V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="209" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29425</Title>
      <Notes>
         <Note Audience="All" Ordinal="209" Title="Details" Type="Details">Vulnerability in the Oracle Communications Convergence product of Oracle Communications Applications (component: Convergence Server (Apache Commons IO)).   The supported version that is affected is 3.0.2.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Convergence.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Convergence accessible data as well as  unauthorized read access to a subset of Oracle Communications Convergence accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29425</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8501V-3.0.2.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Convergence</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831902.1</URL>
            <ProductID>P-8501V-3.0.2.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="210" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29425</Title>
      <Notes>
         <Note Audience="All" Ordinal="210" Title="Details" Type="Details">Vulnerability in the Oracle Communications Offline Mediation Controller product of Oracle Communications Applications (component: Installation (Apache Commons IO)).   The supported version that is affected is 12.0.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Offline Mediation Controller.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Offline Mediation Controller accessible data as well as  unauthorized read access to a subset of Oracle Communications Offline Mediation Controller accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29425</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2269V-12.0.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Offline Mediation Controller</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831903.1</URL>
            <ProductID>P-2269V-12.0.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="211" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29425</Title>
      <Notes>
         <Note Audience="All" Ordinal="211" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Others (Apache Commons IO)).  Supported versions that are affected are 8.0.7-8.1.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Analytical Applications Infrastructure accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29425</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5680V-8.0.7-8.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Financial Services Analytical Applications Infrastructure</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2825591.1</URL>
            <ProductID>P-5680V-8.0.7-8.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="212" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29425</Title>
      <Notes>
         <Note Audience="All" Ordinal="212" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer &amp; Configuration (Apache Commons IO)).  Supported versions that are affected are 8.0.8, 8.1.0 and  8.1.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Model Management and Governance.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Model Management and Governance accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Model Management and Governance accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29425</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14276V-8.0.8</ProductID>
            <ProductID>P-14276V-8.1.0</ProductID>
            <ProductID>P-14276V-8.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Financial Services Model Management and Governance</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2825611.1</URL>
            <ProductID>P-14276V-8.0.8</ProductID>
            <ProductID>P-14276V-8.1.0</ProductID>
            <ProductID>P-14276V-8.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="213" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29425</Title>
      <Notes>
         <Note Audience="All" Ordinal="213" Title="Details" Type="Details">Vulnerability in the Oracle Fusion Middleware MapViewer product of Oracle Fusion Middleware (component: Install (Apache Commons IO)).   The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Fusion Middleware MapViewer.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Fusion Middleware MapViewer accessible data as well as  unauthorized read access to a subset of Oracle Fusion Middleware MapViewer accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29425</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1215V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Fusion Middleware MapViewer</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-1215V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="214" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29425</Title>
      <Notes>
         <Note Audience="All" Ordinal="214" Title="Details" Type="Details">Security-in-Depth issue in Oracle Graph Server and Client (component: Packaging/Install (Apache Commons IO)). This vulnerability cannot be exploited in the context of this product.</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29425</CVE>
      <ProductStatuses>
         <Status Type="Known Not Affected">
            <ProductID>P-14069V-All Supported Versions</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Graph Server and Client</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-14069V-All Supported Versions</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="215" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29425</Title>
      <Notes>
         <Note Audience="All" Ordinal="215" Title="Details" Type="Details">Vulnerability in the OSS Support Tools product of Oracle Support Tools (component: Diagnostic Assistant  (Apache Commons IO)).   The supported version that is affected is Prior to 2.12.42. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise OSS Support Tools.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of OSS Support Tools accessible data as well as  unauthorized read access to a subset of OSS Support Tools accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29425</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1330V-Prior to 2.12.42</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>OSS Support Tools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833277.1</URL>
            <ProductID>P-1330V-Prior to 2.12.42</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="216" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29425</Title>
      <Notes>
         <Note Audience="All" Ordinal="216" Title="Details" Type="Details">Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform (Apache Commons IO)).  Supported versions that are affected are 17.7-17.12, 18.8, 19.12, 20.12 and  21.12. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera Unifier accessible data as well as  unauthorized read access to a subset of Primavera Unifier accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29425</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10354V-17.7-17.12</ProductID>
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
            <ProductID>P-10354V-20.12</ProductID>
            <ProductID>P-10354V-21.12</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera Unifier</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2829871.1</URL>
            <ProductID>P-10354V-17.7-17.12</ProductID>
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
            <ProductID>P-10354V-20.12</ProductID>
            <ProductID>P-10354V-21.12</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="217" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29425</Title>
      <Notes>
         <Note Audience="All" Ordinal="217" Title="Details" Type="Details">Vulnerability in the Oracle Retail Assortment Planning product of Oracle Retail Applications (component: Application Core (Apache Commons IO)).   The supported version that is affected is 16.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Assortment Planning.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Retail Assortment Planning accessible data as well as  unauthorized read access to a subset of Oracle Retail Assortment Planning accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29425</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1788V-16.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Assortment Planning</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-1788V-16.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="218" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29425</Title>
      <Notes>
         <Note Audience="All" Ordinal="218" Title="Details" Type="Details">Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Apache Commons IO)).  Supported versions that are affected are 14.1.3.2, 15.0.3.1, 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Retail Integration Bus accessible data as well as  unauthorized read access to a subset of Oracle Retail Integration Bus accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29425</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1807V-14.1.3.2</ProductID>
            <ProductID>P-1807V-15.0.3.1</ProductID>
            <ProductID>P-1807V-16.0.3</ProductID>
            <ProductID>P-1807V-19.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Integration Bus</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-1807V-14.1.3.2</ProductID>
            <ProductID>P-1807V-15.0.3.1</ProductID>
            <ProductID>P-1807V-16.0.3</ProductID>
            <ProductID>P-1807V-19.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="219" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29425</Title>
      <Notes>
         <Note Audience="All" Ordinal="219" Title="Details" Type="Details">Vulnerability in the Oracle Retail Order Broker product of Oracle Retail Applications (component: System Administration (Apache Commons IO)).  Supported versions that are affected are 16.0, 18.0 and  19.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Order Broker.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Retail Order Broker accessible data as well as  unauthorized read access to a subset of Oracle Retail Order Broker accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29425</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11520V-16.0</ProductID>
            <ProductID>P-11520V-18.0</ProductID>
            <ProductID>P-11520V-19.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Order Broker Cloud Service</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-11520V-16.0</ProductID>
            <ProductID>P-11520V-18.0</ProductID>
            <ProductID>P-11520V-19.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="220" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29425</Title>
      <Notes>
         <Note Audience="All" Ordinal="220" Title="Details" Type="Details">Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (Apache Commons IO)).  Supported versions that are affected are 15.0.3.1, 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Retail Service Backbone accessible data as well as  unauthorized read access to a subset of Oracle Retail Service Backbone accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29425</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10867V-15.0.3.1</ProductID>
            <ProductID>P-10867V-16.0.3</ProductID>
            <ProductID>P-10867V-19.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Service Backbone</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-10867V-15.0.3.1</ProductID>
            <ProductID>P-10867V-16.0.3</ProductID>
            <ProductID>P-10867V-19.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="221" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29425</Title>
      <Notes>
         <Note Audience="All" Ordinal="221" Title="Details" Type="Details">Vulnerability in the Oracle Retail Size Profile Optimization product of Oracle Retail Applications (component: Application Core (Apache Commons IO)).   The supported version that is affected is 16.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Size Profile Optimization.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Retail Size Profile Optimization accessible data as well as  unauthorized read access to a subset of Oracle Retail Size Profile Optimization accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29425</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4670V-16.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Size Profile Optimization</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-4670V-16.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="222" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29425</Title>
      <Notes>
         <Note Audience="All" Ordinal="222" Title="Details" Type="Details">Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Apache Commons IO)).   The supported version that is affected is 6.0.0.1.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Utilities Testing Accelerator accessible data as well as  unauthorized read access to a subset of Oracle Utilities Testing Accelerator accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29425</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13784V-6.0.0.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Utilities Testing Accelerator</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832617.1</URL>
            <ProductID>P-13784V-6.0.0.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="223" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29425</Title>
      <Notes>
         <Note Audience="All" Ordinal="223" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Third Party Tools (Apache Commons IO)).  Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as  unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29425</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="224" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29505</Title>
      <Notes>
         <Note Audience="All" Ordinal="224" Title="Details" Type="Details">Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Rulesets (XStream)).  Supported versions that are affected are 7.3.4, 7.3.5, 7.4.0, 7.4.1 and  7.4.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29505</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4516V-7.3.4</ProductID>
            <ProductID>P-4516V-7.3.5</ProductID>
            <ProductID>P-4516V-7.4.0</ProductID>
            <ProductID>P-4516V-7.4.1</ProductID>
            <ProductID>P-4516V-7.4.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Unified Inventory Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831889.1</URL>
            <ProductID>P-4516V-7.3.4</ProductID>
            <ProductID>P-4516V-7.3.5</ProductID>
            <ProductID>P-4516V-7.4.0</ProductID>
            <ProductID>P-4516V-7.4.1</ProductID>
            <ProductID>P-4516V-7.4.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="225" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29921</Title>
      <Notes>
         <Note Audience="All" Ordinal="225" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: ATS Framework (Python)).   The supported version that is affected is 1.8.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Automated Test Suite accessible data. CVSS 3.1 Base Score 4.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29921</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14488V-1.8.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Automated Test Suite</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833620.1</URL>
            <ProductID>P-14488V-1.8.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="226" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29923</Title>
      <Notes>
         <Note Audience="All" Ordinal="226" Title="Details" Type="Details">Vulnerability in Oracle TimesTen In-Memory Database (component: EM TimesTen plug-in (Go)).   The supported version that is affected is Prior to 21.1.1.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP/IP to compromise Oracle TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle TimesTen In-Memory Database accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29923</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1870V-Prior to 21.1.1.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>TimesTen In-Memory Database</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-1870V-Prior to 21.1.1.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="227" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29923</Title>
      <Notes>
         <Note Audience="All" Ordinal="227" Title="Details" Type="Details">Vulnerability in Oracle TimesTen In-Memory Database (component: Install (Go)).   The supported version that is affected is Prior to 21.1.1.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP/IP to compromise Oracle TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle TimesTen In-Memory Database accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29923</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1870V-Prior to 21.1.1.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>TimesTen In-Memory Database</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-1870V-Prior to 21.1.1.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="228" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-30639</Title>
      <Notes>
         <Note Audience="All" Ordinal="228" Title="Details" Type="Details">Vulnerability in the Big Data Spatial and Graph product of Oracle Big Data Graph (component: Big Data Graph (Apache Tomcat)).   The supported version that is affected is Prior to 23.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Big Data Spatial and Graph.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Big Data Spatial and Graph accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-30639</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11528V-Prior to 23.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Big Data Spatial and Graph</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-11528V-Prior to 23.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="229" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-3177</Title>
      <Notes>
         <Note Audience="All" Ordinal="229" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Ops Center product of Oracle Enterprise Manager (component: Networking  (Python)).   The supported version that is affected is 12.4.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Ops Center.  Successful attacks of this vulnerability can result in takeover of Enterprise Manager Ops Center. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-3177</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9835V-12.4.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Enterprise Manager Ops Center</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-9835V-12.4.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="230" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-31812</Title>
      <Notes>
         <Note Audience="All" Ordinal="230" Title="Details" Type="Details">Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Security (Apache PDFbox)).   The supported version that is affected is 18.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Retail Customer Management and Segmentation Foundation executes to compromise Oracle Retail Customer Management and Segmentation Foundation.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Customer Management and Segmentation Foundation. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-31812</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13388V-18.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Customer Management and Segmentation Foundation</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-13388V-18.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="231" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-32014</Title>
      <Notes>
         <Note Audience="All" Ordinal="231" Title="Details" Type="Details">Vulnerability in Oracle REST Data Services (component: General (SheetJS)).   The supported version that is affected is Prior to 21.2.4. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle REST Data Services executes to compromise Oracle REST Data Services.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle REST Data Services. CVSS 3.1 Base Score 3.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-32014</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9456V-Prior to 21.2.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.3</BaseScore>
            <Vector>AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>REST Data Services</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-9456V-Prior to 21.2.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="232" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-32723</Title>
      <Notes>
         <Note Audience="All" Ordinal="232" Title="Details" Type="Details">Vulnerability in the Oracle Application Express (Prism) component of Oracle Database Server.   The supported version that is affected is Prior to 21.1.4. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express (Prism).  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Application Express (Prism). CVSS 3.1 Base Score 3.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-32723</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1348V-Prior to 21.1.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Application Express (APEX)</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-1348V-Prior to 21.1.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="233" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-32827</Title>
      <Notes>
         <Note Audience="All" Ordinal="233" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (MockServer)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Cloud Native Core Policy, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-32827</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14277V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Policy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833602.1</URL>
            <ProductID>P-14277V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="234" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-33037</Title>
      <Notes>
         <Note Audience="All" Ordinal="234" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security (Apache Tomcat)).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-33037</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Agile PLM Framework</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832006.1</URL>
            <ProductID>P-4461V-9.3.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="235" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-33037</Title>
      <Notes>
         <Note Audience="All" Ordinal="235" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: SCP (Apache Tomcat)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Service Communication Proxy accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-33037</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14117V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Service Communication Proxy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833601.1</URL>
            <ProductID>P-14117V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="236" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-33037</Title>
      <Notes>
         <Note Audience="All" Ordinal="236" Title="Details" Type="Details">Vulnerability in Oracle Graph Server and Client (component: Packaging/Install (Apache Tomcat)).   The supported version that is affected is Prior to 21.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Graph Server and Client.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Graph Server and Client accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-33037</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14069V-Prior to 21.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Graph Server and Client</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-14069V-Prior to 21.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="237" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-33037</Title>
      <Notes>
         <Note Audience="All" Ordinal="237" Title="Details" Type="Details">Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Apache Tomcat)).  Supported versions that are affected are 6.0.0.1.1, 6.0.0.2.2 and  6.0.0.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Utilities Testing Accelerator accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-33037</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13784V-6.0.0.1.1</ProductID>
            <ProductID>P-13784V-6.0.0.2.2</ProductID>
            <ProductID>P-13784V-6.0.0.3.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Utilities Testing Accelerator</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832617.1</URL>
            <ProductID>P-13784V-6.0.0.1.1</ProductID>
            <ProductID>P-13784V-6.0.0.2.2</ProductID>
            <ProductID>P-13784V-6.0.0.3.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="238" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-3326</Title>
      <Notes>
         <Note Audience="All" Ordinal="238" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (glibc)).   The supported version that is affected is 1.5.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-3326</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14123V-1.5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Security Edge Protection Proxy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833594.1</URL>
            <ProductID>P-14123V-1.5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="239" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-3326</Title>
      <Notes>
         <Note Audience="All" Ordinal="239" Title="Details" Type="Details">Vulnerability in the Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers product of Oracle Systems (component: XCP Firmware (glibc)).  Supported versions that are affected are Prior to XCP2410 and  prior to XCP3110. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-3326</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10656V-Prior to XCP2410</ProductID>
            <ProductID>P-10656V-prior to XCP3110</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Fujitsu SPARC Servers Firmware</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832878.1</URL>
            <ProductID>P-10656V-Prior to XCP2410</ProductID>
            <ProductID>P-10656V-prior to XCP3110</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="240" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-33560</Title>
      <Notes>
         <Note Audience="All" Ordinal="240" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: Configuration (libgcrypt)).   The supported version that is affected is 1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Function Cloud Native Environment accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-33560</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14125V-1.9.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Network Function Cloud Native Environment</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833600.1</URL>
            <ProductID>P-14125V-1.9.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="241" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-33880</Title>
      <Notes>
         <Note Audience="All" Ordinal="241" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (aaugustin websockets)).   The supported version that is affected is 1.5.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-33880</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14123V-1.5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Security Edge Protection Proxy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833594.1</URL>
            <ProductID>P-14123V-1.5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="242" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-33880</Title>
      <Notes>
         <Note Audience="All" Ordinal="242" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: SCP (aaugustin websockets)).   The supported version that is affected is 1.14.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Service Communication Proxy accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-33880</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14117V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Service Communication Proxy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833601.1</URL>
            <ProductID>P-14117V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="243" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-33880</Title>
      <Notes>
         <Note Audience="All" Ordinal="243" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: UDR (aaugustin websockets)).   The supported version that is affected is 1.14.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Unified Data Repository accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-33880</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14119V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Unified Data Repository</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833596.1</URL>
            <ProductID>P-14119V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="244" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-33909</Title>
      <Notes>
         <Note Audience="All" Ordinal="244" Title="Details" Type="Details">Vulnerability in the Oracle Communications Session Border Controller product of Oracle Communications (component: Core (Kernel)).  Supported versions that are affected are 8.2, 8.3, 8.4 and  9.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Session Border Controller executes to compromise Oracle Communications Session Border Controller.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Session Border Controller. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-33909</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10750V-8.2</ProductID>
            <ProductID>P-10750V-8.3</ProductID>
            <ProductID>P-10750V-8.4</ProductID>
            <ProductID>P-10750V-9.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Session Border Controller</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833085.1</URL>
            <ProductID>P-10750V-8.2</ProductID>
            <ProductID>P-10750V-8.3</ProductID>
            <ProductID>P-10750V-8.4</ProductID>
            <ProductID>P-10750V-9.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="245" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-3426</Title>
      <Notes>
         <Note Audience="All" Ordinal="245" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Binding Support Function (Python)).   The supported version that is affected is 1.10.0. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Communications Cloud Native Core Binding Support Function executes to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Binding Support Function accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-3426</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14121V-1.10.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.7</BaseScore>
            <Vector>AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Binding Support Function</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833618.1</URL>
            <ProductID>P-14121V-1.10.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="246" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-34429</Title>
      <Notes>
         <Note Audience="All" Ordinal="246" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Binding Support Function (Eclipse Jetty)).   The supported version that is affected is 1.10.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Cloud Native Core Binding Support Function accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-34429</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14121V-1.10.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Binding Support Function</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833618.1</URL>
            <ProductID>P-14121V-1.10.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="247" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-34429</Title>
      <Notes>
         <Note Audience="All" Ordinal="247" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (Eclipse Jetty)).   The supported version that is affected is 1.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-34429</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14123V-1.5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Security Edge Protection Proxy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833594.1</URL>
            <ProductID>P-14123V-1.5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="248" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-34429</Title>
      <Notes>
         <Note Audience="All" Ordinal="248" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: SCP (Eclipse Jetty)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Cloud Native Core Service Communication Proxy accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-34429</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14117V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Service Communication Proxy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833601.1</URL>
            <ProductID>P-14117V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="249" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-34429</Title>
      <Notes>
         <Note Audience="All" Ordinal="249" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: UDR (Eclipse Jetty)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Cloud Native Core Unified Data Repository accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-34429</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14119V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Unified Data Repository</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833596.1</URL>
            <ProductID>P-14119V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="250" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-34429</Title>
      <Notes>
         <Note Audience="All" Ordinal="250" Title="Details" Type="Details">Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: API Gateway (Eclipse Jetty)).  Supported versions that are affected are 8.0.0.0-8.5.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Diameter Signaling Router accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-34429</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10899V-8.0.0.0-8.5.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Diameter Signaling Router (DSR)</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833215.1</URL>
            <ProductID>P-10899V-8.0.0.0-8.5.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="251" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-3448</Title>
      <Notes>
         <Note Audience="All" Ordinal="251" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: Configuration (dnsmasq)).   The supported version that is affected is 1.9.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment.  While the vulnerability is in Oracle Communications Cloud Native Core Network Function Cloud Native Environment, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Network Function Cloud Native Environment accessible data. CVSS 3.1 Base Score 4.0 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-3448</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14125V-1.9.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.0</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Network Function Cloud Native Environment</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833600.1</URL>
            <ProductID>P-14125V-1.9.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="252" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-35043</Title>
      <Notes>
         <Note Audience="All" Ordinal="252" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security  (AntiSamy)).   The supported version that is affected is 9.3.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data as well as  unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-35043</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Agile PLM Framework</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832006.1</URL>
            <ProductID>P-4461V-9.3.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="253" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-35043</Title>
      <Notes>
         <Note Audience="All" Ordinal="253" Title="Details" Type="Details">Vulnerability in the Oracle Banking Enterprise Default Management product of Oracle Financial Services Applications (component: Collections (AntiSamy)).   The supported version that is affected is 2.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Enterprise Default Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Enterprise Default Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Banking Enterprise Default Management accessible data as well as  unauthorized read access to a subset of Oracle Banking Enterprise Default Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-35043</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13390V-2.7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Enterprise Default Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2827842.1</URL>
            <ProductID>P-13390V-2.7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="254" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-35043</Title>
      <Notes>
         <Note Audience="All" Ordinal="254" Title="Details" Type="Details">Vulnerability in the Oracle Banking Party Management product of Oracle Financial Services Applications (component: Web UI (AntiSamy)).   The supported version that is affected is 2.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Party Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Party Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Banking Party Management accessible data as well as  unauthorized read access to a subset of Oracle Banking Party Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-35043</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13929V-2.7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Party Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2827842.1</URL>
            <ProductID>P-13929V-2.7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="255" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-35043</Title>
      <Notes>
         <Note Audience="All" Ordinal="255" Title="Details" Type="Details">Vulnerability in the Oracle Banking Platform product of Oracle Financial Services Applications (component: SECURITY (AntiSamy)).   The supported version that is affected is 2.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Platform.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Banking Platform accessible data as well as  unauthorized read access to a subset of Oracle Banking Platform accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-35043</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9178V-2.7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Platform</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2827842.1</URL>
            <ProductID>P-9178V-2.7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="256" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-3517</Title>
      <Notes>
         <Note Audience="All" Ordinal="256" Title="Details" Type="Details">Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Operating System Image).   The supported version that is affected is 8.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle ZFS Storage Appliance Kit.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle ZFS Storage Appliance Kit as well as  unauthorized update, insert or delete access to some of Oracle ZFS Storage Appliance Kit accessible data and  unauthorized read access to a subset of Oracle ZFS Storage Appliance Kit accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-3517</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10026V-8.8</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Sun ZFS Storage Appliance Kit (AK) Software</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832878.1</URL>
            <ProductID>P-10026V-8.8</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="257" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-35587</Title>
      <Notes>
         <Note Audience="All" Ordinal="257" Title="Details" Type="Details">Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent).  Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-35587</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5565V-11.1.2.3.0</ProductID>
            <ProductID>P-5565V-12.2.1.3.0</ProductID>
            <ProductID>P-5565V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Access Manager</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5565V-11.1.2.3.0</ProductID>
            <ProductID>P-5565V-12.2.1.3.0</ProductID>
            <ProductID>P-5565V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="258" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-35683</Title>
      <Notes>
         <Note Audience="All" Ordinal="258" Title="Details" Type="Details">Vulnerability in the Oracle Essbase Administration Services product of Oracle Essbase (component: EAS Console).   The supported version that is affected is Prior to 11.1.2.4.047. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Essbase Administration Services.  While the vulnerability is in Oracle Essbase Administration Services, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Essbase Administration Services. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-35683</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4380V-Prior to 11.1.2.4.047</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.9</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Hyperion Essbase Administration Services</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-4380V-Prior to 11.1.2.4.047</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="259" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-35686</Title>
      <Notes>
         <Note Audience="All" Ordinal="259" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Unified Metadata Manager).  Supported versions that are affected are 8.0.7-8.1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-35686</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5680V-8.0.7-8.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Financial Services Analytical Applications Infrastructure</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2825591.1</URL>
            <ProductID>P-5680V-8.0.7-8.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="260" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-35687</Title>
      <Notes>
         <Note Audience="All" Ordinal="260" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Unified Metadata Manager).  Supported versions that are affected are 8.0.7-8.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-35687</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5680V-8.0.7-8.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Financial Services Analytical Applications Infrastructure</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2825591.1</URL>
            <ProductID>P-5680V-8.0.7-8.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="261" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-36090</Title>
      <Notes>
         <Note Audience="All" Ordinal="261" Title="Details" Type="Details">Vulnerability in the Oracle Banking APIs product of Oracle Financial Services Applications (component: Framework (Apache Commons Compress)).  Supported versions that are affected are 18.1-18.3, 19.1, 19.2, 20.1 and  21.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking APIs.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking APIs. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-36090</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13676V-18.1-18.3</ProductID>
            <ProductID>P-13676V-19.1</ProductID>
            <ProductID>P-13676V-19.2</ProductID>
            <ProductID>P-13676V-20.1</ProductID>
            <ProductID>P-13676V-21.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking APIs</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-13676V-18.1-18.3</ProductID>
            <ProductID>P-13676V-19.1</ProductID>
            <ProductID>P-13676V-19.2</ProductID>
            <ProductID>P-13676V-20.1</ProductID>
            <ProductID>P-13676V-21.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="262" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-36090</Title>
      <Notes>
         <Note Audience="All" Ordinal="262" Title="Details" Type="Details">Vulnerability in the Oracle Banking Digital Experience product of Oracle Financial Services Applications (component: Framework (Apache Commons Compress)).  Supported versions that are affected are 18.1-18.3, 19.1, 19.2, 20.1 and  21.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Digital Experience.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Digital Experience. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-36090</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12605V-18.1-18.3</ProductID>
            <ProductID>P-12605V-19.1</ProductID>
            <ProductID>P-12605V-19.2</ProductID>
            <ProductID>P-12605V-20.1</ProductID>
            <ProductID>P-12605V-21.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Digital Experience</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-12605V-18.1-18.3</ProductID>
            <ProductID>P-12605V-19.1</ProductID>
            <ProductID>P-12605V-19.2</ProductID>
            <ProductID>P-12605V-20.1</ProductID>
            <ProductID>P-12605V-21.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="263" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-36090</Title>
      <Notes>
         <Note Audience="All" Ordinal="263" Title="Details" Type="Details">Vulnerability in the Oracle Banking Enterprise Default Management product of Oracle Financial Services Applications (component: Collections (Apache Commons Compress)).   The supported version that is affected is 2.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Enterprise Default Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Enterprise Default Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-36090</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13390V-2.7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Enterprise Default Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2827842.1</URL>
            <ProductID>P-13390V-2.7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="264" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-36090</Title>
      <Notes>
         <Note Audience="All" Ordinal="264" Title="Details" Type="Details">Vulnerability in the Oracle Banking Party Management product of Oracle Financial Services Applications (component: Web UI (Apache Commons Compress)).   The supported version that is affected is 2.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Party Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Party Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-36090</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13929V-2.7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Party Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2827842.1</URL>
            <ProductID>P-13929V-2.7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="265" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-36090</Title>
      <Notes>
         <Note Audience="All" Ordinal="265" Title="Details" Type="Details">Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Installer (Apache Commons Compress)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Process Management Suite. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-36090</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5325V-12.2.1.3.0</ProductID>
            <ProductID>P-5325V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Business Process Management Suite</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5325V-12.2.1.3.0</ProductID>
            <ProductID>P-5325V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="266" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-36090</Title>
      <Notes>
         <Note Audience="All" Ordinal="266" Title="Details" Type="Details">Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (Apache Commons Compress)).   The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-36090</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9633V-11.3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Commerce Guided Search / Oracle Commerce Experience Manager</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832419.1</URL>
            <ProductID>P-9633V-11.3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="267" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-36090</Title>
      <Notes>
         <Note Audience="All" Ordinal="267" Title="Details" Type="Details">Security-in-Depth issue in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: NRF (Apache Commons Compress)). This vulnerability cannot be exploited in the context of this product.</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-36090</CVE>
      <ProductStatuses>
         <Status Type="Known Not Affected">
            <ProductID>P-14118V-All Supported Versions</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Network Repository Function</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833598.1</URL>
            <ProductID>P-14118V-All Supported Versions</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="268" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-36090</Title>
      <Notes>
         <Note Audience="All" Ordinal="268" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: SCP (Apache Commons Compress)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-36090</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14117V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Service Communication Proxy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833601.1</URL>
            <ProductID>P-14117V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="269" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-36090</Title>
      <Notes>
         <Note Audience="All" Ordinal="269" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: UDR (Apache Commons Compress)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-36090</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14119V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Unified Data Repository</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833596.1</URL>
            <ProductID>P-14119V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="270" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-36090</Title>
      <Notes>
         <Note Audience="All" Ordinal="270" Title="Details" Type="Details">Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Inventory Organizer (Apache Commons Compress)).  Supported versions that are affected are 7.4.0, 7.4.1, 7.4.2 and  7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-36090</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4516V-7.4.0</ProductID>
            <ProductID>P-4516V-7.4.1</ProductID>
            <ProductID>P-4516V-7.4.2</ProductID>
            <ProductID>P-4516V-7.5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Unified Inventory Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831889.1</URL>
            <ProductID>P-4516V-7.4.0</ProductID>
            <ProductID>P-4516V-7.4.1</ProductID>
            <ProductID>P-4516V-7.4.2</ProductID>
            <ProductID>P-4516V-7.5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="271" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-36090</Title>
      <Notes>
         <Note Audience="All" Ordinal="271" Title="Details" Type="Details">Security-in-Depth issue in the Oracle Database Configuration Assistant (Apache Commons Compress) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-36090</CVE>
      <ProductStatuses>
         <Status Type="Known Not Affected">
            <ProductID>P-383V-All Supported Versions</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Database Configuration Assistant</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-383V-All Supported Versions</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="272" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-36090</Title>
      <Notes>
         <Note Audience="All" Ordinal="272" Title="Details" Type="Details">Security-in-Depth issue in Oracle Essbase (component: Infrastructure  (Apache Commons Compress)). This vulnerability cannot be exploited in the context of this product.</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-36090</CVE>
      <ProductStatuses>
         <Status Type="Known Not Affected">
            <ProductID>P-4379V-All Supported Versions</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Hyperion Essbase</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-4379V-All Supported Versions</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="273" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-36090</Title>
      <Notes>
         <Note Audience="All" Ordinal="273" Title="Details" Type="Details">Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Apache Commons Compress)).  Supported versions that are affected are 6.0.0.1.1, 6.0.0.2.2 and  6.0.0.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Testing Accelerator. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-36090</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13784V-6.0.0.1.1</ProductID>
            <ProductID>P-13784V-6.0.0.2.2</ProductID>
            <ProductID>P-13784V-6.0.0.3.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Utilities Testing Accelerator</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832617.1</URL>
            <ProductID>P-13784V-6.0.0.1.1</ProductID>
            <ProductID>P-13784V-6.0.0.2.2</ProductID>
            <ProductID>P-13784V-6.0.0.3.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="274" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-3634</Title>
      <Notes>
         <Note Audience="All" Ordinal="274" Title="Details" Type="Details">Vulnerability in the MySQL Workbench product of Oracle MySQL (component: Workbench: libssh).  Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via MySQL Workbench to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Workbench. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-3634</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4627V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Workbench</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-4627V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="275" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-36374</Title>
      <Notes>
         <Note Audience="All" Ordinal="275" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security (Apache Ant)).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Agile PLM executes to compromise Oracle Agile PLM.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile PLM. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-36374</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Agile PLM Framework</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832006.1</URL>
            <ProductID>P-4461V-9.3.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="276" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-36374</Title>
      <Notes>
         <Note Audience="All" Ordinal="276" Title="Details" Type="Details">Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Build Tool (Apache Ant)).  Supported versions that are affected are 7.3.0, 7.4.0, 7.4.1, 7.4.2 and  7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Unified Inventory Management executes to compromise Oracle Communications Unified Inventory Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-36374</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4516V-7.3.0</ProductID>
            <ProductID>P-4516V-7.4.0</ProductID>
            <ProductID>P-4516V-7.4.1</ProductID>
            <ProductID>P-4516V-7.4.2</ProductID>
            <ProductID>P-4516V-7.5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Unified Inventory Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831889.1</URL>
            <ProductID>P-4516V-7.3.0</ProductID>
            <ProductID>P-4516V-7.4.0</ProductID>
            <ProductID>P-4516V-7.4.1</ProductID>
            <ProductID>P-4516V-7.4.2</ProductID>
            <ProductID>P-4516V-7.5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="277" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-36374</Title>
      <Notes>
         <Note Audience="All" Ordinal="277" Title="Details" Type="Details">Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Apache Ant)).   The supported version that is affected is 6.0.0.1.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Utilities Testing Accelerator executes to compromise Oracle Utilities Testing Accelerator.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Testing Accelerator. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-36374</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13784V-6.0.0.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Utilities Testing Accelerator</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832617.1</URL>
            <ProductID>P-13784V-6.0.0.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="278" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-3711</Title>
      <Notes>
         <Note Audience="All" Ordinal="278" Title="Details" Type="Details">Vulnerability in Oracle Essbase (component: Infrastructure  (OpenSSL)).  Supported versions that are affected are Prior to 11.1.2.4.047 and  Prior to 21.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Essbase.  Successful attacks of this vulnerability can result in takeover of Oracle Essbase. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-3711</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4379V-Prior to 11.1.2.4.047</ProductID>
            <ProductID>P-4379V-Prior to 21.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Hyperion Essbase</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-4379V-Prior to 11.1.2.4.047</ProductID>
            <ProductID>P-4379V-Prior to 21.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="279" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-3712</Title>
      <Notes>
         <Note Audience="All" Ordinal="279" Title="Details" Type="Details">Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++ (OpenSSL)).  Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all MySQL Connectors accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 7.4 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-3712</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8576V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.4</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Connectors</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8576V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="280" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-3712</Title>
      <Notes>
         <Note Audience="All" Ordinal="280" Title="Details" Type="Details">Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC (OpenSSL)).  Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all MySQL Connectors accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 7.4 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-3712</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8576V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.4</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Connectors</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8576V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="281" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-3712</Title>
      <Notes>
         <Note Audience="All" Ordinal="281" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security (OpenSSL)).  Supported versions that are affected are 8.57, 8.58 and  8.59. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.4 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-3712</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.4</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>PeopleSoft Enterprise PT PeopleTools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831970.1</URL>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="282" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-3712</Title>
      <Notes>
         <Note Audience="All" Ordinal="282" Title="Details" Type="Details">Vulnerability in Oracle Secure Backup (component: Oracle Secure Backup (OpenSSL)).   The supported version that is affected is Prior to 18.1.0.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Secure Backup.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Secure Backup accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Secure Backup. CVSS 3.1 Base Score 7.4 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-3712</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1522V-Prior to 18.1.0.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.4</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Secure Backup</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-1522V-Prior to 18.1.0.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="283" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-37137</Title>
      <Notes>
         <Note Audience="All" Ordinal="283" Title="Details" Type="Details">Vulnerability in the Oracle Banking APIs product of Oracle Financial Services Applications (component: Framework (Netty)).  Supported versions that are affected are 18.1-18.3, 19.1, 19.2, 20.1 and  21.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Banking APIs.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking APIs. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-37137</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13676V-18.1-18.3</ProductID>
            <ProductID>P-13676V-19.1</ProductID>
            <ProductID>P-13676V-19.2</ProductID>
            <ProductID>P-13676V-20.1</ProductID>
            <ProductID>P-13676V-21.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking APIs</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-13676V-18.1-18.3</ProductID>
            <ProductID>P-13676V-19.1</ProductID>
            <ProductID>P-13676V-19.2</ProductID>
            <ProductID>P-13676V-20.1</ProductID>
            <ProductID>P-13676V-21.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="284" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-37137</Title>
      <Notes>
         <Note Audience="All" Ordinal="284" Title="Details" Type="Details">Vulnerability in the Oracle Banking Digital Experience product of Oracle Financial Services Applications (component: Framework (Netty)).  Supported versions that are affected are 18.1-18.3, 19.1, 19.2, 20.1 and  21.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Banking Digital Experience.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Digital Experience. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-37137</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12605V-18.1-18.3</ProductID>
            <ProductID>P-12605V-19.1</ProductID>
            <ProductID>P-12605V-19.2</ProductID>
            <ProductID>P-12605V-20.1</ProductID>
            <ProductID>P-12605V-21.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Digital Experience</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-12605V-18.1-18.3</ProductID>
            <ProductID>P-12605V-19.1</ProductID>
            <ProductID>P-12605V-19.2</ProductID>
            <ProductID>P-12605V-20.1</ProductID>
            <ProductID>P-12605V-21.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="285" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-37137</Title>
      <Notes>
         <Note Audience="All" Ordinal="285" Title="Details" Type="Details">Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (Netty)).   The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-37137</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9633V-11.3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Commerce Guided Search / Oracle Commerce Experience Manager</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832419.1</URL>
            <ProductID>P-9633V-11.3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="286" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-37137</Title>
      <Notes>
         <Note Audience="All" Ordinal="286" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Binding Support Function (Netty)).   The supported version that is affected is 1.10.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-37137</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14121V-1.10.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Binding Support Function</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833618.1</URL>
            <ProductID>P-14121V-1.10.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="287" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-37137</Title>
      <Notes>
         <Note Audience="All" Ordinal="287" Title="Details" Type="Details">Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: API Gateway (Netty)).  Supported versions that are affected are 8.0.0.0-8.5.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-37137</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10899V-8.0.0.0-8.5.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Diameter Signaling Router (DSR)</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833215.1</URL>
            <ProductID>P-10899V-8.0.0.0-8.5.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="288" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-37137</Title>
      <Notes>
         <Note Audience="All" Ordinal="288" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search (Netty)).  Supported versions that are affected are 8.57, 8.58 and  8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-37137</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>PeopleSoft Enterprise PT PeopleTools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831970.1</URL>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="289" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-37695</Title>
      <Notes>
         <Note Audience="All" Ordinal="289" Title="Details" Type="Details">Vulnerability in the Oracle Application Express (CKEditor) component of Oracle Database Server.   The supported version that is affected is Prior to 21.1.4. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express (CKEditor).  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express (CKEditor), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Application Express (CKEditor) accessible data as well as  unauthorized read access to a subset of Oracle Application Express (CKEditor) accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-37695</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1348V-Prior to 21.1.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Application Express (APEX)</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-1348V-Prior to 21.1.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="290" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-37695</Title>
      <Notes>
         <Note Audience="All" Ordinal="290" Title="Details" Type="Details">Vulnerability in the Oracle Banking Party Management product of Oracle Financial Services Applications (component: Web UI (CKEditor)).   The supported version that is affected is 2.7.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Party Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Party Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Banking Party Management accessible data as well as  unauthorized read access to a subset of Oracle Banking Party Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-37695</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13929V-2.7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Party Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2827842.1</URL>
            <ProductID>P-13929V-2.7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="291" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-37695</Title>
      <Notes>
         <Note Audience="All" Ordinal="291" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Others (CKEditor)).  Supported versions that are affected are 8.0.7-8.1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Analytical Applications Infrastructure, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Analytical Applications Infrastructure accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-37695</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5680V-8.0.7-8.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Financial Services Analytical Applications Infrastructure</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2825591.1</URL>
            <ProductID>P-5680V-8.0.7-8.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="292" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-37695</Title>
      <Notes>
         <Note Audience="All" Ordinal="292" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Rich Text Editor (CKEditor)).  Supported versions that are affected are 8.57, 8.58 and  8.59. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-37695</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>PeopleSoft Enterprise PT PeopleTools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831970.1</URL>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="293" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-37714</Title>
      <Notes>
         <Note Audience="All" Ordinal="293" Title="Details" Type="Details">Vulnerability in the Oracle Communications Messaging Server product of Oracle Communications Applications (component: ISC (jsoup)).   The supported version that is affected is 8.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Messaging Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Messaging Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-37714</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8496V-8.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Messaging Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831902.1</URL>
            <ProductID>P-8496V-8.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="294" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-37714</Title>
      <Notes>
         <Note Audience="All" Ordinal="294" Title="Details" Type="Details">Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform,Data Parsing (jsoup)).  Supported versions that are affected are 20.12 and  21.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Primavera Unifier. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-37714</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10354V-20.12</ProductID>
            <ProductID>P-10354V-21.12</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera Unifier</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2829871.1</URL>
            <ProductID>P-10354V-20.12</ProductID>
            <ProductID>P-10354V-21.12</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="295" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-38153</Title>
      <Notes>
         <Note Audience="All" Ordinal="295" Title="Details" Type="Details">Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Event Streams and Communications (Apache Kafka)).  Supported versions that are affected are 18.8, 19.12, 20.12 and  21.12. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Primavera Unifier accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-38153</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
            <ProductID>P-10354V-20.12</ProductID>
            <ProductID>P-10354V-21.12</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera Unifier</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2829871.1</URL>
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
            <ProductID>P-10354V-20.12</ProductID>
            <ProductID>P-10354V-21.12</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="296" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-39139</Title>
      <Notes>
         <Note Audience="All" Ordinal="296" Title="Details" Type="Details">Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications Applications (component: Updater (XStream)).  Supported versions that are affected are 11.3 and  12.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in takeover of Oracle Communications BRM - Elastic Charging Engine. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-39139</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9742V-11.3</ProductID>
            <ProductID>P-9742V-12.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications BRM - Elastic Charging Engine</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831903.1</URL>
            <ProductID>P-9742V-11.3</ProductID>
            <ProductID>P-9742V-12.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="297" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-39139</Title>
      <Notes>
         <Note Audience="All" Ordinal="297" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Binding Support Function (XStream)).   The supported version that is affected is 1.10.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-39139</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14121V-1.10.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Binding Support Function</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833618.1</URL>
            <ProductID>P-14121V-1.10.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="298" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-39139</Title>
      <Notes>
         <Note Audience="All" Ordinal="298" Title="Details" Type="Details">Vulnerability in the Oracle Utilities Framework product of Oracle Utilities Applications (component: General (XStream)).  Supported versions that are affected are 4.2.0.2.0, 4.2.0.3.0, 4.3.0.1.0-4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0 and  4.4.0.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Utilities Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Framework. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-39139</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2245V-4.2.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.3.0</ProductID>
            <ProductID>P-2245V-4.3.0.1.0-4.3.0.6.0</ProductID>
            <ProductID>P-2245V-4.4.0.0.0</ProductID>
            <ProductID>P-2245V-4.4.0.2.0</ProductID>
            <ProductID>P-2245V-4.4.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Utilities Framework</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832617.1</URL>
            <ProductID>P-2245V-4.2.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.3.0</ProductID>
            <ProductID>P-2245V-4.3.0.1.0-4.3.0.6.0</ProductID>
            <ProductID>P-2245V-4.4.0.0.0</ProductID>
            <ProductID>P-2245V-4.4.0.2.0</ProductID>
            <ProductID>P-2245V-4.4.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="299" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-39139</Title>
      <Notes>
         <Note Audience="All" Ordinal="299" Title="Details" Type="Details">Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (XStream)).   The supported version that is affected is 6.0.0.1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Testing Accelerator. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-39139</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13784V-6.0.0.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Utilities Testing Accelerator</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832617.1</URL>
            <ProductID>P-13784V-6.0.0.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="300" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-39153</Title>
      <Notes>
         <Note Audience="All" Ordinal="300" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Signaling  (XStream)).   The supported version that is affected is 1.14.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  While the vulnerability is in Oracle Communications Cloud Native Core Policy, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-39153</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14277V-1.14.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.5</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Policy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833602.1</URL>
            <ProductID>P-14277V-1.14.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="301" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-39154</Title>
      <Notes>
         <Note Audience="All" Ordinal="301" Title="Details" Type="Details">Vulnerability in the Oracle Business Activity Monitoring product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (XStream)).   The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Activity Monitoring.  While the vulnerability is in Oracle Business Activity Monitoring, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Business Activity Monitoring. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-39154</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1675V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.5</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>BAM (Business Activity Monitoring)</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-1675V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="302" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-40438</Title>
      <Notes>
         <Note Audience="All" Ordinal="302" Title="Details" Type="Details">Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: OSSL Module (Apache HTTP Server)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  While the vulnerability is in Oracle HTTP Server, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-40438</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1042V-12.2.1.3.0</ProductID>
            <ProductID>P-1042V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.0</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>HTTP Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-1042V-12.2.1.3.0</ProductID>
            <ProductID>P-1042V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="303" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-4104</Title>
      <Notes>
         <Note Audience="All" Ordinal="303" Title="Details" Type="Details">Vulnerability in the Oracle Retail Allocation product of Oracle Retail Applications (component: General (Apache Log4j)).  Supported versions that are affected are 14.1.3.2, 15.0.3.1, 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Allocation.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Allocation. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-4104</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1786V-14.1.3.2</ProductID>
            <ProductID>P-1786V-15.0.3.1</ProductID>
            <ProductID>P-1786V-16.0.3</ProductID>
            <ProductID>P-1786V-19.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Allocation</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-1786V-14.1.3.2</ProductID>
            <ProductID>P-1786V-15.0.3.1</ProductID>
            <ProductID>P-1786V-16.0.3</ProductID>
            <ProductID>P-1786V-19.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="304" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-4104</Title>
      <Notes>
         <Note Audience="All" Ordinal="304" Title="Details" Type="Details">Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Apache Log4j)).  Supported versions that are affected are 6.0.0.1.1, 6.0.0.2.2 and  6.0.0.3.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Testing Accelerator. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-4104</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13784V-6.0.0.1.1</ProductID>
            <ProductID>P-13784V-6.0.0.2.2</ProductID>
            <ProductID>P-13784V-6.0.0.3.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Utilities Testing Accelerator</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832617.1</URL>
            <ProductID>P-13784V-6.0.0.1.1</ProductID>
            <ProductID>P-13784V-6.0.0.2.2</ProductID>
            <ProductID>P-13784V-6.0.0.3.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="305" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-4104</Title>
      <Notes>
         <Note Audience="All" Ordinal="305" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Apache Log4j)).  Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-4104</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="306" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-41165</Title>
      <Notes>
         <Note Audience="All" Ordinal="306" Title="Details" Type="Details">Vulnerability in the Oracle Banking APIs product of Oracle Financial Services Applications (component: Framework (CKEditor)).  Supported versions that are affected are 18.1-18.3, 19.1, 19.2, 20.1 and  21.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking APIs.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking APIs, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Banking APIs accessible data as well as  unauthorized read access to a subset of Oracle Banking APIs accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-41165</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13676V-18.1-18.3</ProductID>
            <ProductID>P-13676V-19.1</ProductID>
            <ProductID>P-13676V-19.2</ProductID>
            <ProductID>P-13676V-20.1</ProductID>
            <ProductID>P-13676V-21.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking APIs</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-13676V-18.1-18.3</ProductID>
            <ProductID>P-13676V-19.1</ProductID>
            <ProductID>P-13676V-19.2</ProductID>
            <ProductID>P-13676V-20.1</ProductID>
            <ProductID>P-13676V-21.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="307" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-41165</Title>
      <Notes>
         <Note Audience="All" Ordinal="307" Title="Details" Type="Details">Vulnerability in the Oracle Banking Digital Experience product of Oracle Financial Services Applications (component: Framework (CKEditor)).  Supported versions that are affected are 18.1-18.3, 19.1, 19.2, 20.1 and  21.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Digital Experience.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Digital Experience, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Banking Digital Experience accessible data as well as  unauthorized read access to a subset of Oracle Banking Digital Experience accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-41165</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12605V-18.1-18.3</ProductID>
            <ProductID>P-12605V-19.1</ProductID>
            <ProductID>P-12605V-19.2</ProductID>
            <ProductID>P-12605V-20.1</ProductID>
            <ProductID>P-12605V-21.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Digital Experience</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-12605V-18.1-18.3</ProductID>
            <ProductID>P-12605V-19.1</ProductID>
            <ProductID>P-12605V-19.2</ProductID>
            <ProductID>P-12605V-20.1</ProductID>
            <ProductID>P-12605V-21.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="308" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-42340</Title>
      <Notes>
         <Note Audience="All" Ordinal="308" Title="Details" Type="Details">Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Platform (Apache Tomcat)).  Supported versions that are affected are 8.0.0.0-8.5.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-42340</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10899V-8.0.0.0-8.5.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Diameter Signaling Router (DSR)</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833215.1</URL>
            <ProductID>P-10899V-8.0.0.0-8.5.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="309" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-42340</Title>
      <Notes>
         <Note Audience="All" Ordinal="309" Title="Details" Type="Details">Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System product of Oracle Hospitality Applications (component: Next-Gen SPMS (Apache Tomcat)).   The supported version that is affected is 20.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Cruise Shipboard Property Management System.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Cruise Shipboard Property Management System. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-42340</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11607V-20.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Hospitality Cruise Shipboard Property Management System</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2824526.1</URL>
            <ProductID>P-11607V-20.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="310" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-42340</Title>
      <Notes>
         <Note Audience="All" Ordinal="310" Title="Details" Type="Details">Vulnerability in the Oracle SD-WAN Edge product of Oracle Communications (component: Management (Apache Tomcat)).  Supported versions that are affected are 9.0 and  9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SD-WAN Edge.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle SD-WAN Edge. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-42340</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13940V-9.0</ProductID>
            <ProductID>P-13940V-9.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>SD-WAN Edge</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833604.1</URL>
            <ProductID>P-13940V-9.0</ProductID>
            <ProductID>P-13940V-9.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="311" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-42575</Title>
      <Notes>
         <Note Audience="All" Ordinal="311" Title="Details" Type="Details">Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform, Data Persistence (OWASP Java HTML Sanitizer)).  Supported versions that are affected are 17.7-17.12, 18.8, 19.12, 20.12 and  21.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in takeover of Primavera Unifier. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-42575</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10354V-17.7-17.12</ProductID>
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
            <ProductID>P-10354V-20.12</ProductID>
            <ProductID>P-10354V-21.12</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera Unifier</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2829871.1</URL>
            <ProductID>P-10354V-17.7-17.12</ProductID>
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
            <ProductID>P-10354V-20.12</ProductID>
            <ProductID>P-10354V-21.12</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="312" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-43395</Title>
      <Notes>
         <Note Audience="All" Ordinal="312" Title="Details" Type="Details">Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem).  Supported versions that are affected are 11 and  10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris.  While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-43395</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
            <ProductID>P-10006V-10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Solaris Operating System</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832878.1</URL>
            <ProductID>P-10006V-11</ProductID>
            <ProductID>P-10006V-10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="313" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-44790</Title>
      <Notes>
         <Note Audience="All" Ordinal="313" Title="Details" Type="Details">Vulnerability in the Instantis EnterpriseTrack product of Oracle Construction and Engineering (component: Core (Apache HTTP Server)).  Supported versions that are affected are 17.1, 17.2 and  17.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Instantis EnterpriseTrack.  Successful attacks of this vulnerability can result in takeover of Instantis EnterpriseTrack. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-44790</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10563V-17.1</ProductID>
            <ProductID>P-10563V-17.2</ProductID>
            <ProductID>P-10563V-17.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Instantis EnterpriseTrack</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2829871.1</URL>
            <ProductID>P-10563V-17.1</ProductID>
            <ProductID>P-10563V-17.2</ProductID>
            <ProductID>P-10563V-17.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="314" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-44832</Title>
      <Notes>
         <Note Audience="All" Ordinal="314" Title="Details" Type="Details">Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Virtual Network Function Manager, API Gateway (Apache Log4j)).  Supported versions that are affected are 8.3.0.0-8.5.1.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Signaling Router.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-44832</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10899V-8.3.0.0-8.5.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.6</BaseScore>
            <Vector>AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Diameter Signaling Router (DSR)</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833215.1</URL>
            <ProductID>P-10899V-8.3.0.0-8.5.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="315" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-44832</Title>
      <Notes>
         <Note Audience="All" Ordinal="315" Title="Details" Type="Details">Vulnerability in the Oracle Communications Interactive Session Recorder product of Oracle Communications (component: RSS (Apache Log4j)).  Supported versions that are affected are 6.3 and  6.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Interactive Session Recorder.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Interactive Session Recorder.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-44832</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10765V-6.3</ProductID>
            <ProductID>P-10765V-6.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.6</BaseScore>
            <Vector>AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Interactive Session Recorder</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833605.1</URL>
            <ProductID>P-10765V-6.3</ProductID>
            <ProductID>P-10765V-6.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="316" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-44832</Title>
      <Notes>
         <Note Audience="All" Ordinal="316" Title="Details" Type="Details">Vulnerability in the Primavera Gateway product of Oracle Construction and Engineering (component: Admin (Apache Log4j)).  Supported versions that are affected are 17.12.0-17.12.11, 18.8.0-18.8.13, 19.12.0-19.12.12, 20.12.0-20.12.7 and  21.12.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Primavera Gateway.  Successful attacks of this vulnerability can result in takeover of Primavera Gateway.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-44832</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10605V-17.12.0-17.12.11</ProductID>
            <ProductID>P-10605V-18.8.0-18.8.13</ProductID>
            <ProductID>P-10605V-19.12.0-19.12.12</ProductID>
            <ProductID>P-10605V-20.12.0-20.12.7</ProductID>
            <ProductID>P-10605V-21.12.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.6</BaseScore>
            <Vector>AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera Gateway</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2829871.1</URL>
            <ProductID>P-10605V-17.12.0-17.12.11</ProductID>
            <ProductID>P-10605V-18.8.0-18.8.13</ProductID>
            <ProductID>P-10605V-19.12.0-19.12.12</ProductID>
            <ProductID>P-10605V-20.12.0-20.12.7</ProductID>
            <ProductID>P-10605V-21.12.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="317" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-44832</Title>
      <Notes>
         <Note Audience="All" Ordinal="317" Title="Details" Type="Details">Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access (Apache Log4j)).  Supported versions that are affected are 19.12.0.0-19.12.18.0, 20.12.0.0-20.12.12.0 and  21.12.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management.  Successful attacks of this vulnerability can result in takeover of Primavera P6 Enterprise Project Portfolio Management.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-44832</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5579V-19.12.0.0-19.12.18.0</ProductID>
            <ProductID>P-5579V-20.12.0.0-20.12.12.0</ProductID>
            <ProductID>P-5579V-21.12.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.6</BaseScore>
            <Vector>AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera P6 Enterprise Project Portfolio Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2829871.1</URL>
            <ProductID>P-5579V-19.12.0.0-19.12.18.0</ProductID>
            <ProductID>P-5579V-20.12.0.0-20.12.12.0</ProductID>
            <ProductID>P-5579V-21.12.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="318" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-44832</Title>
      <Notes>
         <Note Audience="All" Ordinal="318" Title="Details" Type="Details">Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Logging (Apache Log4j)).  Supported versions that are affected are 18.8, 19.12, 20.12 and  21.12. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in takeover of Primavera Unifier.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-44832</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
            <ProductID>P-10354V-20.12</ProductID>
            <ProductID>P-10354V-21.12</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.6</BaseScore>
            <Vector>AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera Unifier</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2829871.1</URL>
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
            <ProductID>P-10354V-20.12</ProductID>
            <ProductID>P-10354V-21.12</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="319" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-44832</Title>
      <Notes>
         <Note Audience="All" Ordinal="319" Title="Details" Type="Details">Vulnerability in the Oracle Retail Assortment Planning product of Oracle Retail Applications (component: Application Core (Apache Log4j)).   The supported version that is affected is 16.0.3. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Retail Assortment Planning.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Assortment Planning.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-44832</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1788V-16.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.6</BaseScore>
            <Vector>AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Assortment Planning</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-1788V-16.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="320" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-44832</Title>
      <Notes>
         <Note Audience="All" Ordinal="320" Title="Details" Type="Details">Vulnerability in the Oracle Retail Fiscal Management product of Oracle Retail Applications (component: NF Issuing  (Apache Log4j)).   The supported version that is affected is 14.2. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Retail Fiscal Management.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Fiscal Management.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-44832</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9038V-14.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.6</BaseScore>
            <Vector>AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Fiscal Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-9038V-14.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="321" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-44832</Title>
      <Notes>
         <Note Audience="All" Ordinal="321" Title="Details" Type="Details">Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: Enterprise Cache (Apache Log4j)).  Supported versions that are affected are 21.12 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel UI Framework.  Successful attacks of this vulnerability can result in takeover of Siebel UI Framework.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-44832</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9011V-21.12 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.6</BaseScore>
            <Vector>AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Siebel UI Framework</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832003.1</URL>
            <ProductID>P-9011V-21.12 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="322" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-44832</Title>
      <Notes>
         <Note Audience="All" Ordinal="322" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Apache Log4j)).  Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-44832</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.6</BaseScore>
            <Vector>AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="323" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-45105</Title>
      <Notes>
         <Note Audience="All" Ordinal="323" Title="Details" Type="Details">Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Server (Apache Log4j)).   The supported version that is affected is 5.5.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-45105</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2025V-5.5.0.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Business Intelligence Enterprise Edition</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-2025V-5.5.0.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="324" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-45105</Title>
      <Notes>
         <Note Audience="All" Ordinal="324" Title="Details" Type="Details">Vulnerability in the Oracle Communications Service Broker product of Oracle Communications (component: Integration (Apache Log4j)).   The supported version that is affected is 6.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Broker.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Broker.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-45105</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8565V-6.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Service Broker</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833617.1</URL>
            <ProductID>P-8565V-6.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="325" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-45105</Title>
      <Notes>
         <Note Audience="All" Ordinal="325" Title="Details" Type="Details">Vulnerability in the Oracle Communications Services Gatekeeper product of Oracle Communications (component: API Portal (Apache Log4j)).   The supported version that is affected is 7.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Services Gatekeeper.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Services Gatekeeper.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-45105</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5381V-7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Services Gatekeeper</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833211.1</URL>
            <ProductID>P-5381V-7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="326" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-45105</Title>
      <Notes>
         <Note Audience="All" Ordinal="326" Title="Details" Type="Details">Vulnerability in the Oracle Communications WebRTC Session Controller product of Oracle Communications (component: Signaling Engine, Media Engine (Apache Log4j)).  Supported versions that are affected are 7.2.0 and  7.2.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications WebRTC Session Controller.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications WebRTC Session Controller.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-45105</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10811V-7.2.0</ProductID>
            <ProductID>P-10811V-7.2.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications WebRTC Session Controller</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833614.1</URL>
            <ProductID>P-10811V-7.2.0</ProductID>
            <ProductID>P-10811V-7.2.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="327" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-45105</Title>
      <Notes>
         <Note Audience="All" Ordinal="327" Title="Details" Type="Details">Security-in-Depth issue in the Trace file analyzer (Apache Log4j) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-45105</CVE>
      <ProductStatuses>
         <Status Type="Known Not Affected">
            <ProductID>P-10655V-All Supported Versions</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Engineered Systems Utilities</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-10655V-All Supported Versions</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="328" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-45105</Title>
      <Notes>
         <Note Audience="All" Ordinal="328" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Others (Apache Log4j)).  Supported versions that are affected are 8.0.7-8.1.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Analytical Applications Infrastructure.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-45105</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5680V-8.0.7-8.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Financial Services Analytical Applications Infrastructure</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2825591.1</URL>
            <ProductID>P-5680V-8.0.7-8.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="329" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-45105</Title>
      <Notes>
         <Note Audience="All" Ordinal="329" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer &amp; Configuration (Apache Log4j)).  Supported versions that are affected are 8.0.8, 8.1.0 and  8.1.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Model Management and Governance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Model Management and Governance.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-45105</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14276V-8.0.8</ProductID>
            <ProductID>P-14276V-8.1.0</ProductID>
            <ProductID>P-14276V-8.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Financial Services Model Management and Governance</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2825611.1</URL>
            <ProductID>P-14276V-8.0.8</ProductID>
            <ProductID>P-14276V-8.1.0</ProductID>
            <ProductID>P-14276V-8.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="330" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-45105</Title>
      <Notes>
         <Note Audience="All" Ordinal="330" Title="Details" Type="Details">Vulnerability in the Instantis EnterpriseTrack product of Oracle Construction and Engineering (component: Logging (Apache Log4j)).  Supported versions that are affected are 17.1, 17.2 and  17.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Instantis EnterpriseTrack.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Instantis EnterpriseTrack.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-45105</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10563V-17.1</ProductID>
            <ProductID>P-10563V-17.2</ProductID>
            <ProductID>P-10563V-17.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Instantis EnterpriseTrack</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2829871.1</URL>
            <ProductID>P-10563V-17.1</ProductID>
            <ProductID>P-10563V-17.2</ProductID>
            <ProductID>P-10563V-17.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="331" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-45105</Title>
      <Notes>
         <Note Audience="All" Ordinal="331" Title="Details" Type="Details">Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server  (Apache Log4j)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Managed File Transfer.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Managed File Transfer.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-45105</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10198V-12.2.1.3.0</ProductID>
            <ProductID>P-10198V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Managed File Transfer</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-10198V-12.2.1.3.0</ProductID>
            <ProductID>P-10198V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="332" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-45105</Title>
      <Notes>
         <Note Audience="All" Ordinal="332" Title="Details" Type="Details">Vulnerability in the Oracle Retail Back Office product of Oracle Retail Applications (component: Security (Apache Log4j)).   The supported version that is affected is 14.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Back Office.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Back Office.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-45105</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2013V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Back Office</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-2013V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="333" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-45105</Title>
      <Notes>
         <Note Audience="All" Ordinal="333" Title="Details" Type="Details">Vulnerability in the Oracle Retail Central Office product of Oracle Retail Applications (component: Security (Apache Log4j)).   The supported version that is affected is 14.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Central Office.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Central Office.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-45105</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2016V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Central Office</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-2016V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="334" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-45105</Title>
      <Notes>
         <Note Audience="All" Ordinal="334" Title="Details" Type="Details">Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applications (component: Installation (Apache Log4j)).  Supported versions that are affected are 16.0.3, 17.0.2, 18.0.1, 19.0.1 and  20.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail EFTLink.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail EFTLink.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-45105</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11516V-16.0.3</ProductID>
            <ProductID>P-11516V-17.0.2</ProductID>
            <ProductID>P-11516V-18.0.1</ProductID>
            <ProductID>P-11516V-19.0.1</ProductID>
            <ProductID>P-11516V-20.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail EFTLink</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-11516V-16.0.3</ProductID>
            <ProductID>P-11516V-17.0.2</ProductID>
            <ProductID>P-11516V-18.0.1</ProductID>
            <ProductID>P-11516V-19.0.1</ProductID>
            <ProductID>P-11516V-20.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="335" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-45105</Title>
      <Notes>
         <Note Audience="All" Ordinal="335" Title="Details" Type="Details">Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Apache Log4j)).  Supported versions that are affected are 14.1.3.0, 14.1.3.2, 15.0.3.1, 16.0.1-16.0.3, 19.0.0 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Integration Bus.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-45105</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1807V-14.1.3.0</ProductID>
            <ProductID>P-1807V-14.1.3.2</ProductID>
            <ProductID>P-1807V-15.0.3.1</ProductID>
            <ProductID>P-1807V-16.0.1-16.0.3</ProductID>
            <ProductID>P-1807V-19.0.0</ProductID>
            <ProductID>P-1807V-19.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Integration Bus</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-1807V-14.1.3.0</ProductID>
            <ProductID>P-1807V-14.1.3.2</ProductID>
            <ProductID>P-1807V-15.0.3.1</ProductID>
            <ProductID>P-1807V-16.0.1-16.0.3</ProductID>
            <ProductID>P-1807V-19.0.0</ProductID>
            <ProductID>P-1807V-19.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="336" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-45105</Title>
      <Notes>
         <Note Audience="All" Ordinal="336" Title="Details" Type="Details">Vulnerability in the Oracle Retail Invoice Matching product of Oracle Retail Applications (component: Security (Apache Log4j)).  Supported versions that are affected are 15.0.3 and  16.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Invoice Matching.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Invoice Matching.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-45105</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1810V-15.0.3</ProductID>
            <ProductID>P-1810V-16.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Invoice Matching</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-1810V-15.0.3</ProductID>
            <ProductID>P-1810V-16.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="337" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-45105</Title>
      <Notes>
         <Note Audience="All" Ordinal="337" Title="Details" Type="Details">Vulnerability in the Oracle Retail Order Broker product of Oracle Retail Applications (component: System Administration (Apache Log4j)).  Supported versions that are affected are 16.0, 18.0 and  19.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Order Broker.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Order Broker.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-45105</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11520V-16.0</ProductID>
            <ProductID>P-11520V-18.0</ProductID>
            <ProductID>P-11520V-19.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Order Broker Cloud Service</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-11520V-16.0</ProductID>
            <ProductID>P-11520V-18.0</ProductID>
            <ProductID>P-11520V-19.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="338" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-45105</Title>
      <Notes>
         <Note Audience="All" Ordinal="338" Title="Details" Type="Details">Vulnerability in the Oracle Retail Order Management System product of Oracle Retail Applications (component: Upgrade Install (Apache Log4j)).   The supported version that is affected is 19.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Order Management System.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Order Management System.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-45105</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11519V-19.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Order Management System Cloud Service</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-11519V-19.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="339" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-45105</Title>
      <Notes>
         <Note Audience="All" Ordinal="339" Title="Details" Type="Details">Vulnerability in the Oracle Retail Point-of-Service product of Oracle Retail Applications (component: Administration (Apache Log4j)).   The supported version that is affected is 14.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Point-of-Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Point-of-Service.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-45105</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2017V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Point-of-Service</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-2017V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="340" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-45105</Title>
      <Notes>
         <Note Audience="All" Ordinal="340" Title="Details" Type="Details">Vulnerability in the Oracle Retail Predictive Application Server product of Oracle Retail Applications (component: RPAS Server (Apache Log4j)).  Supported versions that are affected are 14.1.3.46, 15.0.3.115 and  16.0.3.240. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Predictive Application Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Predictive Application Server.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-45105</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1823V-14.1.3.46</ProductID>
            <ProductID>P-1823V-15.0.3.115</ProductID>
            <ProductID>P-1823V-16.0.3.240</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Predictive Application Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-1823V-14.1.3.46</ProductID>
            <ProductID>P-1823V-15.0.3.115</ProductID>
            <ProductID>P-1823V-16.0.3.240</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="341" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-45105</Title>
      <Notes>
         <Note Audience="All" Ordinal="341" Title="Details" Type="Details">Vulnerability in the Oracle Retail Price Management product of Oracle Retail Applications (component: Security (Apache Log4j)).  Supported versions that are affected are 13.2, 14.0.4, 14.1.3, 15.0.3 and  16.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Price Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Price Management.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-45105</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1824V-13.2</ProductID>
            <ProductID>P-1824V-14.0.4</ProductID>
            <ProductID>P-1824V-14.1.3</ProductID>
            <ProductID>P-1824V-15.0.3</ProductID>
            <ProductID>P-1824V-16.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Price Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-1824V-13.2</ProductID>
            <ProductID>P-1824V-14.0.4</ProductID>
            <ProductID>P-1824V-14.1.3</ProductID>
            <ProductID>P-1824V-15.0.3</ProductID>
            <ProductID>P-1824V-16.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="342" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-45105</Title>
      <Notes>
         <Note Audience="All" Ordinal="342" Title="Details" Type="Details">Vulnerability in the Oracle Retail Returns Management product of Oracle Retail Applications (component: Security (Apache Log4j)).   The supported version that is affected is 14.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Returns Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Returns Management.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-45105</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2020V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Returns Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-2020V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="343" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-45105</Title>
      <Notes>
         <Note Audience="All" Ordinal="343" Title="Details" Type="Details">Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation   (Apache Log4j)).  Supported versions that are affected are 14.1.3.0, 14.1.3.2, 15.0.3.1, 16.0.1-16.0.3, 19.0.0 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Service Backbone.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-45105</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10867V-14.1.3.0</ProductID>
            <ProductID>P-10867V-14.1.3.2</ProductID>
            <ProductID>P-10867V-15.0.3.1</ProductID>
            <ProductID>P-10867V-16.0.1-16.0.3</ProductID>
            <ProductID>P-10867V-19.0.0</ProductID>
            <ProductID>P-10867V-19.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Service Backbone</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2826068.1</URL>
            <ProductID>P-10867V-14.1.3.0</ProductID>
            <ProductID>P-10867V-14.1.3.2</ProductID>
            <ProductID>P-10867V-15.0.3.1</ProductID>
            <ProductID>P-10867V-16.0.1-16.0.3</ProductID>
            <ProductID>P-10867V-19.0.0</ProductID>
            <ProductID>P-10867V-19.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="344" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-45105</Title>
      <Notes>
         <Note Audience="All" Ordinal="344" Title="Details" Type="Details">Security-in-Depth issue in the Oracle Spatial and Graph (Apache Log4j) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-45105</CVE>
      <ProductStatuses>
         <Status Type="Known Not Affected">
            <ProductID>P-619V-All Supported Versions</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Spatial and Graph</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-619V-All Supported Versions</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="345" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-45105</Title>
      <Notes>
         <Note Audience="All" Ordinal="345" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework  (Apache Log4j)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebCenter Portal.  Note: This patch also addresses vulnerabilities CVE-2021-44228 and CVE-2021-45046. Customers need not apply the patches/mitigations of Security Alert CVE-2021-44228 and CVE-2021-45046 for this product. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-45105</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1696V-12.2.1.3.0</ProductID>
            <ProductID>P-1696V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebCenter Portal</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-1696V-12.2.1.3.0</ProductID>
            <ProductID>P-1696V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="346" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21242</Title>
      <Notes>
         <Note Audience="All" Ordinal="346" Title="Details" Type="Details">Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Access).  Supported versions that are affected are 18.0.0.0-18.0.3.0, 19.0.0.0-19.0.1.2, 20.0.0.0 and  20.0.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera Portfolio Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera Portfolio Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera Portfolio Management accessible data as well as  unauthorized read access to a subset of Primavera Portfolio Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21242</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5584V-18.0.0.0-18.0.3.0</ProductID>
            <ProductID>P-5584V-19.0.0.0-19.0.1.2</ProductID>
            <ProductID>P-5584V-20.0.0.0</ProductID>
            <ProductID>P-5584V-20.0.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera Portfolio Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2829871.1</URL>
            <ProductID>P-5584V-18.0.0.0-18.0.3.0</ProductID>
            <ProductID>P-5584V-19.0.0.0-19.0.1.2</ProductID>
            <ProductID>P-5584V-20.0.0.0</ProductID>
            <ProductID>P-5584V-20.0.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="347" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21243</Title>
      <Notes>
         <Note Audience="All" Ordinal="347" Title="Details" Type="Details">Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Access).  Supported versions that are affected are 18.0.0.0-18.0.3.0, 19.0.0.0-19.0.1.2, 20.0.0.0 and  20.0.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera Portfolio Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Primavera Portfolio Management. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21243</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5584V-18.0.0.0-18.0.3.0</ProductID>
            <ProductID>P-5584V-19.0.0.0-19.0.1.2</ProductID>
            <ProductID>P-5584V-20.0.0.0</ProductID>
            <ProductID>P-5584V-20.0.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera Portfolio Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2829871.1</URL>
            <ProductID>P-5584V-18.0.0.0-18.0.3.0</ProductID>
            <ProductID>P-5584V-19.0.0.0-19.0.1.2</ProductID>
            <ProductID>P-5584V-20.0.0.0</ProductID>
            <ProductID>P-5584V-20.0.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="348" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21244</Title>
      <Notes>
         <Note Audience="All" Ordinal="348" Title="Details" Type="Details">Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Access).  Supported versions that are affected are 18.0.0.0-18.0.3.0, 19.0.0.0-19.0.1.2, 20.0.0.0 and  20.0.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Portfolio Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera Portfolio Management accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21244</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5584V-18.0.0.0-18.0.3.0</ProductID>
            <ProductID>P-5584V-19.0.0.0-19.0.1.2</ProductID>
            <ProductID>P-5584V-20.0.0.0</ProductID>
            <ProductID>P-5584V-20.0.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera Portfolio Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2829871.1</URL>
            <ProductID>P-5584V-18.0.0.0-18.0.3.0</ProductID>
            <ProductID>P-5584V-19.0.0.0-19.0.1.2</ProductID>
            <ProductID>P-5584V-20.0.0.0</ProductID>
            <ProductID>P-5584V-20.0.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="349" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21245</Title>
      <Notes>
         <Note Audience="All" Ordinal="349" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges).  Supported versions that are affected are 5.7.36 and prior and  8.0.27 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21245</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.36 and prior</ProductID>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-5.7.36 and prior</ProductID>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="350" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21246</Title>
      <Notes>
         <Note Audience="All" Ordinal="350" Title="Details" Type="Details">Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine).  Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and  5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Operations Monitor accessible data as well as  unauthorized read access to a subset of Oracle Communications Operations Monitor accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21246</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10761V-3.4</ProductID>
            <ProductID>P-10761V-4.2</ProductID>
            <ProductID>P-10761V-4.3</ProductID>
            <ProductID>P-10761V-4.4</ProductID>
            <ProductID>P-10761V-5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Operations Monitor</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833603.1</URL>
            <ProductID>P-10761V-3.4</ProductID>
            <ProductID>P-10761V-4.2</ProductID>
            <ProductID>P-10761V-4.3</ProductID>
            <ProductID>P-10761V-4.4</ProductID>
            <ProductID>P-10761V-5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="351" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21247</Title>
      <Notes>
         <Note Audience="All" Ordinal="351" Title="Details" Type="Details">Vulnerability in the Core RDBMS component of Oracle Database Server.  Supported versions that are affected are 12.2.0.1 and  19c. Easily exploitable vulnerability allows high privileged attacker having Create Session, Execute Catalog Role privilege with network access via Oracle Net to compromise Core RDBMS.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Core RDBMS accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21247</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.7</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Database - Enterprise Edition</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="352" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21248</Title>
      <Notes>
         <Note Audience="All" Ordinal="352" Title="Details" Type="Details">Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization).  Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.01; Oracle GraalVM Enterprise Edition: 20.3.4 and  21.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21248</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Oracle Java SE:7u321</ProductID>
            <ProductID>P-856V-Oracle Java SE:8u311</ProductID>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Java SE JDK and JRE</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2828114.1</URL>
            <ProductID>P-856V-Oracle Java SE:7u321</ProductID>
            <ProductID>P-856V-Oracle Java SE:8u311</ProductID>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="353" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21249</Title>
      <Notes>
         <Note Audience="All" Ordinal="353" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL).  Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 2.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21249</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.7</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="354" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21250</Title>
      <Notes>
         <Note Audience="All" Ordinal="354" Title="Details" Type="Details">Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: GL Accounts).  Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Trade Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Trade Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Trade Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21250</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-765V-12.2.3-12.2.11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Trade Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2484000.1</URL>
            <ProductID>P-765V-12.2.3-12.2.11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="355" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21251</Title>
      <Notes>
         <Note Audience="All" Ordinal="355" Title="Details" Type="Details">Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Instance Main).  Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Installed Base.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Installed Base. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21251</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1118V-12.2.3-12.2.11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Installed Base</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2484000.1</URL>
            <ProductID>P-1118V-12.2.3-12.2.11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="356" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21252</Title>
      <Notes>
         <Note Audience="All" Ordinal="356" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as  unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21252</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="357" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21253</Title>
      <Notes>
         <Note Audience="All" Ordinal="357" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21253</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="358" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21254</Title>
      <Notes>
         <Note Audience="All" Ordinal="358" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21254</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="359" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21255</Title>
      <Notes>
         <Note Audience="All" Ordinal="359" Title="Details" Type="Details">Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: UI Servlet).  Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Configurator.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Configurator accessible data as well as  unauthorized access to critical data or complete access to all Oracle Configurator accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21255</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-31V-12.2.3-12.2.11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Configurator</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2484000.1</URL>
            <ProductID>P-31V-12.2.3-12.2.11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="360" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21256</Title>
      <Notes>
         <Note Audience="All" Ordinal="360" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin).  Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21256</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="361" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21257</Title>
      <Notes>
         <Note Audience="All" Ordinal="361" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as  unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21257</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="362" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21258</Title>
      <Notes>
         <Note Audience="All" Ordinal="362" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples).   The supported version that is affected is 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as  unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21258</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="363" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21259</Title>
      <Notes>
         <Note Audience="All" Ordinal="363" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as  unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21259</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="364" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21260</Title>
      <Notes>
         <Note Audience="All" Ordinal="364" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as  unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21260</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="365" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21261</Title>
      <Notes>
         <Note Audience="All" Ordinal="365" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as  unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21261</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="366" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21262</Title>
      <Notes>
         <Note Audience="All" Ordinal="366" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as  unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21262</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="367" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21263</Title>
      <Notes>
         <Note Audience="All" Ordinal="367" Title="Details" Type="Details">Vulnerability in the Oracle Solaris product of Oracle Systems (component: Fault Management Architecture).   The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Solaris accessible data as well as  unauthorized read access to a subset of Oracle Solaris accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Solaris. CVSS 3.1 Base Score 4.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21263</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Solaris Operating System</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832878.1</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="368" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21264</Title>
      <Notes>
         <Note Audience="All" Ordinal="368" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21264</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="369" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21265</Title>
      <Notes>
         <Note Audience="All" Ordinal="369" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 3.8 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21265</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.8</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="370" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21266</Title>
      <Notes>
         <Note Audience="All" Ordinal="370" Title="Details" Type="Details">Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Pipeline Manager).  Supported versions that are affected are 12.0.0.3 and  12.0.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Billing and Revenue Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21266</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2136V-12.0.0.3</ProductID>
            <ProductID>P-2136V-12.0.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Billing and Revenue Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831903.1</URL>
            <ProductID>P-2136V-12.0.0.3</ProductID>
            <ProductID>P-2136V-12.0.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="371" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21267</Title>
      <Notes>
         <Note Audience="All" Ordinal="371" Title="Details" Type="Details">Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Pipeline Manager).  Supported versions that are affected are 12.0.0.3 and  12.0.0.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Billing and Revenue Management executes to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Billing and Revenue Management accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21267</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2136V-12.0.0.3</ProductID>
            <ProductID>P-2136V-12.0.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.3</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Billing and Revenue Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831903.1</URL>
            <ProductID>P-2136V-12.0.0.3</ProductID>
            <ProductID>P-2136V-12.0.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="372" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21268</Title>
      <Notes>
         <Note Audience="All" Ordinal="372" Title="Details" Type="Details">Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Pipeline Manager).  Supported versions that are affected are 12.0.0.3 and  12.0.0.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Billing and Revenue Management executes to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Billing and Revenue Management accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21268</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2136V-12.0.0.3</ProductID>
            <ProductID>P-2136V-12.0.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.3</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Billing and Revenue Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831903.1</URL>
            <ProductID>P-2136V-12.0.0.3</ProductID>
            <ProductID>P-2136V-12.0.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="373" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21269</Title>
      <Notes>
         <Note Audience="All" Ordinal="373" Title="Details" Type="Details">Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Access).  Supported versions that are affected are 18.0.0.0-18.0.3.0, 19.0.0.0-19.0.1.2, 20.0.0.0 and  20.0.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Portfolio Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera Portfolio Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera Portfolio Management accessible data as well as  unauthorized read access to a subset of Primavera Portfolio Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21269</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5584V-18.0.0.0-18.0.3.0</ProductID>
            <ProductID>P-5584V-19.0.0.0-19.0.1.2</ProductID>
            <ProductID>P-5584V-20.0.0.0</ProductID>
            <ProductID>P-5584V-20.0.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera Portfolio Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2829871.1</URL>
            <ProductID>P-5584V-18.0.0.0-18.0.3.0</ProductID>
            <ProductID>P-5584V-19.0.0.0-19.0.1.2</ProductID>
            <ProductID>P-5584V-20.0.0.0</ProductID>
            <ProductID>P-5584V-20.0.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="374" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21270</Title>
      <Notes>
         <Note Audience="All" Ordinal="374" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Federated).  Supported versions that are affected are 5.7.36 and prior and  8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21270</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.36 and prior</ProductID>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-5.7.36 and prior</ProductID>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="375" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21271</Title>
      <Notes>
         <Note Audience="All" Ordinal="375" Title="Details" Type="Details">Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).  Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13; Oracle GraalVM Enterprise Edition: 20.3.4 and  21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21271</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Oracle Java SE:7u321</ProductID>
            <ProductID>P-856V-Oracle Java SE:8u311</ProductID>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Java SE JDK and JRE</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2828114.1</URL>
            <ProductID>P-856V-Oracle Java SE:7u321</ProductID>
            <ProductID>P-856V-Oracle Java SE:8u311</ProductID>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="376" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21271</Title>
      <Notes>
         <Note Audience="All" Ordinal="376" Title="Details" Type="Details">Vulnerability in the Oracle Solaris product of Oracle Systems (component: Libraries).   The supported version that is affected is 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Solaris.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Solaris. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21271</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Solaris Operating System</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832878.1</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="377" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21272</Title>
      <Notes>
         <Note Audience="All" Ordinal="377" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal).  Supported versions that are affected are 8.57, 8.58 and  8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21272</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>PeopleSoft Enterprise PT PeopleTools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831970.1</URL>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="378" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21273</Title>
      <Notes>
         <Note Audience="All" Ordinal="378" Title="Details" Type="Details">Vulnerability in the Oracle Project Costing product of Oracle E-Business Suite (component: Expenses, Currency Override).  Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Costing.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Project Costing accessible data as well as  unauthorized access to critical data or complete access to all Oracle Project Costing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21273</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1287V-12.2.3-12.2.11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Project Costing</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2484000.1</URL>
            <ProductID>P-1287V-12.2.3-12.2.11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="379" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21274</Title>
      <Notes>
         <Note Audience="All" Ordinal="379" Title="Details" Type="Details">Vulnerability in the Oracle Sourcing product of Oracle E-Business Suite (component: Intelligence, RFx Creation).  Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sourcing.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Sourcing accessible data as well as  unauthorized access to critical data or complete access to all Oracle Sourcing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21274</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1273V-12.2.3-12.2.11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Sourcing</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2484000.1</URL>
            <ProductID>P-1273V-12.2.3-12.2.11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="380" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21275</Title>
      <Notes>
         <Note Audience="All" Ordinal="380" Title="Details" Type="Details">Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager).  Supported versions that are affected are 12.0.0.3 and  12.0.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  While the vulnerability is in Oracle Communications Billing and Revenue Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21275</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2136V-12.0.0.3</ProductID>
            <ProductID>P-2136V-12.0.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Billing and Revenue Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831903.1</URL>
            <ProductID>P-2136V-12.0.0.3</ProductID>
            <ProductID>P-2136V-12.0.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="381" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21276</Title>
      <Notes>
         <Note Audience="All" Ordinal="381" Title="Details" Type="Details">Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager).  Supported versions that are affected are 12.0.0.3 and  12.0.0.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  While the vulnerability is in Oracle Communications Billing and Revenue Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21276</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2136V-12.0.0.3</ProductID>
            <ProductID>P-2136V-12.0.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.9</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Billing and Revenue Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831903.1</URL>
            <ProductID>P-2136V-12.0.0.3</ProductID>
            <ProductID>P-2136V-12.0.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="382" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21277</Title>
      <Notes>
         <Note Audience="All" Ordinal="382" Title="Details" Type="Details">Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO).  Supported versions that are affected are Oracle Java SE: 11.0.13, 17.01; Oracle GraalVM Enterprise Edition: 20.3.4 and  21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21277</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Java SE JDK and JRE</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2828114.1</URL>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="383" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21278</Title>
      <Notes>
         <Note Audience="All" Ordinal="383" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21278</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.26 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-8.0.26 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="384" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21279</Title>
      <Notes>
         <Note Audience="All" Ordinal="384" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21279</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="385" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21280</Title>
      <Notes>
         <Note Audience="All" Ordinal="385" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21280</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="386" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21281</Title>
      <Notes>
         <Note Audience="All" Ordinal="386" Title="Details" Type="Details">Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Access).  Supported versions that are affected are 18.0.0.0-18.0.3.0, 19.0.0.0-19.0.1.2, 20.0.0.0 and  20.0.0.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Primavera Portfolio Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera Portfolio Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera Portfolio Management accessible data as well as  unauthorized read access to a subset of Primavera Portfolio Management accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21281</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5584V-18.0.0.0-18.0.3.0</ProductID>
            <ProductID>P-5584V-19.0.0.0-19.0.1.2</ProductID>
            <ProductID>P-5584V-20.0.0.0</ProductID>
            <ProductID>P-5584V-20.0.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera Portfolio Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2829871.1</URL>
            <ProductID>P-5584V-18.0.0.0-18.0.3.0</ProductID>
            <ProductID>P-5584V-19.0.0.0-19.0.1.2</ProductID>
            <ProductID>P-5584V-20.0.0.0</ProductID>
            <ProductID>P-5584V-20.0.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="387" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21282</Title>
      <Notes>
         <Note Audience="All" Ordinal="387" Title="Details" Type="Details">Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP).  Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.01; Oracle GraalVM Enterprise Edition: 20.3.4 and  21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21282</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Oracle Java SE:7u321</ProductID>
            <ProductID>P-856V-Oracle Java SE:8u311</ProductID>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Java SE JDK and JRE</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2828114.1</URL>
            <ProductID>P-856V-Oracle Java SE:7u321</ProductID>
            <ProductID>P-856V-Oracle Java SE:8u311</ProductID>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="388" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21283</Title>
      <Notes>
         <Note Audience="All" Ordinal="388" Title="Details" Type="Details">Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).  Supported versions that are affected are Oracle Java SE: 11.0.13, 17.01; Oracle GraalVM Enterprise Edition: 20.3.4 and  21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21283</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Java SE JDK and JRE</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2828114.1</URL>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="389" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21284</Title>
      <Notes>
         <Note Audience="All" Ordinal="389" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21284</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="390" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21285</Title>
      <Notes>
         <Note Audience="All" Ordinal="390" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21285</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="391" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21286</Title>
      <Notes>
         <Note Audience="All" Ordinal="391" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21286</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="392" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21287</Title>
      <Notes>
         <Note Audience="All" Ordinal="392" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21287</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="393" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21288</Title>
      <Notes>
         <Note Audience="All" Ordinal="393" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21288</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="394" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21289</Title>
      <Notes>
         <Note Audience="All" Ordinal="394" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21289</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="395" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21290</Title>
      <Notes>
         <Note Audience="All" Ordinal="395" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21290</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="396" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21291</Title>
      <Notes>
         <Note Audience="All" Ordinal="396" Title="Details" Type="Details">Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot).  Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.01; Oracle GraalVM Enterprise Edition: 20.3.4 and  21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21291</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Oracle Java SE:7u321</ProductID>
            <ProductID>P-856V-Oracle Java SE:8u311</ProductID>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Java SE JDK and JRE</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2828114.1</URL>
            <ProductID>P-856V-Oracle Java SE:7u321</ProductID>
            <ProductID>P-856V-Oracle Java SE:8u311</ProductID>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="397" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21292</Title>
      <Notes>
         <Note Audience="All" Ordinal="397" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21292</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="398" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21293</Title>
      <Notes>
         <Note Audience="All" Ordinal="398" Title="Details" Type="Details">Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).  Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.01; Oracle GraalVM Enterprise Edition: 20.3.4 and  21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21293</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Oracle Java SE:7u321</ProductID>
            <ProductID>P-856V-Oracle Java SE:8u311</ProductID>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Java SE JDK and JRE</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2828114.1</URL>
            <ProductID>P-856V-Oracle Java SE:7u321</ProductID>
            <ProductID>P-856V-Oracle Java SE:8u311</ProductID>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="399" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21294</Title>
      <Notes>
         <Note Audience="All" Ordinal="399" Title="Details" Type="Details">Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).  Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.01; Oracle GraalVM Enterprise Edition: 20.3.4 and  21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21294</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Oracle Java SE:7u321</ProductID>
            <ProductID>P-856V-Oracle Java SE:8u311</ProductID>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Java SE JDK and JRE</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2828114.1</URL>
            <ProductID>P-856V-Oracle Java SE:7u321</ProductID>
            <ProductID>P-856V-Oracle Java SE:8u311</ProductID>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="400" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21295</Title>
      <Notes>
         <Note Audience="All" Ordinal="400" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is Prior to 6.1.32. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21295</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-Prior to 6.1.32</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>VM VirtualBox</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833279.1</URL>
            <ProductID>P-8370V-Prior to 6.1.32</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="401" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21296</Title>
      <Notes>
         <Note Audience="All" Ordinal="401" Title="Details" Type="Details">Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP).  Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.01; Oracle GraalVM Enterprise Edition: 20.3.4 and  21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21296</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Oracle Java SE:7u321</ProductID>
            <ProductID>P-856V-Oracle Java SE:8u311</ProductID>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Java SE JDK and JRE</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2828114.1</URL>
            <ProductID>P-856V-Oracle Java SE:7u321</ProductID>
            <ProductID>P-856V-Oracle Java SE:8u311</ProductID>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="402" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21297</Title>
      <Notes>
         <Note Audience="All" Ordinal="402" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21297</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.26 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-8.0.26 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="403" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21298</Title>
      <Notes>
         <Note Audience="All" Ordinal="403" Title="Details" Type="Details">Vulnerability in the Oracle Solaris product of Oracle Systems (component: Install).   The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Solaris accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Solaris. CVSS 3.1 Base Score 3.9 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21298</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.9</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Solaris Operating System</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832878.1</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="404" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21299</Title>
      <Notes>
         <Note Audience="All" Ordinal="404" Title="Details" Type="Details">Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP).  Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.01; Oracle GraalVM Enterprise Edition: 20.3.4 and  21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21299</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Oracle Java SE:7u321</ProductID>
            <ProductID>P-856V-Oracle Java SE:8u311</ProductID>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Java SE JDK and JRE</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2828114.1</URL>
            <ProductID>P-856V-Oracle Java SE:7u321</ProductID>
            <ProductID>P-856V-Oracle Java SE:8u311</ProductID>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="405" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21300</Title>
      <Notes>
         <Note Audience="All" Ordinal="405" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise CS SA Integration Pack product of Oracle PeopleSoft (component: Snapshot Integration).  Supported versions that are affected are 9.0 and  9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS SA Integration Pack.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS SA Integration Pack accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21300</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5107V-9.0</ProductID>
            <ProductID>P-5107V-9.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>PeopleSoft Enterprise CS SA Integration Pack</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831970.1</URL>
            <ProductID>P-5107V-9.0</ProductID>
            <ProductID>P-5107V-9.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="406" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21301</Title>
      <Notes>
         <Note Audience="All" Ordinal="406" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML).  Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21301</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="407" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21302</Title>
      <Notes>
         <Note Audience="All" Ordinal="407" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21302</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="408" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21303</Title>
      <Notes>
         <Note Audience="All" Ordinal="408" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure).  Supported versions that are affected are 5.7.36 and prior and  8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21303</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.36 and prior</ProductID>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-5.7.36 and prior</ProductID>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="409" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21304</Title>
      <Notes>
         <Note Audience="All" Ordinal="409" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser).  Supported versions that are affected are 5.7.36 and prior and  8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21304</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.36 and prior</ProductID>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-5.7.36 and prior</ProductID>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="410" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21305</Title>
      <Notes>
         <Note Audience="All" Ordinal="410" Title="Details" Type="Details">Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot).  Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.01; Oracle GraalVM Enterprise Edition: 20.3.4 and  21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21305</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Oracle Java SE:7u321</ProductID>
            <ProductID>P-856V-Oracle Java SE:8u311</ProductID>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Java SE JDK and JRE</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2828114.1</URL>
            <ProductID>P-856V-Oracle Java SE:7u321</ProductID>
            <ProductID>P-856V-Oracle Java SE:8u311</ProductID>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="411" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21306</Title>
      <Notes>
         <Note Audience="All" Ordinal="411" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21306</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="412" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21307</Title>
      <Notes>
         <Note Audience="All" Ordinal="412" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21307</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="413" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21308</Title>
      <Notes>
         <Note Audience="All" Ordinal="413" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21308</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="414" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21309</Title>
      <Notes>
         <Note Audience="All" Ordinal="414" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21309</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="415" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21310</Title>
      <Notes>
         <Note Audience="All" Ordinal="415" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21310</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="416" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21311</Title>
      <Notes>
         <Note Audience="All" Ordinal="416" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Cluster accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Cluster. CVSS 3.1 Base Score 2.9 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21311</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.9</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="417" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21312</Title>
      <Notes>
         <Note Audience="All" Ordinal="417" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Cluster accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Cluster. CVSS 3.1 Base Score 2.9 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21312</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.9</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="418" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21313</Title>
      <Notes>
         <Note Audience="All" Ordinal="418" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Cluster accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Cluster. CVSS 3.1 Base Score 2.9 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21313</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.9</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="419" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21314</Title>
      <Notes>
         <Note Audience="All" Ordinal="419" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21314</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="420" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21315</Title>
      <Notes>
         <Note Audience="All" Ordinal="420" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21315</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="421" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21316</Title>
      <Notes>
         <Note Audience="All" Ordinal="421" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21316</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="422" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21317</Title>
      <Notes>
         <Note Audience="All" Ordinal="422" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Cluster accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Cluster. CVSS 3.1 Base Score 2.9 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21317</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.9</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="423" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21318</Title>
      <Notes>
         <Note Audience="All" Ordinal="423" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21318</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="424" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21319</Title>
      <Notes>
         <Note Audience="All" Ordinal="424" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Cluster accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Cluster. CVSS 3.1 Base Score 2.9 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21319</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.9</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="425" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21320</Title>
      <Notes>
         <Note Audience="All" Ordinal="425" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21320</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="426" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21321</Title>
      <Notes>
         <Note Audience="All" Ordinal="426" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Cluster accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Cluster. CVSS 3.1 Base Score 2.9 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21321</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.9</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="427" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21322</Title>
      <Notes>
         <Note Audience="All" Ordinal="427" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21322</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="428" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21323</Title>
      <Notes>
         <Note Audience="All" Ordinal="428" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Cluster accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Cluster. CVSS 3.1 Base Score 2.9 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21323</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.9</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="429" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21324</Title>
      <Notes>
         <Note Audience="All" Ordinal="429" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Cluster accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Cluster. CVSS 3.1 Base Score 2.9 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21324</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.9</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="430" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21325</Title>
      <Notes>
         <Note Audience="All" Ordinal="430" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Cluster accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Cluster. CVSS 3.1 Base Score 2.9 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21325</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.9</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="431" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21326</Title>
      <Notes>
         <Note Audience="All" Ordinal="431" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21326</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="432" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21327</Title>
      <Notes>
         <Note Audience="All" Ordinal="432" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21327</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="433" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21328</Title>
      <Notes>
         <Note Audience="All" Ordinal="433" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21328</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="434" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21329</Title>
      <Notes>
         <Note Audience="All" Ordinal="434" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21329</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="435" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21330</Title>
      <Notes>
         <Note Audience="All" Ordinal="435" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21330</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="436" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21331</Title>
      <Notes>
         <Note Audience="All" Ordinal="436" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Cluster accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Cluster. CVSS 3.1 Base Score 2.9 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21331</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.9</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="437" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21332</Title>
      <Notes>
         <Note Audience="All" Ordinal="437" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21332</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="438" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21333</Title>
      <Notes>
         <Note Audience="All" Ordinal="438" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Cluster accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Cluster. CVSS 3.1 Base Score 2.9 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21333</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.9</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="439" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21334</Title>
      <Notes>
         <Note Audience="All" Ordinal="439" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21334</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="440" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21335</Title>
      <Notes>
         <Note Audience="All" Ordinal="440" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21335</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="441" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21336</Title>
      <Notes>
         <Note Audience="All" Ordinal="441" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21336</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="442" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21337</Title>
      <Notes>
         <Note Audience="All" Ordinal="442" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21337</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="443" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21338</Title>
      <Notes>
         <Note Audience="All" Ordinal="443" Title="Details" Type="Details">Vulnerability in the Oracle Communications Convergence product of Oracle Communications Applications (component: General Framework).   The supported version that is affected is 3.0.2.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Convergence.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Convergence accessible data as well as  unauthorized read access to a subset of Oracle Communications Convergence accessible data. CVSS 3.1 Base Score 4.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21338</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8501V-3.0.2.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.6</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Convergence</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831902.1</URL>
            <ProductID>P-8501V-3.0.2.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="444" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21339</Title>
      <Notes>
         <Note Audience="All" Ordinal="444" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21339</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="445" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21340</Title>
      <Notes>
         <Note Audience="All" Ordinal="445" Title="Details" Type="Details">Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).  Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.01; Oracle GraalVM Enterprise Edition: 20.3.4 and  21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21340</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Oracle Java SE:7u321</ProductID>
            <ProductID>P-856V-Oracle Java SE:8u311</ProductID>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Java SE JDK and JRE</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2828114.1</URL>
            <ProductID>P-856V-Oracle Java SE:7u321</ProductID>
            <ProductID>P-856V-Oracle Java SE:8u311</ProductID>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="446" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21341</Title>
      <Notes>
         <Note Audience="All" Ordinal="446" Title="Details" Type="Details">Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization).  Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.01; Oracle GraalVM Enterprise Edition: 20.3.4 and  21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21341</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Oracle Java SE:7u321</ProductID>
            <ProductID>P-856V-Oracle Java SE:8u311</ProductID>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Java SE JDK and JRE</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2828114.1</URL>
            <ProductID>P-856V-Oracle Java SE:7u321</ProductID>
            <ProductID>P-856V-Oracle Java SE:8u311</ProductID>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="447" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21342</Title>
      <Notes>
         <Note Audience="All" Ordinal="447" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21342</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="448" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21344</Title>
      <Notes>
         <Note Audience="All" Ordinal="448" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are 5.7.36 and prior and  8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21344</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.36 and prior</ProductID>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-5.7.36 and prior</ProductID>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="449" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21345</Title>
      <Notes>
         <Note Audience="All" Ordinal="449" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security).  Supported versions that are affected are 8.58 and  8.59. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21345</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>PeopleSoft Enterprise PT PeopleTools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831970.1</URL>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="450" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21346</Title>
      <Notes>
         <Note Audience="All" Ordinal="450" Title="Details" Type="Details">Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security).  Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21346</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1479V-5.5.0.0.0</ProductID>
            <ProductID>P-1479V-12.2.1.3.0</ProductID>
            <ProductID>P-1479V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>BI Publisher (formerly XML Publisher)</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-1479V-5.5.0.0.0</ProductID>
            <ProductID>P-1479V-12.2.1.3.0</ProductID>
            <ProductID>P-1479V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="451" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21347</Title>
      <Notes>
         <Note Audience="All" Ordinal="451" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21347</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="452" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21348</Title>
      <Notes>
         <Note Audience="All" Ordinal="452" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21348</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="453" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21349</Title>
      <Notes>
         <Note Audience="All" Ordinal="453" Title="Details" Type="Details">Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D).  Supported versions that are affected are Oracle Java SE: 7u321, 8u311; Oracle GraalVM Enterprise Edition: 20.3.4 and  21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21349</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Oracle Java SE:7u321</ProductID>
            <ProductID>P-856V-Oracle Java SE:8u311</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Java SE JDK and JRE</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2828114.1</URL>
            <ProductID>P-856V-Oracle Java SE:7u321</ProductID>
            <ProductID>P-856V-Oracle Java SE:8u311</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="454" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21350</Title>
      <Notes>
         <Note Audience="All" Ordinal="454" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21350</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="455" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21351</Title>
      <Notes>
         <Note Audience="All" Ordinal="455" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="456" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21352</Title>
      <Notes>
         <Note Audience="All" Ordinal="456" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Server accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 5.9 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21352</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.26 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-8.0.26 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="457" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21353</Title>
      <Notes>
         <Note Audience="All" Ordinal="457" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21353</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="458" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21354</Title>
      <Notes>
         <Note Audience="All" Ordinal="458" Title="Details" Type="Details">Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: User Interface).  Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iStore, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle iStore accessible data as well as  unauthorized read access to a subset of Oracle iStore accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21354</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-384V-12.2.3-12.2.11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>iStore</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2484000.1</URL>
            <ProductID>P-384V-12.2.3-12.2.11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="459" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21355</Title>
      <Notes>
         <Note Audience="All" Ordinal="459" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Cluster accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Cluster. CVSS 3.1 Base Score 2.9 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21355</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.9</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="460" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21356</Title>
      <Notes>
         <Note Audience="All" Ordinal="460" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21356</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="461" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21357</Title>
      <Notes>
         <Note Audience="All" Ordinal="461" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Cluster accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Cluster. CVSS 3.1 Base Score 2.9 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21357</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.9</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="462" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21358</Title>
      <Notes>
         <Note Audience="All" Ordinal="462" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption).  Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21358</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="463" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21359</Title>
      <Notes>
         <Note Audience="All" Ordinal="463" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Optimization Framework).  Supported versions that are affected are 8.57, 8.58 and  8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21359</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>PeopleSoft Enterprise PT PeopleTools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831970.1</URL>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="464" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21360</Title>
      <Notes>
         <Note Audience="All" Ordinal="464" Title="Details" Type="Details">Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO).  Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.01; Oracle GraalVM Enterprise Edition: 20.3.4 and  21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21360</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Oracle Java SE:7u321</ProductID>
            <ProductID>P-856V-Oracle Java SE:8u311</ProductID>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Java SE JDK and JRE</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2828114.1</URL>
            <ProductID>P-856V-Oracle Java SE:7u321</ProductID>
            <ProductID>P-856V-Oracle Java SE:8u311</ProductID>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="465" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21361</Title>
      <Notes>
         <Note Audience="All" Ordinal="465" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Sample apps).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as  unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21361</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="466" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21362</Title>
      <Notes>
         <Note Audience="All" Ordinal="466" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema).  Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21362</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="467" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21363</Title>
      <Notes>
         <Note Audience="All" Ordinal="467" Title="Details" Type="Details">Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J).  Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21363</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8576V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.6</BaseScore>
            <Vector>AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Connectors</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8576V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="468" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21364</Title>
      <Notes>
         <Note Audience="All" Ordinal="468" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Weblogic).  Supported versions that are affected are 8.57, 8.58 and  8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21364</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>PeopleSoft Enterprise PT PeopleTools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831970.1</URL>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="469" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21365</Title>
      <Notes>
         <Note Audience="All" Ordinal="469" Title="Details" Type="Details">Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO).  Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.01; Oracle GraalVM Enterprise Edition: 20.3.4 and  21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21365</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Oracle Java SE:7u321</ProductID>
            <ProductID>P-856V-Oracle Java SE:8u311</ProductID>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Java SE JDK and JRE</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2828114.1</URL>
            <ProductID>P-856V-Oracle Java SE:7u321</ProductID>
            <ProductID>P-856V-Oracle Java SE:8u311</ProductID>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="470" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21366</Title>
      <Notes>
         <Note Audience="All" Ordinal="470" Title="Details" Type="Details">Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO).  Supported versions that are affected are Oracle Java SE: 11.0.13, 17.01; Oracle GraalVM Enterprise Edition: 20.3.4 and  21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21366</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Java SE JDK and JRE</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2828114.1</URL>
            <ProductID>P-856V-Oracle Java SE:11.0.13</ProductID>
            <ProductID>P-856V-Oracle Java SE:17.01</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:20.3.4</ProductID>
            <ProductID>P-14564V-Oracle GraalVM Enterprise Edition:21.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="471" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21367</Title>
      <Notes>
         <Note Audience="All" Ordinal="471" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Compiling).  Supported versions that are affected are 5.7.36 and prior and  8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21367</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.36 and prior</ProductID>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-5.7.36 and prior</ProductID>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="472" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21368</Title>
      <Notes>
         <Note Audience="All" Ordinal="472" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services).  Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Server accessible data as well as  unauthorized read access to a subset of MySQL Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 4.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21368</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.7</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="473" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21369</Title>
      <Notes>
         <Note Audience="All" Ordinal="473" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Rich Text Editor).  Supported versions that are affected are 8.57, 8.58 and  8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21369</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>PeopleSoft Enterprise PT PeopleTools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831970.1</URL>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="474" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21370</Title>
      <Notes>
         <Note Audience="All" Ordinal="474" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21370</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="475" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21371</Title>
      <Notes>
         <Note Audience="All" Ordinal="475" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container).  Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21371</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="476" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21372</Title>
      <Notes>
         <Note Audience="All" Ordinal="476" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption).  Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 2.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21372</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.7</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="477" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21373</Title>
      <Notes>
         <Note Audience="All" Ordinal="477" Title="Details" Type="Details">Vulnerability in the Oracle Partner Management product of Oracle E-Business Suite (component: Reseller Locator).  Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Partner Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Partner Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Partner Management accessible data as well as  unauthorized read access to a subset of Oracle Partner Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21373</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1065V-12.2.3-12.2.11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Partner Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2484000.1</URL>
            <ProductID>P-1065V-12.2.3-12.2.11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="478" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21374</Title>
      <Notes>
         <Note Audience="All" Ordinal="478" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema).  Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21374</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="479" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21375</Title>
      <Notes>
         <Note Audience="All" Ordinal="479" Title="Details" Type="Details">Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel).   The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21375</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Solaris Operating System</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832878.1</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="480" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21376</Title>
      <Notes>
         <Note Audience="All" Ordinal="480" Title="Details" Type="Details">Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Access).  Supported versions that are affected are 18.0.0.0-18.0.3.0, 19.0.0.0-19.0.1.2 and  20.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Portfolio Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera Portfolio Management accessible data as well as  unauthorized read access to a subset of Primavera Portfolio Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21376</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5584V-18.0.0.0-18.0.3.0</ProductID>
            <ProductID>P-5584V-19.0.0.0-19.0.1.2</ProductID>
            <ProductID>P-5584V-20.0.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera Portfolio Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2829871.1</URL>
            <ProductID>P-5584V-18.0.0.0-18.0.3.0</ProductID>
            <ProductID>P-5584V-19.0.0.0-19.0.1.2</ProductID>
            <ProductID>P-5584V-20.0.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="481" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21377</Title>
      <Notes>
         <Note Audience="All" Ordinal="481" Title="Details" Type="Details">Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web API).  Supported versions that are affected are 18.0.0.0-18.0.3.0, 19.0.0.0-19.0.1.2 and  20.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Portfolio Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera Portfolio Management accessible data as well as  unauthorized read access to a subset of Primavera Portfolio Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21377</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5584V-18.0.0.0-18.0.3.0</ProductID>
            <ProductID>P-5584V-19.0.0.0-19.0.1.2</ProductID>
            <ProductID>P-5584V-20.0.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera Portfolio Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2829871.1</URL>
            <ProductID>P-5584V-18.0.0.0-18.0.3.0</ProductID>
            <ProductID>P-5584V-19.0.0.0-19.0.1.2</ProductID>
            <ProductID>P-5584V-20.0.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="482" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21378</Title>
      <Notes>
         <Note Audience="All" Ordinal="482" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21378</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="483" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21379</Title>
      <Notes>
         <Note Audience="All" Ordinal="483" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin).  Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21379</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8478V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="484" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21380</Title>
      <Notes>
         <Note Audience="All" Ordinal="484" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and  8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21380</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832117.1</URL>
            <ProductID>P-8479V-7.4.34 and prior</ProductID>
            <ProductID>P-8479V-7.5.24 and prior</ProductID>
            <ProductID>P-8479V-7.6.20 and prior</ProductID>
            <ProductID>P-8479V-8.0.27 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="485" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21381</Title>
      <Notes>
         <Note Audience="All" Ordinal="485" Title="Details" Type="Details">Vulnerability in the Oracle Enterprise Session Border Controller product of Oracle Communications (component: WebUI).  Supported versions that are affected are 8.4 and  9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Session Border Controller.  While the vulnerability is in Oracle Enterprise Session Border Controller, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Enterprise Session Border Controller accessible data as well as  unauthorized read access to a subset of Oracle Enterprise Session Border Controller accessible data. CVSS 3.1 Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21381</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10757V-8.4</ProductID>
            <ProductID>P-10757V-9.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Enterprise Session Border Controller</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833085.1</URL>
            <ProductID>P-10757V-8.4</ProductID>
            <ProductID>P-10757V-9.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="486" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21382</Title>
      <Notes>
         <Note Audience="All" Ordinal="486" Title="Details" Type="Details">Vulnerability in the Oracle Enterprise Session Border Controller product of Oracle Communications (component: WebUI).  Supported versions that are affected are 8.4 and  9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Session Border Controller.  While the vulnerability is in Oracle Enterprise Session Border Controller, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Session Border Controller accessible data. CVSS 3.1 Base Score 7.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21382</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10757V-8.4</ProductID>
            <ProductID>P-10757V-9.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.7</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Enterprise Session Border Controller</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833085.1</URL>
            <ProductID>P-10757V-8.4</ProductID>
            <ProductID>P-10757V-9.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="487" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21383</Title>
      <Notes>
         <Note Audience="All" Ordinal="487" Title="Details" Type="Details">Vulnerability in the Oracle Enterprise Session Border Controller product of Oracle Communications (component: Log).  Supported versions that are affected are 8.4 and  9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Session Border Controller.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Session Border Controller. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21383</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10757V-8.4</ProductID>
            <ProductID>P-10757V-9.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Enterprise Session Border Controller</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833085.1</URL>
            <ProductID>P-10757V-8.4</ProductID>
            <ProductID>P-10757V-9.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="488" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21386</Title>
      <Notes>
         <Note Audience="All" Ordinal="488" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container).  Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as  unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21386</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="489" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21387</Title>
      <Notes>
         <Note Audience="All" Ordinal="489" Title="Details" Type="Details">Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework).  Supported versions that are affected are 11.3.0, 11.3.1 and  11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21387</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9348V-11.3.0</ProductID>
            <ProductID>P-9348V-11.3.1</ProductID>
            <ProductID>P-9348V-11.3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Commerce Platform</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2832419.1</URL>
            <ProductID>P-9348V-11.3.0</ProductID>
            <ProductID>P-9348V-11.3.1</ProductID>
            <ProductID>P-9348V-11.3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="490" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21388</Title>
      <Notes>
         <Note Audience="All" Ordinal="490" Title="Details" Type="Details">Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications Applications (component: On Premise Install).  Supported versions that are affected are 12.0.0.3.0 and  12.0.0.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Pricing Design Center executes to compromise Oracle Communications Pricing Design Center.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Pricing Design Center accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21388</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9437V-12.0.0.3.0</ProductID>
            <ProductID>P-9437V-12.0.0.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.3</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Pricing Design Center</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831903.1</URL>
            <ProductID>P-9437V-12.0.0.3.0</ProductID>
            <ProductID>P-9437V-12.0.0.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="491" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21389</Title>
      <Notes>
         <Note Audience="All" Ordinal="491" Title="Details" Type="Details">Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager).  Supported versions that are affected are 12.0.0.3 and  12.0.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  While the vulnerability is in Oracle Communications Billing and Revenue Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21389</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2136V-12.0.0.3</ProductID>
            <ProductID>P-2136V-12.0.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Billing and Revenue Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831903.1</URL>
            <ProductID>P-2136V-12.0.0.3</ProductID>
            <ProductID>P-2136V-12.0.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="492" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21390</Title>
      <Notes>
         <Note Audience="All" Ordinal="492" Title="Details" Type="Details">Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Webservices Manager).  Supported versions that are affected are 12.0.0.3 and  12.0.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  While the vulnerability is in Oracle Communications Billing and Revenue Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21390</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2136V-12.0.0.3</ProductID>
            <ProductID>P-2136V-12.0.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Billing and Revenue Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831903.1</URL>
            <ProductID>P-2136V-12.0.0.3</ProductID>
            <ProductID>P-2136V-12.0.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="493" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21391</Title>
      <Notes>
         <Note Audience="All" Ordinal="493" Title="Details" Type="Details">Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager).  Supported versions that are affected are 12.0.0.3 and  12.0.0.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  While the vulnerability is in Oracle Communications Billing and Revenue Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21391</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2136V-12.0.0.3</ProductID>
            <ProductID>P-2136V-12.0.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.9</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Billing and Revenue Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2831903.1</URL>
            <ProductID>P-2136V-12.0.0.3</ProductID>
            <ProductID>P-2136V-12.0.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="494" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21392</Title>
      <Notes>
         <Note Audience="All" Ordinal="494" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Policy Framework).  Supported versions that are affected are 13.4.0.0 and  13.5.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Enterprise Manager Base Platform executes to compromise Enterprise Manager Base Platform.  While the vulnerability is in Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21392</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-13.4.0.0</ProductID>
            <ProductID>P-1370V-13.5.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Enterprise Manager Base Platform</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-1370V-13.4.0.0</ProductID>
            <ProductID>P-1370V-13.5.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="495" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21393</Title>
      <Notes>
         <Note Audience="All" Ordinal="495" Title="Details" Type="Details">Vulnerability in the Java VM component of Oracle Database Server.  Supported versions that are affected are 12.1.0.2, 12.2.0.1, 19c and  21c. Easily exploitable vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to compromise Java VM.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java VM. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21393</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-19c</ProductID>
            <ProductID>P-5V-21c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Database - Enterprise Edition</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2817011.1</URL>
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-19c</ProductID>
            <ProductID>P-5V-21c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="496" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21394</Title>
      <Notes>
         <Note Audience="All" Ordinal="496" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is Prior to 6.1.32. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data.  Note: This vulnerability applies to Windows systems only. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21394</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-Prior to 6.1.32</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>VM VirtualBox</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833279.1</URL>
            <ProductID>P-8370V-Prior to 6.1.32</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="497" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21395</Title>
      <Notes>
         <Note Audience="All" Ordinal="497" Title="Details" Type="Details">Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine).  Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and  5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Operations Monitor. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21395</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10761V-3.4</ProductID>
            <ProductID>P-10761V-4.2</ProductID>
            <ProductID>P-10761V-4.3</ProductID>
            <ProductID>P-10761V-4.4</ProductID>
            <ProductID>P-10761V-5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.2</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Operations Monitor</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833603.1</URL>
            <ProductID>P-10761V-3.4</ProductID>
            <ProductID>P-10761V-4.2</ProductID>
            <ProductID>P-10761V-4.3</ProductID>
            <ProductID>P-10761V-4.4</ProductID>
            <ProductID>P-10761V-5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="498" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21396</Title>
      <Notes>
         <Note Audience="All" Ordinal="498" Title="Details" Type="Details">Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine).  Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and  5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Operations Monitor accessible data as well as  unauthorized read access to a subset of Oracle Communications Operations Monitor accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21396</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10761V-3.4</ProductID>
            <ProductID>P-10761V-4.2</ProductID>
            <ProductID>P-10761V-4.3</ProductID>
            <ProductID>P-10761V-4.4</ProductID>
            <ProductID>P-10761V-5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Operations Monitor</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833603.1</URL>
            <ProductID>P-10761V-3.4</ProductID>
            <ProductID>P-10761V-4.2</ProductID>
            <ProductID>P-10761V-4.3</ProductID>
            <ProductID>P-10761V-4.4</ProductID>
            <ProductID>P-10761V-5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="499" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21397</Title>
      <Notes>
         <Note Audience="All" Ordinal="499" Title="Details" Type="Details">Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine).  Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and  5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Operations Monitor accessible data as well as  unauthorized read access to a subset of Oracle Communications Operations Monitor accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21397</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10761V-3.4</ProductID>
            <ProductID>P-10761V-4.2</ProductID>
            <ProductID>P-10761V-4.3</ProductID>
            <ProductID>P-10761V-4.4</ProductID>
            <ProductID>P-10761V-5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Operations Monitor</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833603.1</URL>
            <ProductID>P-10761V-3.4</ProductID>
            <ProductID>P-10761V-4.2</ProductID>
            <ProductID>P-10761V-4.3</ProductID>
            <ProductID>P-10761V-4.4</ProductID>
            <ProductID>P-10761V-5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="500" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21398</Title>
      <Notes>
         <Note Audience="All" Ordinal="500" Title="Details" Type="Details">Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine).  Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and  5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Operations Monitor accessible data as well as  unauthorized read access to a subset of Oracle Communications Operations Monitor accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21398</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10761V-3.4</ProductID>
            <ProductID>P-10761V-4.2</ProductID>
            <ProductID>P-10761V-4.3</ProductID>
            <ProductID>P-10761V-4.4</ProductID>
            <ProductID>P-10761V-5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Operations Monitor</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833603.1</URL>
            <ProductID>P-10761V-3.4</ProductID>
            <ProductID>P-10761V-4.2</ProductID>
            <ProductID>P-10761V-4.3</ProductID>
            <ProductID>P-10761V-4.4</ProductID>
            <ProductID>P-10761V-5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="501" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21399</Title>
      <Notes>
         <Note Audience="All" Ordinal="501" Title="Details" Type="Details">Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine).  Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and  5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  While the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Operations Monitor accessible data as well as  unauthorized read access to a subset of Oracle Communications Operations Monitor accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Operations Monitor. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21399</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10761V-3.4</ProductID>
            <ProductID>P-10761V-4.2</ProductID>
            <ProductID>P-10761V-4.3</ProductID>
            <ProductID>P-10761V-4.4</ProductID>
            <ProductID>P-10761V-5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.6</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Operations Monitor</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833603.1</URL>
            <ProductID>P-10761V-3.4</ProductID>
            <ProductID>P-10761V-4.2</ProductID>
            <ProductID>P-10761V-4.3</ProductID>
            <ProductID>P-10761V-4.4</ProductID>
            <ProductID>P-10761V-5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="502" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21400</Title>
      <Notes>
         <Note Audience="All" Ordinal="502" Title="Details" Type="Details">Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine).  Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and  5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Operations Monitor accessible data as well as  unauthorized read access to a subset of Oracle Communications Operations Monitor accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21400</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10761V-3.4</ProductID>
            <ProductID>P-10761V-4.2</ProductID>
            <ProductID>P-10761V-4.3</ProductID>
            <ProductID>P-10761V-4.4</ProductID>
            <ProductID>P-10761V-5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Operations Monitor</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833603.1</URL>
            <ProductID>P-10761V-3.4</ProductID>
            <ProductID>P-10761V-4.2</ProductID>
            <ProductID>P-10761V-4.3</ProductID>
            <ProductID>P-10761V-4.4</ProductID>
            <ProductID>P-10761V-5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="503" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21401</Title>
      <Notes>
         <Note Audience="All" Ordinal="503" Title="Details" Type="Details">Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine).  Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and  5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  While the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Operations Monitor accessible data as well as  unauthorized read access to a subset of Oracle Communications Operations Monitor accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Operations Monitor. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21401</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10761V-3.4</ProductID>
            <ProductID>P-10761V-4.2</ProductID>
            <ProductID>P-10761V-4.3</ProductID>
            <ProductID>P-10761V-4.4</ProductID>
            <ProductID>P-10761V-5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.6</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Operations Monitor</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833603.1</URL>
            <ProductID>P-10761V-3.4</ProductID>
            <ProductID>P-10761V-4.2</ProductID>
            <ProductID>P-10761V-4.3</ProductID>
            <ProductID>P-10761V-4.4</ProductID>
            <ProductID>P-10761V-5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="504" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21402</Title>
      <Notes>
         <Note Audience="All" Ordinal="504" Title="Details" Type="Details">Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine).  Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and  5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Operations Monitor accessible data as well as  unauthorized read access to a subset of Oracle Communications Operations Monitor accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21402</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10761V-3.4</ProductID>
            <ProductID>P-10761V-4.2</ProductID>
            <ProductID>P-10761V-4.3</ProductID>
            <ProductID>P-10761V-4.4</ProductID>
            <ProductID>P-10761V-5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Operations Monitor</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833603.1</URL>
            <ProductID>P-10761V-3.4</ProductID>
            <ProductID>P-10761V-4.2</ProductID>
            <ProductID>P-10761V-4.3</ProductID>
            <ProductID>P-10761V-4.4</ProductID>
            <ProductID>P-10761V-5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="505" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2022-21403</Title>
      <Notes>
         <Note Audience="All" Ordinal="505" Title="Details" Type="Details">Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine).  Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and  5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  While the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Operations Monitor accessible data as well as  unauthorized read access to a subset of Oracle Communications Operations Monitor accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Operations Monitor. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2022-21403</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10761V-3.4</ProductID>
            <ProductID>P-10761V-4.2</ProductID>
            <ProductID>P-10761V-4.3</ProductID>
            <ProductID>P-10761V-4.4</ProductID>
            <ProductID>P-10761V-5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.6</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Operations Monitor</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2833603.1</URL>
            <ProductID>P-10761V-3.4</ProductID>
            <ProductID>P-10761V-4.2</ProductID>
            <ProductID>P-10761V-4.3</ProductID>
            <ProductID>P-10761V-4.4</ProductID>
            <ProductID>P-10761V-5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
</cvrf:cvrfdoc>
