<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet type="text/xsl" href="2967710.xsl"?>
<?xml-stylesheet type="text/css" href="2967708.css"?>
<cvrf:cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
   <DocumentTitle xml:lang="en">Oracle Critical Patch Update Advisory - July 2021 - Oracle CVRF</DocumentTitle>
   <DocumentType xml:lang="en">Oracle Critical Patch Update Advisory</DocumentType>
   <DocumentPublisher Type="Vendor"/>
   <DocumentTracking>
      <Identification>
         <ID>CPUJul2021</ID>
      </Identification>
      <Status>Final</Status>
      <Version>6.0</Version>
      <RevisionHistory>
         <Revision>
            <Number>6.0</Number>
            <Date>2021-08-19T15:00:00-07:00</Date>
            <Description>Updated CVSS scores for Outside In Technology
</Description>
         </Revision>
      </RevisionHistory>
      <InitialReleaseDate>2021-07-20T13:00:00-07:00</InitialReleaseDate>
      <CurrentReleaseDate>2021-08-19T15:00:00-07:00</CurrentReleaseDate>
   </DocumentTracking>
   <DocumentNotes>
      <Note Audience="All" Ordinal="1" Title="Summary" Type="Summary" xml:lang="en">This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document.</Note>
   </DocumentNotes>
   <DocumentDistribution>This document is published at: https://www.oracle.com/a/tech/docs/cpujul2021cvrf.xml</DocumentDistribution>
   <DocumentReferences>
      <Reference Type="External">
         <URL>https://www.oracle.com/security-alerts/cpujul2021.html</URL>
         <Description>URL to html version of Advisory</Description>
      </Reference>
   </DocumentReferences>
   <Acknowledgments>
      <Acknowledgment>
         <Name>0xfoxone</Name>
         <Organization>0xfoxone</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Abhishek Morla</Name>
         <Organization>Abhishek Morla</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Adeel Khan</Name>
         <Organization>Adeel Khan</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Aleksey Shipilev</Name>
         <Organization>Red Hat</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Varnavas Papaioannou</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Andrej Simko</Name>
         <Organization>Accenture</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Anonymous researcher working with Trend Micro's Zero Day Initiative</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Armaan Khurshid Pathan of Emirates Group</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ashik Kunjumon</Name>
         <Organization>Ashik Kunjumon</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Billy Jheng Bing Jhong of STAR Labs</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Boumediene Kaddour</Name>
         <Organization>Boumediene Kaddour</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Brian Reilly</Name>
         <Organization>Brian Reilly</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Devin Rosenbauer</Name>
         <Organization>Identity Works LLC</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Dimitris Doganos</Name>
         <Organization>COSMOTE - Mobile Telecommunications S.A.</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Eddie Zhu of Beijing DBSEC Technology Co., Ltd</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Emad Al-Mousa</Name>
         <Organization>Emad Al-Mousa</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Faraz Khan from Emirates Group</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Filip Ceglik</Name>
         <Organization>Filip Ceglik</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Gaurang Maheta</Name>
         <Organization>gaurang maheta</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Gianluca Danesin</Name>
         <Organization>Mondadori</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Girlelecta</Name>
         <Organization>Girlelecta</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Guillaume Jacques</Name>
         <Organization>synacktiv</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Hamoud Al-Helmani</Name>
         <Organization>Hamoud Al-Helmani</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Haya Shulman</Name>
         <Organization>Fraunhofer.de</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Huixin Ma of Tencent.com</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Husnain Iqbal</Name>
         <Organization>Husnain Iqbal</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Information Security Management</Name>
         <Organization>Information Security Management</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jang Laptop of VNPT ISC working with Trend Micro Zero Day Initiative</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>KPC</Name>
         <Organization>Trend Micro's Zero Day Initiative</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Kajetan Rostojek</Name>
         <Organization>Kajetan Rostojek</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Khalid matar Alharthi</Name>
         <Organization>Khalid matar Alharthi</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Li Boheng</Name>
         <Organization>Li Boheng</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>thiscodecc of MoyunSec V-Lab</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Longofo</Name>
         <Organization>Knownsec 404 Team</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Maciej Grabiec of ING Tech Poland</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Markus Loewe</Name>
         <Organization>Markus Loewe</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Martin Neumann</Name>
         <Organization>Accenture</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Matthias Kaiser of Apple Information Security</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Mohamed Ahmed Naji</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Mohit Rawat</Name>
         <Organization>Mohit Rawat</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Moritz Bechler</Name>
         <Organization>SySS GmbH</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Naman Shah</Name>
         <Organization>Naman Shah</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Nik Czuprinski</Name>
         <Organization>Nik Czuprinski</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Okan Basegmez</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Paul Barbé</Name>
         <Organization>synacktiv</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Peterjson of RedTeam@VNG Corporation working with Trend Micro Zero Day Initiative</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Philipp Jeitner</Name>
         <Organization>Fraunhofer.de</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Pratik Khalane</Name>
         <Organization>Pratik Khalane</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Qiguang Zhu</Name>
         <Organization>Qiguang Zhu</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Quynh Le of VNPT ISC working with Trend Micro Zero Day Initiative</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Rajnish Kumar Gupta</Name>
         <Organization>Rajnish Kumar Gupta</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Rakan Abdulrahman Al Khaled</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Sakhare Vinayak</Name>
         <Organization>Sakhare Vinayak</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Snigdha Priya</Name>
         <Organization>Snigdha Priya</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Sohamin Durkar</Name>
         <Organization>Sohamin Durkar</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Stefano Barber</Name>
         <Organization>Stefano Barber</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Tech Zone</Name>
         <Organization>Tech Zone</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Théo Louis-Tisserand</Name>
         <Organization>synacktiv</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ved Prabhu</Name>
         <Organization>Ved Prabhu</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Vishnu Dev T J working with Trend Micro's Zero Day Initiative</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Vivek Panday</Name>
         <Organization>Vivek Panday</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Waleed Ezz Eldin of Cysiv (Previously SecureMisr)</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Yaoguang Chen</Name>
         <Organization>Ant Security Light-Year Lab</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Yash Sharma</Name>
         <Organization>Yash Sharma</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Zach Edwards</Name>
         <Organization>victorymedium.com</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Zoe Pentaleri</Name>
         <Organization>Zoe Pentaleri</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Max Van Amerongen (maxpl0it)</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>r00t4dm at Cloud-Penetrating Arrow Lab</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Marwan Albahar</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>threedr3am</Name>
         <Organization>threedr3am</Organization>
      </Acknowledgment>
   </Acknowledgments>
   <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
      <Branch Name="Oracle" Type="Vendor">
         <Branch Name="Oracle Big Data Graph" Type="Product Family">
            <Branch Name="Big Data Spatial and Graph" Type="Product Name">
               <Branch Name="All Supported Versions" Type="Product Version">
                  <FullProductName ProductID="P-11528V-All Supported Versions">Big Data Spatial and Graph Version All Supported Versions</FullProductName>
               </Branch>
               <Branch Name="Prior to 2.0" Type="Product Version">
                  <FullProductName ProductID="P-11528V-Prior to 2.0">Big Data Spatial and Graph Version Prior to 2.0</FullProductName>
               </Branch>
               <Branch Name="Prior to 23.1" Type="Product Version">
                  <FullProductName ProductID="P-11528V-Prior to 23.1">Big Data Spatial and Graph Version Prior to 23.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Commerce" Type="Product Family">
            <Branch Name="Commerce Platform" Type="Product Name">
               <Branch Name="11.0.0" Type="Product Version">
                  <FullProductName ProductID="P-9348V-11.0.0">Commerce Platform Version 11.0.0</FullProductName>
               </Branch>
               <Branch Name="11.1.0" Type="Product Version">
                  <FullProductName ProductID="P-9348V-11.1.0">Commerce Platform Version 11.1.0</FullProductName>
               </Branch>
               <Branch Name="11.2.0" Type="Product Version">
                  <FullProductName ProductID="P-9348V-11.2.0">Commerce Platform Version 11.2.0</FullProductName>
               </Branch>
               <Branch Name="11.3.0-11.3.2" Type="Product Version">
                  <FullProductName ProductID="P-9348V-11.3.0-11.3.2">Commerce Platform Version 11.3.0-11.3.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Commerce Merchandising" Type="Product Name">
               <Branch Name="11.1.0" Type="Product Version">
                  <FullProductName ProductID="P-9349V-11.1.0">Commerce Merchandising Version 11.1.0</FullProductName>
               </Branch>
               <Branch Name="11.2.0" Type="Product Version">
                  <FullProductName ProductID="P-9349V-11.2.0">Commerce Merchandising Version 11.2.0</FullProductName>
               </Branch>
               <Branch Name="11.3.0-11.3.2" Type="Product Version">
                  <FullProductName ProductID="P-9349V-11.3.0-11.3.2">Commerce Merchandising Version 11.3.0-11.3.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Commerce Service Center" Type="Product Name">
               <Branch Name="11.0.0" Type="Product Version">
                  <FullProductName ProductID="P-9351V-11.0.0">Commerce Service Center Version 11.0.0</FullProductName>
               </Branch>
               <Branch Name="11.1.0" Type="Product Version">
                  <FullProductName ProductID="P-9351V-11.1.0">Commerce Service Center Version 11.1.0</FullProductName>
               </Branch>
               <Branch Name="11.2.0" Type="Product Version">
                  <FullProductName ProductID="P-9351V-11.2.0">Commerce Service Center Version 11.2.0</FullProductName>
               </Branch>
               <Branch Name="11.3.0-11.3.2" Type="Product Version">
                  <FullProductName ProductID="P-9351V-11.3.0-11.3.2">Commerce Service Center Version 11.3.0-11.3.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Commerce Guided Search / Oracle Commerce Experience Manager" Type="Product Name">
               <Branch Name="11.3.1.5" Type="Product Version">
                  <FullProductName ProductID="P-9633V-11.3.1.5">Commerce Guided Search / Oracle Commerce Experience Manager Version 11.3.1.5</FullProductName>
               </Branch>
               <Branch Name="11.3.2" Type="Product Version">
                  <FullProductName ProductID="P-9633V-11.3.2">Commerce Guided Search / Oracle Commerce Experience Manager Version 11.3.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Communications" Type="Product Family">
            <Branch Name="Communications Services Gatekeeper" Type="Product Name">
               <Branch Name="7.0" Type="Product Version">
                  <FullProductName ProductID="P-5381V-7.0">Communications Services Gatekeeper Version 7.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications EAGLE (Software)" Type="Product Name">
               <Branch Name="46.6.0-46.8.2" Type="Product Version">
                  <FullProductName ProductID="P-10768V-46.6.0-46.8.2">Communications EAGLE (Software) Version 46.6.0-46.8.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Application Session Controller" Type="Product Name">
               <Branch Name="3.9" Type="Product Version">
                  <FullProductName ProductID="P-10769V-3.9">Communications Application Session Controller Version 3.9</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Diameter Signaling Router (DSR)" Type="Product Name">
               <Branch Name="8.0.0-8.5.0" Type="Product Version">
                  <FullProductName ProductID="P-10899V-8.0.0-8.5.0">Communications Diameter Signaling Router (DSR) Version 8.0.0-8.5.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Evolved Communications Application Server" Type="Product Name">
               <Branch Name="7.1" Type="Product Version">
                  <FullProductName ProductID="P-10994V-7.1">Communications Evolved Communications Application Server Version 7.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="SD-WAN Edge" Type="Product Name">
               <Branch Name="8.2" Type="Product Version">
                  <FullProductName ProductID="P-13940V-8.2">SD-WAN Edge Version 8.2</FullProductName>
               </Branch>
               <Branch Name="9.0" Type="Product Version">
                  <FullProductName ProductID="P-13940V-9.0">SD-WAN Edge Version 9.0</FullProductName>
               </Branch>
               <Branch Name="9.1" Type="Product Version">
                  <FullProductName ProductID="P-13940V-9.1">SD-WAN Edge Version 9.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="SD-WAN Aware" Type="Product Name">
               <Branch Name="8.2" Type="Product Version">
                  <FullProductName ProductID="P-13941V-8.2">SD-WAN Aware Version 8.2</FullProductName>
               </Branch>
               <Branch Name="9.0" Type="Product Version">
                  <FullProductName ProductID="P-13941V-9.0">SD-WAN Aware Version 9.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Cloud Native Core Service Communication Proxy" Type="Product Name">
               <Branch Name="1.5.2" Type="Product Version">
                  <FullProductName ProductID="P-14117V-1.5.2">Communications Cloud Native Core Service Communication Proxy Version 1.5.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Cloud Native Core Unified Data Repository" Type="Product Name">
               <Branch Name="1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-14119V-1.4.0">Communications Cloud Native Core Unified Data Repository Version 1.4.0</FullProductName>
               </Branch>
               <Branch Name="1.6.0" Type="Product Version">
                  <FullProductName ProductID="P-14119V-1.6.0">Communications Cloud Native Core Unified Data Repository Version 1.6.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Cloud Native Core Security Edge Protection Proxy" Type="Product Name">
               <Branch Name="1.7.0" Type="Product Version">
                  <FullProductName ProductID="P-14123V-1.7.0">Communications Cloud Native Core Security Edge Protection Proxy Version 1.7.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Cloud Native Core Network Function Cloud Native Environment" Type="Product Name">
               <Branch Name="1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-14125V-1.4.0">Communications Cloud Native Core Network Function Cloud Native Environment Version 1.4.0</FullProductName>
               </Branch>
               <Branch Name="1.7.0" Type="Product Version">
                  <FullProductName ProductID="P-14125V-1.7.0">Communications Cloud Native Core Network Function Cloud Native Environment Version 1.7.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Cloud Native Core Network Slice Selection Function" Type="Product Name">
               <Branch Name="1.2.1" Type="Product Version">
                  <FullProductName ProductID="P-14130V-1.2.1">Communications Cloud Native Core Network Slice Selection Function Version 1.2.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Cloud Native Core Console" Type="Product Name">
               <Branch Name="1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-14250V-1.4.0">Communications Cloud Native Core Console Version 1.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Cloud Native Core Policy" Type="Product Name">
               <Branch Name="1.5.0" Type="Product Version">
                  <FullProductName ProductID="P-14277V-1.5.0">Communications Cloud Native Core Policy Version 1.5.0</FullProductName>
               </Branch>
               <Branch Name="1.9.0" Type="Product Version">
                  <FullProductName ProductID="P-14277V-1.9.0">Communications Cloud Native Core Policy Version 1.9.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Communications Applications" Type="Product Family">
            <Branch Name="Communications Billing and Revenue Management" Type="Product Name">
               <Branch Name="12.0.0.3.0" Type="Product Version">
                  <FullProductName ProductID="P-2136V-12.0.0.3.0">Communications Billing and Revenue Management Version 12.0.0.3.0</FullProductName>
               </Branch>
               <Branch Name="7.5.0.23.0" Type="Product Version">
                  <FullProductName ProductID="P-2136V-7.5.0.23.0">Communications Billing and Revenue Management Version 7.5.0.23.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Offline Mediation Controller" Type="Product Name">
               <Branch Name="12.0.0.3.0" Type="Product Version">
                  <FullProductName ProductID="P-2269V-12.0.0.3.0">Communications Offline Mediation Controller Version 12.0.0.3.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Design Studio" Type="Product Name">
               <Branch Name="7.4.2" Type="Product Version">
                  <FullProductName ProductID="P-2283V-7.4.2">Communications Design Studio Version 7.4.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Unified Inventory Management" Type="Product Name">
               <Branch Name="7.3.2" Type="Product Version">
                  <FullProductName ProductID="P-4516V-7.3.2">Communications Unified Inventory Management Version 7.3.2</FullProductName>
               </Branch>
               <Branch Name="7.3.4" Type="Product Version">
                  <FullProductName ProductID="P-4516V-7.3.4">Communications Unified Inventory Management Version 7.3.4</FullProductName>
               </Branch>
               <Branch Name="7.3.5" Type="Product Version">
                  <FullProductName ProductID="P-4516V-7.3.5">Communications Unified Inventory Management Version 7.3.5</FullProductName>
               </Branch>
               <Branch Name="7.4.0" Type="Product Version">
                  <FullProductName ProductID="P-4516V-7.4.0">Communications Unified Inventory Management Version 7.4.0</FullProductName>
               </Branch>
               <Branch Name="7.4.1" Type="Product Version">
                  <FullProductName ProductID="P-4516V-7.4.1">Communications Unified Inventory Management Version 7.4.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Network Charging and Control" Type="Product Name">
               <Branch Name="12.0.1.0-12.0.4.0" Type="Product Version">
                  <FullProductName ProductID="P-4623V-12.0.1.0-12.0.4.0">Communications Network Charging and Control Version 12.0.1.0-12.0.4.0</FullProductName>
               </Branch>
               <Branch Name="12.0.4.0.0" Type="Product Version">
                  <FullProductName ProductID="P-4623V-12.0.4.0.0">Communications Network Charging and Control Version 12.0.4.0.0</FullProductName>
               </Branch>
               <Branch Name="6.0.1.0" Type="Product Version">
                  <FullProductName ProductID="P-4623V-6.0.1.0">Communications Network Charging and Control Version 6.0.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Instant Messaging Server" Type="Product Name">
               <Branch Name="10.0.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-8495V-10.0.1.4.0">Communications Instant Messaging Server Version 10.0.1.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Pricing Design Center" Type="Product Name">
               <Branch Name="12.0.0.3.0" Type="Product Version">
                  <FullProductName ProductID="P-9437V-12.0.0.3.0">Communications Pricing Design Center Version 12.0.0.3.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications BRM - Elastic Charging Engine" Type="Product Name">
               <Branch Name="11.3.0.9.0" Type="Product Version">
                  <FullProductName ProductID="P-9742V-11.3.0.9.0">Communications BRM - Elastic Charging Engine Version 11.3.0.9.0</FullProductName>
               </Branch>
               <Branch Name="12.0.0.3.0" Type="Product Version">
                  <FullProductName ProductID="P-9742V-12.0.0.3.0">Communications BRM - Elastic Charging Engine Version 12.0.0.3.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Convergent Charging Controller" Type="Product Name">
               <Branch Name="12.0.4.0.0" Type="Product Version">
                  <FullProductName ProductID="P-12985V-12.0.4.0.0">Communications Convergent Charging Controller Version 12.0.4.0.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Construction and Engineering" Type="Product Family">
            <Branch Name="Primavera P6 Enterprise Project Portfolio Management" Type="Product Name">
               <Branch Name="17.12.0-17.12.20" Type="Product Version">
                  <FullProductName ProductID="P-5579V-17.12.0-17.12.20">Primavera P6 Enterprise Project Portfolio Management Version 17.12.0-17.12.20</FullProductName>
               </Branch>
               <Branch Name="18.8.0-18.8.23" Type="Product Version">
                  <FullProductName ProductID="P-5579V-18.8.0-18.8.23">Primavera P6 Enterprise Project Portfolio Management Version 18.8.0-18.8.23</FullProductName>
               </Branch>
               <Branch Name="19.12.0-19.12.14" Type="Product Version">
                  <FullProductName ProductID="P-5579V-19.12.0-19.12.14">Primavera P6 Enterprise Project Portfolio Management Version 19.12.0-19.12.14</FullProductName>
               </Branch>
               <Branch Name="20.12.0-20.12.3" Type="Product Version">
                  <FullProductName ProductID="P-5579V-20.12.0-20.12.3">Primavera P6 Enterprise Project Portfolio Management Version 20.12.0-20.12.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Primavera Unifier" Type="Product Name">
               <Branch Name="17.7-17.12" Type="Product Version">
                  <FullProductName ProductID="P-10354V-17.7-17.12">Primavera Unifier Version 17.7-17.12</FullProductName>
               </Branch>
               <Branch Name="18.8" Type="Product Version">
                  <FullProductName ProductID="P-10354V-18.8">Primavera Unifier Version 18.8</FullProductName>
               </Branch>
               <Branch Name="19.12" Type="Product Version">
                  <FullProductName ProductID="P-10354V-19.12">Primavera Unifier Version 19.12</FullProductName>
               </Branch>
               <Branch Name="20.12" Type="Product Version">
                  <FullProductName ProductID="P-10354V-20.12">Primavera Unifier Version 20.12</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Instantis EnterpriseTrack" Type="Product Name">
               <Branch Name="17.1" Type="Product Version">
                  <FullProductName ProductID="P-10563V-17.1">Instantis EnterpriseTrack Version 17.1</FullProductName>
               </Branch>
               <Branch Name="17.2" Type="Product Version">
                  <FullProductName ProductID="P-10563V-17.2">Instantis EnterpriseTrack Version 17.2</FullProductName>
               </Branch>
               <Branch Name="17.3" Type="Product Version">
                  <FullProductName ProductID="P-10563V-17.3">Instantis EnterpriseTrack Version 17.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Primavera Gateway" Type="Product Name">
               <Branch Name="17.12.0-17.12.11" Type="Product Version">
                  <FullProductName ProductID="P-10605V-17.12.0-17.12.11">Primavera Gateway Version 17.12.0-17.12.11</FullProductName>
               </Branch>
               <Branch Name="18.8.0-18.8.11" Type="Product Version">
                  <FullProductName ProductID="P-10605V-18.8.0-18.8.11">Primavera Gateway Version 18.8.0-18.8.11</FullProductName>
               </Branch>
               <Branch Name="19.12.0-19.12.10" Type="Product Version">
                  <FullProductName ProductID="P-10605V-19.12.0-19.12.10">Primavera Gateway Version 19.12.0-19.12.10</FullProductName>
               </Branch>
               <Branch Name="20.12.0" Type="Product Version">
                  <FullProductName ProductID="P-10605V-20.12.0">Primavera Gateway Version 20.12.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Database Server" Type="Product Family">
            <Branch Name="Database - Enterprise Edition" Type="Product Name">
               <Branch Name="12.1.0.2" Type="Product Version">
                  <FullProductName ProductID="P-5V-12.1.0.2">Database - Enterprise Edition Version 12.1.0.2</FullProductName>
               </Branch>
               <Branch Name="12.2.0.1" Type="Product Version">
                  <FullProductName ProductID="P-5V-12.2.0.1">Database - Enterprise Edition Version 12.2.0.1</FullProductName>
               </Branch>
               <Branch Name="19c" Type="Product Version">
                  <FullProductName ProductID="P-5V-19c">Database - Enterprise Edition Version 19c</FullProductName>
               </Branch>
               <Branch Name="All Supported Versions" Type="Product Version">
                  <FullProductName ProductID="P-5V-All Supported Versions">Database - Enterprise Edition Version All Supported Versions</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Text" Type="Product Name">
               <Branch Name="12.1.0.2" Type="Product Version">
                  <FullProductName ProductID="P-211V-12.1.0.2">Text Version 12.1.0.2</FullProductName>
               </Branch>
               <Branch Name="12.2.0.1" Type="Product Version">
                  <FullProductName ProductID="P-211V-12.2.0.1">Text Version 12.2.0.1</FullProductName>
               </Branch>
               <Branch Name="19c" Type="Product Version">
                  <FullProductName ProductID="P-211V-19c">Text Version 19c</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Advanced Networking Option" Type="Product Name">
               <Branch Name="12.1.0.2" Type="Product Version">
                  <FullProductName ProductID="P-219V-12.1.0.2">Advanced Networking Option Version 12.1.0.2</FullProductName>
               </Branch>
               <Branch Name="12.2.0.1" Type="Product Version">
                  <FullProductName ProductID="P-219V-12.2.0.1">Advanced Networking Option Version 12.2.0.1</FullProductName>
               </Branch>
               <Branch Name="19c" Type="Product Version">
                  <FullProductName ProductID="P-219V-19c">Advanced Networking Option Version 19c</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Spatial and Graph" Type="Product Name">
               <Branch Name="12.2.0.1" Type="Product Version">
                  <FullProductName ProductID="P-619V-12.2.0.1">Spatial and Graph Version 12.2.0.1</FullProductName>
               </Branch>
               <Branch Name="19c" Type="Product Version">
                  <FullProductName ProductID="P-619V-19c">Spatial and Graph Version 19c</FullProductName>
               </Branch>
               <Branch Name="All Supported Versions" Type="Product Version">
                  <FullProductName ProductID="P-619V-All Supported Versions">Spatial and Graph Version All Supported Versions</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Universal Installer" Type="Product Name">
               <Branch Name="All Supported Versions" Type="Product Version">
                  <FullProductName ProductID="P-662V-All Supported Versions">Universal Installer Version All Supported Versions</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Application Express (APEX)" Type="Product Name">
               <Branch Name="Prior to 21.1.0.00.01" Type="Product Version">
                  <FullProductName ProductID="P-1348V-Prior to 21.1.0.00.01">Application Express (APEX) Version Prior to 21.1.0.00.01</FullProductName>
               </Branch>
               <Branch Name="Prior to 21.1.0.00.04" Type="Product Version">
                  <FullProductName ProductID="P-1348V-Prior to 21.1.0.00.04">Application Express (APEX) Version Prior to 21.1.0.00.04</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle E-Business Suite" Type="Product Family">
            <Branch Name="Public Sector Financials (International)" Type="Product Name">
               <Branch Name="12.1.1-12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-26V-12.1.1-12.1.3">Public Sector Financials (International) Version 12.1.1-12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Workflow" Type="Product Name">
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-174V-12.1.3">Workflow Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3-12.2.10" Type="Product Version">
                  <FullProductName ProductID="P-174V-12.2.3-12.2.10">Workflow Version 12.2.3-12.2.10</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="iSupplier Portal" Type="Product Name">
               <Branch Name="12.1.1-12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-208V-12.1.1-12.1.3">iSupplier Portal Version 12.1.1-12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3-12.2.10" Type="Product Version">
                  <FullProductName ProductID="P-208V-12.2.3-12.2.10">iSupplier Portal Version 12.2.3-12.2.10</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Marketing" Type="Product Name">
               <Branch Name="12.1.1-12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-229V-12.1.1-12.1.3">Marketing Version 12.1.1-12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3-12.2.10" Type="Product Version">
                  <FullProductName ProductID="P-229V-12.2.3-12.2.10">Marketing Version 12.2.3-12.2.10</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Advanced Inbound Telephony" Type="Product Name">
               <Branch Name="12.1.1-12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-265V-12.1.1-12.1.3">Advanced Inbound Telephony Version 12.1.1-12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3-12.2.10" Type="Product Version">
                  <FullProductName ProductID="P-265V-12.2.3-12.2.10">Advanced Inbound Telephony Version 12.2.3-12.2.10</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Time and Labor" Type="Product Name">
               <Branch Name="12.1.1-12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-311V-12.1.1-12.1.3">Time and Labor Version 12.1.1-12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3-12.2.10" Type="Product Version">
                  <FullProductName ProductID="P-311V-12.2.3-12.2.10">Time and Labor Version 12.2.3-12.2.10</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Human Resources" Type="Product Name">
               <Branch Name="12.1.1-12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-507V-12.1.1-12.1.3">Human Resources Version 12.1.1-12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Engineering" Type="Product Name">
               <Branch Name="12.2.3-12.2.10" Type="Product Version">
                  <FullProductName ProductID="P-532V-12.2.3-12.2.10">Engineering Version 12.2.3-12.2.10</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Field Service" Type="Product Name">
               <Branch Name="12.1.1-12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-747V-12.1.1-12.1.3">Field Service Version 12.1.1-12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Advanced Outbound Telephony" Type="Product Name">
               <Branch Name="12.1.1-12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-785V-12.1.1-12.1.3">Advanced Outbound Telephony Version 12.1.1-12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3-12.2.10" Type="Product Version">
                  <FullProductName ProductID="P-785V-12.2.3-12.2.10">Advanced Outbound Telephony Version 12.2.3-12.2.10</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Collaborative Planning" Type="Product Name">
               <Branch Name="12.1.1-12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1037V-12.1.1-12.1.3">Collaborative Planning Version 12.1.1-12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Approvals Management" Type="Product Name">
               <Branch Name="12.1.1-12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1168V-12.1.1-12.1.3">Approvals Management Version 12.1.1-12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Web Applications Desktop Integrator" Type="Product Name">
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1171V-12.1.3">Web Applications Desktop Integrator Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3-12.2.10" Type="Product Version">
                  <FullProductName ProductID="P-1171V-12.2.3-12.2.10">Web Applications Desktop Integrator Version 12.2.3-12.2.10</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Common Applications" Type="Product Name">
               <Branch Name="12.1.1-12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1198V-12.1.1-12.1.3">Common Applications Version 12.1.1-12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3-12.2.10" Type="Product Version">
                  <FullProductName ProductID="P-1198V-12.2.3-12.2.10">Common Applications Version 12.2.3-12.2.10</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="E-Records" Type="Product Name">
               <Branch Name="12.1.1-12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1325V-12.1.1-12.1.3">E-Records Version 12.1.1-12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3-12.2.10" Type="Product Version">
                  <FullProductName ProductID="P-1325V-12.2.3-12.2.10">E-Records Version 12.2.3-12.2.10</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Applications Framework" Type="Product Name">
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1472V-12.1.3">Applications Framework Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3-12.2.10" Type="Product Version">
                  <FullProductName ProductID="P-1472V-12.2.3-12.2.10">Applications Framework Version 12.2.3-12.2.10</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Enterprise Manager" Type="Product Family">
            <Branch Name="Enterprise Manager Base Platform" Type="Product Name">
               <Branch Name="13.4.0.0" Type="Product Version">
                  <FullProductName ProductID="P-1370V-13.4.0.0">Enterprise Manager Base Platform Version 13.4.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Configuration Manager" Type="Product Name">
               <Branch Name="12.1.2.0.8" Type="Product Version">
                  <FullProductName ProductID="P-1967V-12.1.2.0.8">Configuration Manager Version 12.1.2.0.8</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Application Testing Suite" Type="Product Name">
               <Branch Name="13.3.0.1" Type="Product Version">
                  <FullProductName ProductID="P-4622V-13.3.0.1">Application Testing Suite Version 13.3.0.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Essbase" Type="Product Family">
            <Branch Name="Hyperion Analytic Provider Services" Type="Product Name">
               <Branch Name="11.1.2.4" Type="Product Version">
                  <FullProductName ProductID="P-4349V-11.1.2.4">Hyperion Analytic Provider Services Version 11.1.2.4</FullProductName>
               </Branch>
               <Branch Name="21.2" Type="Product Version">
                  <FullProductName ProductID="P-4349V-21.2">Hyperion Analytic Provider Services Version 21.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Hyperion Essbase" Type="Product Name">
               <Branch Name="21.2" Type="Product Version">
                  <FullProductName ProductID="P-4379V-21.2">Hyperion Essbase Version 21.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Hyperion Essbase Administration Services" Type="Product Name">
               <Branch Name="11.1.2.4" Type="Product Version">
                  <FullProductName ProductID="P-4380V-11.1.2.4">Hyperion Essbase Administration Services Version 11.1.2.4</FullProductName>
               </Branch>
               <Branch Name="21.2" Type="Product Version">
                  <FullProductName ProductID="P-4380V-21.2">Hyperion Essbase Administration Services Version 21.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Financial Services Applications" Type="Product Family">
            <Branch Name="Financial Services Analytical Applications Infrastructure" Type="Product Name">
               <Branch Name="8.0.6-8.0.9" Type="Product Version">
                  <FullProductName ProductID="P-5680V-8.0.6-8.0.9">Financial Services Analytical Applications Infrastructure Version 8.0.6-8.0.9</FullProductName>
               </Branch>
               <Branch Name="8.1.0" Type="Product Version">
                  <FullProductName ProductID="P-5680V-8.1.0">Financial Services Analytical Applications Infrastructure Version 8.1.0</FullProductName>
               </Branch>
               <Branch Name="8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-5680V-8.1.1">Financial Services Analytical Applications Infrastructure Version 8.1.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="FLEXCUBE Universal Banking" Type="Product Name">
               <Branch Name="12.0-12.4" Type="Product Version">
                  <FullProductName ProductID="P-9052V-12.0-12.4">FLEXCUBE Universal Banking Version 12.0-12.4</FullProductName>
               </Branch>
               <Branch Name="12.3" Type="Product Version">
                  <FullProductName ProductID="P-9052V-12.3">FLEXCUBE Universal Banking Version 12.3</FullProductName>
               </Branch>
               <Branch Name="12.4" Type="Product Version">
                  <FullProductName ProductID="P-9052V-12.4">FLEXCUBE Universal Banking Version 12.4</FullProductName>
               </Branch>
               <Branch Name="14.0-14.4" Type="Product Version">
                  <FullProductName ProductID="P-9052V-14.0-14.4">FLEXCUBE Universal Banking Version 14.0-14.4</FullProductName>
               </Branch>
               <Branch Name="14.1.0-14.4.0" Type="Product Version">
                  <FullProductName ProductID="P-9052V-14.1.0-14.4.0">FLEXCUBE Universal Banking Version 14.1.0-14.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="FLEXCUBE Private Banking" Type="Product Name">
               <Branch Name="12.0.0" Type="Product Version">
                  <FullProductName ProductID="P-9110V-12.0.0">FLEXCUBE Private Banking Version 12.0.0</FullProductName>
               </Branch>
               <Branch Name="12.1.0" Type="Product Version">
                  <FullProductName ProductID="P-9110V-12.1.0">FLEXCUBE Private Banking Version 12.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Banking Platform" Type="Product Name">
               <Branch Name="2.12.0" Type="Product Version">
                  <FullProductName ProductID="P-9178V-2.12.0">Banking Platform Version 2.12.0</FullProductName>
               </Branch>
               <Branch Name="2.4.0" Type="Product Version">
                  <FullProductName ProductID="P-9178V-2.4.0">Banking Platform Version 2.4.0</FullProductName>
               </Branch>
               <Branch Name="2.7.1" Type="Product Version">
                  <FullProductName ProductID="P-9178V-2.7.1">Banking Platform Version 2.7.1</FullProductName>
               </Branch>
               <Branch Name="2.9.0" Type="Product Version">
                  <FullProductName ProductID="P-9178V-2.9.0">Banking Platform Version 2.9.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Revenue Management and Billing Analytics" Type="Product Name">
               <Branch Name="2.7.0" Type="Product Version">
                  <FullProductName ProductID="P-11527V-2.7.0">Financial Services Revenue Management and Billing Analytics Version 2.7.0</FullProductName>
               </Branch>
               <Branch Name="2.8.0" Type="Product Version">
                  <FullProductName ProductID="P-11527V-2.8.0">Financial Services Revenue Management and Billing Analytics Version 2.8.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Regulatory Reporting with AgileREPORTER" Type="Product Name">
               <Branch Name="8.0.9.6.3" Type="Product Version">
                  <FullProductName ProductID="P-13077V-8.0.9.6.3">Financial Services Regulatory Reporting with AgileREPORTER Version 8.0.9.6.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Banking Liquidity Management" Type="Product Name">
               <Branch Name="14.2" Type="Product Version">
                  <FullProductName ProductID="P-13304V-14.2">Banking Liquidity Management Version 14.2</FullProductName>
               </Branch>
               <Branch Name="14.3" Type="Product Version">
                  <FullProductName ProductID="P-13304V-14.3">Banking Liquidity Management Version 14.3</FullProductName>
               </Branch>
               <Branch Name="14.5" Type="Product Version">
                  <FullProductName ProductID="P-13304V-14.5">Banking Liquidity Management Version 14.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Banking Enterprise Default Management" Type="Product Name">
               <Branch Name="2.10.0" Type="Product Version">
                  <FullProductName ProductID="P-13390V-2.10.0">Banking Enterprise Default Management Version 2.10.0</FullProductName>
               </Branch>
               <Branch Name="2.12.0" Type="Product Version">
                  <FullProductName ProductID="P-13390V-2.12.0">Banking Enterprise Default Management Version 2.12.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Banking Party Management" Type="Product Name">
               <Branch Name="2.7.0" Type="Product Version">
                  <FullProductName ProductID="P-13929V-2.7.0">Banking Party Management Version 2.7.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Crime and Compliance Investigation Hub" Type="Product Name">
               <Branch Name="20.1.2" Type="Product Version">
                  <FullProductName ProductID="P-13964V-20.1.2">Financial Services Crime and Compliance Investigation Hub Version 20.1.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Banking Treasury Management" Type="Product Name">
               <Branch Name="14.4" Type="Product Version">
                  <FullProductName ProductID="P-14133V-14.4">Banking Treasury Management Version 14.4</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Food and Beverage Applications" Type="Product Family">
            <Branch Name="Hospitality Reporting and Analytics" Type="Product Name">
               <Branch Name="9.1.0" Type="Product Version">
                  <FullProductName ProductID="P-11599V-9.1.0">Hospitality Reporting and Analytics Version 9.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="MICROS Workstation 6" Type="Product Name">
               <Branch Name="610-655" Type="Product Version">
                  <FullProductName ProductID="P-11628V-610-655">MICROS Workstation 6 Version 610-655</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="MICROS Workstation 5A" Type="Product Name">
               <Branch Name="5A" Type="Product Version">
                  <FullProductName ProductID="P-11636V-5A">MICROS Workstation 5A Version 5A</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="MICROS Kitchen Display System Hardware" Type="Product Name">
               <Branch Name="210" Type="Product Version">
                  <FullProductName ProductID="P-11641V-210">MICROS Kitchen Display System Hardware Version 210</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="MICROS Compact Workstation 3" Type="Product Name">
               <Branch Name="310" Type="Product Version">
                  <FullProductName ProductID="P-13794V-310">MICROS Compact Workstation 3 Version 310</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="MICROS ES400 Series" Type="Product Name">
               <Branch Name="400-410" Type="Product Version">
                  <FullProductName ProductID="P-14212V-400-410">MICROS ES400 Series Version 400-410</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Fusion Middleware" Type="Product Family">
            <Branch Name="JDeveloper" Type="Product Name">
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-807V-12.2.1.4.0">JDeveloper Version 12.2.1.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Fusion Middleware MapViewer" Type="Product Name">
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-1215V-12.2.1.4.0">Fusion Middleware MapViewer Version 12.2.1.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="BI Publisher (formerly XML Publisher)" Type="Product Name">
               <Branch Name="11.1.1.9.0" Type="Product Version">
                  <FullProductName ProductID="P-1479V-11.1.1.9.0">BI Publisher (formerly XML Publisher) Version 11.1.1.9.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1479V-12.2.1.3.0">BI Publisher (formerly XML Publisher) Version 12.2.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-1479V-12.2.1.4.0">BI Publisher (formerly XML Publisher) Version 12.2.1.4.0</FullProductName>
               </Branch>
               <Branch Name="5.5.0.0.0" Type="Product Version">
                  <FullProductName ProductID="P-1479V-5.5.0.0.0">BI Publisher (formerly XML Publisher) Version 5.5.0.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="BAM (Business Activity Monitoring)" Type="Product Name">
               <Branch Name="11.1.1.9.0" Type="Product Version">
                  <FullProductName ProductID="P-1675V-11.1.1.9.0">BAM (Business Activity Monitoring) Version 11.1.1.9.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1675V-12.2.1.3.0">BAM (Business Activity Monitoring) Version 12.2.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-1675V-12.2.1.4.0">BAM (Business Activity Monitoring) Version 12.2.1.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="WebCenter Portal" Type="Product Name">
               <Branch Name="11.1.1.9.0" Type="Product Version">
                  <FullProductName ProductID="P-1696V-11.1.1.9.0">WebCenter Portal Version 11.1.1.9.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1696V-12.2.1.3.0">WebCenter Portal Version 12.2.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-1696V-12.2.1.4.0">WebCenter Portal Version 12.2.1.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Identity Manager" Type="Product Name">
               <Branch Name="11.1.2.2.0" Type="Product Version">
                  <FullProductName ProductID="P-1980V-11.1.2.2.0">Identity Manager Version 11.1.2.2.0</FullProductName>
               </Branch>
               <Branch Name="11.1.2.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1980V-11.1.2.3.0">Identity Manager Version 11.1.2.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1980V-12.2.1.3.0">Identity Manager Version 12.2.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-1980V-12.2.1.4.0">Identity Manager Version 12.2.1.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Business Intelligence Enterprise Edition" Type="Product Name">
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-2025V-12.2.1.4.0">Business Intelligence Enterprise Edition Version 12.2.1.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Data Integrator" Type="Product Name">
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-2196V-12.2.1.3.0">Data Integrator Version 12.2.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-2196V-12.2.1.4.0">Data Integrator Version 12.2.1.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Outside In Technology" Type="Product Name">
               <Branch Name="8.5.5" Type="Product Version">
                  <FullProductName ProductID="P-2276V-8.5.5">Outside In Technology Version 8.5.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Coherence" Type="Product Name">
               <Branch Name="12.1.3.0.0" Type="Product Version">
                  <FullProductName ProductID="P-2545V-12.1.3.0.0">Coherence Version 12.1.3.0.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-2545V-12.2.1.3.0">Coherence Version 12.2.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-2545V-12.2.1.4.0">Coherence Version 12.2.1.4.0</FullProductName>
               </Branch>
               <Branch Name="14.1.1.0.0" Type="Product Version">
                  <FullProductName ProductID="P-2545V-14.1.1.0.0">Coherence Version 14.1.1.0.0</FullProductName>
               </Branch>
               <Branch Name="3.7.1.0" Type="Product Version">
                  <FullProductName ProductID="P-2545V-3.7.1.0">Coherence Version 3.7.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Real-Time Decisions (RTD) Solutions" Type="Product Name">
               <Branch Name="3.2.0.0" Type="Product Version">
                  <FullProductName ProductID="P-4509V-3.2.0.0">Real-Time Decisions (RTD) Solutions Version 3.2.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="WebLogic Server" Type="Product Name">
               <Branch Name="10.3.6.0.0" Type="Product Version">
                  <FullProductName ProductID="P-5242V-10.3.6.0.0">WebLogic Server Version 10.3.6.0.0</FullProductName>
               </Branch>
               <Branch Name="12.1.3.0.0" Type="Product Version">
                  <FullProductName ProductID="P-5242V-12.1.3.0.0">WebLogic Server Version 12.1.3.0.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-5242V-12.2.1.3.0">WebLogic Server Version 12.2.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-5242V-12.2.1.4.0">WebLogic Server Version 12.2.1.4.0</FullProductName>
               </Branch>
               <Branch Name="14.1.1.0.0" Type="Product Version">
                  <FullProductName ProductID="P-5242V-14.1.1.0.0">WebLogic Server Version 14.1.1.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Enterprise Repository" Type="Product Name">
               <Branch Name="11.1.1.7.0" Type="Product Version">
                  <FullProductName ProductID="P-5326V-11.1.1.7.0">Enterprise Repository Version 11.1.1.7.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Access Manager" Type="Product Name">
               <Branch Name="11.1.2.3.0" Type="Product Version">
                  <FullProductName ProductID="P-5565V-11.1.2.3.0">Access Manager Version 11.1.2.3.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="GoldenGate Big Data and Application Adapters" Type="Product Name">
               <Branch Name="19.1.0.0.0" Type="Product Version">
                  <FullProductName ProductID="P-5760V-19.1.0.0.0">GoldenGate Big Data and Application Adapters Version 19.1.0.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Enterprise Data Quality" Type="Product Name">
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-9464V-12.2.1.3.0">Enterprise Data Quality Version 12.2.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-9464V-12.2.1.4.0">Enterprise Data Quality Version 12.2.1.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Managed File Transfer" Type="Product Name">
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-10198V-12.2.1.3.0">Managed File Transfer Version 12.2.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-10198V-12.2.1.4.0">Managed File Transfer Version 12.2.1.4.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Hospitality Applications" Type="Product Family">
            <Branch Name="MICROS BellaVita" Type="Product Name">
               <Branch Name="8.13" Type="Product Version">
                  <FullProductName ProductID="P-12614V-8.13">MICROS BellaVita Version 8.13</FullProductName>
               </Branch>
               <Branch Name="8.14" Type="Product Version">
                  <FullProductName ProductID="P-12614V-8.14">MICROS BellaVita Version 8.14</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Hyperion" Type="Product Family">
            <Branch Name="Hyperion BI+" Type="Product Name">
               <Branch Name="11.1.2.4" Type="Product Version">
                  <FullProductName ProductID="P-4361V-11.1.2.4">Hyperion BI+ Version 11.1.2.4</FullProductName>
               </Branch>
               <Branch Name="11.2.5.0" Type="Product Version">
                  <FullProductName ProductID="P-4361V-11.2.5.0">Hyperion BI+ Version 11.2.5.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Hyperion Infrastructure Technology" Type="Product Name">
               <Branch Name="11.1.2.4" Type="Product Version">
                  <FullProductName ProductID="P-4392V-11.1.2.4">Hyperion Infrastructure Technology Version 11.1.2.4</FullProductName>
               </Branch>
               <Branch Name="11.2.5.0" Type="Product Version">
                  <FullProductName ProductID="P-4392V-11.2.5.0">Hyperion Infrastructure Technology Version 11.2.5.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Hyperion Financial Reporting" Type="Product Name">
               <Branch Name="11.1.2.4" Type="Product Version">
                  <FullProductName ProductID="P-8776V-11.1.2.4">Hyperion Financial Reporting Version 11.1.2.4</FullProductName>
               </Branch>
               <Branch Name="11.2.5.0" Type="Product Version">
                  <FullProductName ProductID="P-8776V-11.2.5.0">Hyperion Financial Reporting Version 11.2.5.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Insurance Applications" Type="Product Family">
            <Branch Name="Insurance Policy Administration J2EE" Type="Product Name">
               <Branch Name="11.0.2" Type="Product Version">
                  <FullProductName ProductID="P-5279V-11.0.2">Insurance Policy Administration J2EE Version 11.0.2</FullProductName>
               </Branch>
               <Branch Name="11.1.0-11.3.0" Type="Product Version">
                  <FullProductName ProductID="P-5279V-11.1.0-11.3.0">Insurance Policy Administration J2EE Version 11.1.0-11.3.0</FullProductName>
               </Branch>
               <Branch Name="11.2.0" Type="Product Version">
                  <FullProductName ProductID="P-5279V-11.2.0">Insurance Policy Administration J2EE Version 11.2.0</FullProductName>
               </Branch>
               <Branch Name="11.3.0" Type="Product Version">
                  <FullProductName ProductID="P-5279V-11.3.0">Insurance Policy Administration J2EE Version 11.3.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Insurance Rules Palette" Type="Product Name">
               <Branch Name="11.0.2" Type="Product Version">
                  <FullProductName ProductID="P-5288V-11.0.2">Insurance Rules Palette Version 11.0.2</FullProductName>
               </Branch>
               <Branch Name="11.1.0-11.3.0" Type="Product Version">
                  <FullProductName ProductID="P-5288V-11.1.0-11.3.0">Insurance Rules Palette Version 11.1.0-11.3.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle JD Edwards" Type="Product Family">
            <Branch Name="JD Edwards EnterpriseOne Tools" Type="Product Name">
               <Branch Name="9.2.5.3 and Prior" Type="Product Version">
                  <FullProductName ProductID="P-4781V-9.2.5.3 and Prior">JD Edwards EnterpriseOne Tools Version 9.2.5.3 and Prior</FullProductName>
               </Branch>
               <Branch Name="9.2.5.3 and prior" Type="Product Version">
                  <FullProductName ProductID="P-4781V-9.2.5.3 and prior">JD Edwards EnterpriseOne Tools Version 9.2.5.3 and prior</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="JD Edwards EnterpriseOne Orchestrator" Type="Product Name">
               <Branch Name="9.2.5.3 and Prior" Type="Product Version">
                  <FullProductName ProductID="P-11681V-9.2.5.3 and Prior">JD Edwards EnterpriseOne Orchestrator Version 9.2.5.3 and Prior</FullProductName>
               </Branch>
               <Branch Name="9.2.5.3 and prior" Type="Product Version">
                  <FullProductName ProductID="P-11681V-9.2.5.3 and prior">JD Edwards EnterpriseOne Orchestrator Version 9.2.5.3 and prior</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Java SE" Type="Product Family">
            <Branch Name="Java SE JDK and JRE" Type="Product Name">
               <Branch Name="Java SE:11.0.11" Type="Product Version">
                  <FullProductName ProductID="P-856V-Java SE:11.0.11">Java SE JDK and JRE Version Java SE:11.0.11</FullProductName>
               </Branch>
               <Branch Name="Java SE:16.0.1" Type="Product Version">
                  <FullProductName ProductID="P-856V-Java SE:16.0.1">Java SE JDK and JRE Version Java SE:16.0.1</FullProductName>
               </Branch>
               <Branch Name="Java SE:7u301" Type="Product Version">
                  <FullProductName ProductID="P-856V-Java SE:7u301">Java SE JDK and JRE Version Java SE:7u301</FullProductName>
               </Branch>
               <Branch Name="Java SE:8u291" Type="Product Version">
                  <FullProductName ProductID="P-856V-Java SE:8u291">Java SE JDK and JRE Version Java SE:8u291</FullProductName>
               </Branch>
               <Branch Name="Oracle GraalVM Enterprise Edition:20.3.2" Type="Product Version">
                  <FullProductName ProductID="P-13497V-Oracle GraalVM Enterprise Edition:20.3.2">Java SE JDK and JRE Version Oracle GraalVM Enterprise Edition:20.3.2</FullProductName>
               </Branch>
               <Branch Name="Oracle GraalVM Enterprise Edition:21.1.0" Type="Product Version">
                  <FullProductName ProductID="P-13497V-Oracle GraalVM Enterprise Edition:21.1.0">Java SE JDK and JRE Version Oracle GraalVM Enterprise Edition:21.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="GraalVM Enterprise Edition" Type="Product Name">
               <Branch Name="Oracle GraalVM Enterprise Edition:20.3.2" Type="Product Version">
                  <FullProductName ProductID="P-13497V-Oracle GraalVM Enterprise Edition:20.3.2">GraalVM Enterprise Edition Version Oracle GraalVM Enterprise Edition:20.3.2</FullProductName>
               </Branch>
               <Branch Name="Oracle GraalVM Enterprise Edition:21.1.0" Type="Product Version">
                  <FullProductName ProductID="P-13497V-Oracle GraalVM Enterprise Edition:21.1.0">GraalVM Enterprise Edition Version Oracle GraalVM Enterprise Edition:21.1.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle MySQL" Type="Product Family">
            <Branch Name="MySQL Server" Type="Product Name">
               <Branch Name="5.7.34 and prior" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.7.34 and prior">MySQL Server Version 5.7.34 and prior</FullProductName>
               </Branch>
               <Branch Name="8.0.21 and prior" Type="Product Version">
                  <FullProductName ProductID="P-8478V-8.0.21 and prior">MySQL Server Version 8.0.21 and prior</FullProductName>
               </Branch>
               <Branch Name="8.0.23 and prior" Type="Product Version">
                  <FullProductName ProductID="P-8478V-8.0.23 and prior">MySQL Server Version 8.0.23 and prior</FullProductName>
               </Branch>
               <Branch Name="8.0.25 and prior" Type="Product Version">
                  <FullProductName ProductID="P-8478V-8.0.25 and prior">MySQL Server Version 8.0.25 and prior</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="MySQL Cluster" Type="Product Name">
               <Branch Name="8.0.25 and prior" Type="Product Version">
                  <FullProductName ProductID="P-8479V-8.0.25 and prior">MySQL Cluster Version 8.0.25 and prior</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="MySQL Enterprise Monitor" Type="Product Name">
               <Branch Name="8.0.23 and prior" Type="Product Version">
                  <FullProductName ProductID="P-8480V-8.0.23 and prior">MySQL Enterprise Monitor Version 8.0.23 and prior</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="MySQL Connectors" Type="Product Name">
               <Branch Name="8.0.23 and prior" Type="Product Version">
                  <FullProductName ProductID="P-8576V-8.0.23 and prior">MySQL Connectors Version 8.0.23 and prior</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle PeopleSoft" Type="Product Family">
            <Branch Name="PeopleSoft Enterprise HCM Candidate Gateway" Type="Product Name">
               <Branch Name="9.2" Type="Product Version">
                  <FullProductName ProductID="P-5043V-9.2">PeopleSoft Enterprise HCM Candidate Gateway Version 9.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="PeopleSoft Enterprise PT PeopleTools" Type="Product Name">
               <Branch Name="8.57" Type="Product Version">
                  <FullProductName ProductID="P-5085V-8.57">PeopleSoft Enterprise PT PeopleTools Version 8.57</FullProductName>
               </Branch>
               <Branch Name="8.58" Type="Product Version">
                  <FullProductName ProductID="P-5085V-8.58">PeopleSoft Enterprise PT PeopleTools Version 8.58</FullProductName>
               </Branch>
               <Branch Name="8.58. 8.59" Type="Product Version">
                  <FullProductName ProductID="P-5085V-8.58. 8.59">PeopleSoft Enterprise PT PeopleTools Version 8.58. 8.59</FullProductName>
               </Branch>
               <Branch Name="8.59" Type="Product Version">
                  <FullProductName ProductID="P-5085V-8.59">PeopleSoft Enterprise PT PeopleTools Version 8.59</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="PeopleSoft Enterprise CS Campus Community" Type="Product Name">
               <Branch Name="9.0" Type="Product Version">
                  <FullProductName ProductID="P-5183V-9.0">PeopleSoft Enterprise CS Campus Community Version 9.0</FullProductName>
               </Branch>
               <Branch Name="9.2" Type="Product Version">
                  <FullProductName ProductID="P-5183V-9.2">PeopleSoft Enterprise CS Campus Community Version 9.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="PeopleSoft Enterprise HCM Shared Components" Type="Product Name">
               <Branch Name="9.2" Type="Product Version">
                  <FullProductName ProductID="P-8943V-9.2">PeopleSoft Enterprise HCM Shared Components Version 9.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Policy Automation" Type="Product Family">
            <Branch Name="Policy Automation" Type="Product Name">
               <Branch Name="12.2.0-12.2.22" Type="Product Version">
                  <FullProductName ProductID="P-5624V-12.2.0-12.2.22">Policy Automation Version 12.2.0-12.2.22</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Retail Applications" Type="Product Family">
            <Branch Name="Retail Integration Bus" Type="Product Name">
               <Branch Name="14.1.3.2" Type="Product Version">
                  <FullProductName ProductID="P-1807V-14.1.3.2">Retail Integration Bus Version 14.1.3.2</FullProductName>
               </Branch>
               <Branch Name="15.0.3.1" Type="Product Version">
                  <FullProductName ProductID="P-1807V-15.0.3.1">Retail Integration Bus Version 15.0.3.1</FullProductName>
               </Branch>
               <Branch Name="16.0.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1807V-16.0.3.0">Retail Integration Bus Version 16.0.3.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Merchandising System" Type="Product Name">
               <Branch Name="14.1.3.2" Type="Product Version">
                  <FullProductName ProductID="P-1816V-14.1.3.2">Retail Merchandising System Version 14.1.3.2</FullProductName>
               </Branch>
               <Branch Name="15.0.3.1" Type="Product Version">
                  <FullProductName ProductID="P-1816V-15.0.3.1">Retail Merchandising System Version 15.0.3.1</FullProductName>
               </Branch>
               <Branch Name="16.0.3" Type="Product Version">
                  <FullProductName ProductID="P-1816V-16.0.3">Retail Merchandising System Version 16.0.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Price Management" Type="Product Name">
               <Branch Name="14.0" Type="Product Version">
                  <FullProductName ProductID="P-1824V-14.0">Retail Price Management Version 14.0</FullProductName>
               </Branch>
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-1824V-14.1">Retail Price Management Version 14.1</FullProductName>
               </Branch>
               <Branch Name="15.0" Type="Product Version">
                  <FullProductName ProductID="P-1824V-15.0">Retail Price Management Version 15.0</FullProductName>
               </Branch>
               <Branch Name="16.0" Type="Product Version">
                  <FullProductName ProductID="P-1824V-16.0">Retail Price Management Version 16.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Back Office" Type="Product Name">
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-2013V-14.1">Retail Back Office Version 14.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Central Office" Type="Product Name">
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-2016V-14.1">Retail Central Office Version 14.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Point-of-Service" Type="Product Name">
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-2017V-14.1">Retail Point-of-Service Version 14.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Returns Management" Type="Product Name">
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-2020V-14.1">Retail Returns Management Version 14.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Financial Integration" Type="Product Name">
               <Branch Name="14.1.3.2" Type="Product Version">
                  <FullProductName ProductID="P-10722V-14.1.3.2">Retail Financial Integration Version 14.1.3.2</FullProductName>
               </Branch>
               <Branch Name="15.0.3.1" Type="Product Version">
                  <FullProductName ProductID="P-10722V-15.0.3.1">Retail Financial Integration Version 15.0.3.1</FullProductName>
               </Branch>
               <Branch Name="16.0.3.0" Type="Product Version">
                  <FullProductName ProductID="P-10722V-16.0.3.0">Retail Financial Integration Version 16.0.3.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Service Backbone" Type="Product Name">
               <Branch Name="14.1.3.2" Type="Product Version">
                  <FullProductName ProductID="P-10867V-14.1.3.2">Retail Service Backbone Version 14.1.3.2</FullProductName>
               </Branch>
               <Branch Name="15.0.3.1" Type="Product Version">
                  <FullProductName ProductID="P-10867V-15.0.3.1">Retail Service Backbone Version 15.0.3.1</FullProductName>
               </Branch>
               <Branch Name="16.0.3.0" Type="Product Version">
                  <FullProductName ProductID="P-10867V-16.0.3.0">Retail Service Backbone Version 16.0.3.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Xstore Point of Service" Type="Product Name">
               <Branch Name="16.0.6" Type="Product Version">
                  <FullProductName ProductID="P-11513V-16.0.6">Retail Xstore Point of Service Version 16.0.6</FullProductName>
               </Branch>
               <Branch Name="17.0.4" Type="Product Version">
                  <FullProductName ProductID="P-11513V-17.0.4">Retail Xstore Point of Service Version 17.0.4</FullProductName>
               </Branch>
               <Branch Name="18.0.3" Type="Product Version">
                  <FullProductName ProductID="P-11513V-18.0.3">Retail Xstore Point of Service Version 18.0.3</FullProductName>
               </Branch>
               <Branch Name="19.0.2" Type="Product Version">
                  <FullProductName ProductID="P-11513V-19.0.2">Retail Xstore Point of Service Version 19.0.2</FullProductName>
               </Branch>
               <Branch Name="20.0.1" Type="Product Version">
                  <FullProductName ProductID="P-11513V-20.0.1">Retail Xstore Point of Service Version 20.0.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Customer Management and Segmentation Foundation Cloud Service" Type="Product Name">
               <Branch Name="16.0-19.0" Type="Product Version">
                  <FullProductName ProductID="P-11518V-16.0-19.0">Retail Customer Management and Segmentation Foundation Cloud Service Version 16.0-19.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Order Management System Cloud Service" Type="Product Name">
               <Branch Name="19.5" Type="Product Version">
                  <FullProductName ProductID="P-11519V-19.5">Retail Order Management System Cloud Service Version 19.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Order Broker Cloud Service" Type="Product Name">
               <Branch Name="15.0" Type="Product Version">
                  <FullProductName ProductID="P-11520V-15.0">Retail Order Broker Cloud Service Version 15.0</FullProductName>
               </Branch>
               <Branch Name="16.0" Type="Product Version">
                  <FullProductName ProductID="P-11520V-16.0">Retail Order Broker Cloud Service Version 16.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Customer Management and Segmentation Foundation" Type="Product Name">
               <Branch Name="16.0-19.0" Type="Product Version">
                  <FullProductName ProductID="P-13388V-16.0-19.0">Retail Customer Management and Segmentation Foundation Version 16.0-19.0</FullProductName>
               </Branch>
               <Branch Name="19.0" Type="Product Version">
                  <FullProductName ProductID="P-13388V-19.0">Retail Customer Management and Segmentation Foundation Version 19.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Siebel CRM" Type="Product Family">
            <Branch Name="Siebel Apps - Marketing" Type="Product Name">
               <Branch Name="21.5 and Prior" Type="Product Version">
                  <FullProductName ProductID="P-8974V-21.5 and Prior">Siebel Apps - Marketing Version 21.5 and Prior</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Siebel Core - Automation" Type="Product Name">
               <Branch Name="21.5 and Prior" Type="Product Version">
                  <FullProductName ProductID="P-8988V-21.5 and Prior">Siebel Core - Automation Version 21.5 and Prior</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Siebel Core - Server Framework" Type="Product Name">
               <Branch Name="21.5 and Prior" Type="Product Version">
                  <FullProductName ProductID="P-9001V-21.5 and Prior">Siebel Core - Server Framework Version 21.5 and Prior</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Supply Chain" Type="Product Family">
            <Branch Name="Transportation Management" Type="Product Name">
               <Branch Name="6.4.3" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.4.3">Transportation Management Version 6.4.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Agile Engineering Data Management" Type="Product Name">
               <Branch Name="6.2.1.0" Type="Product Version">
                  <FullProductName ProductID="P-4436V-6.2.1.0">Agile Engineering Data Management Version 6.2.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Agile PLM Framework" Type="Product Name">
               <Branch Name="9.3.3" Type="Product Version">
                  <FullProductName ProductID="P-4461V-9.3.3">Agile PLM Framework Version 9.3.3</FullProductName>
               </Branch>
               <Branch Name="9.3.5" Type="Product Version">
                  <FullProductName ProductID="P-4461V-9.3.5">Agile PLM Framework Version 9.3.5</FullProductName>
               </Branch>
               <Branch Name="9.3.6" Type="Product Version">
                  <FullProductName ProductID="P-4461V-9.3.6">Agile PLM Framework Version 9.3.6</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Support Tools" Type="Product Family">
            <Branch Name="OSS Support Tools" Type="Product Name">
               <Branch Name="Prior to 2.12.41" Type="Product Version">
                  <FullProductName ProductID="P-1330V-Prior to 2.12.41">OSS Support Tools Version Prior to 2.12.41</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Systems" Type="Product Family">
            <Branch Name="Solaris Cluster" Type="Product Name">
               <Branch Name="4.4" Type="Product Version">
                  <FullProductName ProductID="P-10005V-4.4">Solaris Cluster Version 4.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Solaris Operating System" Type="Product Name">
               <Branch Name="11" Type="Product Version">
                  <FullProductName ProductID="P-10006V-11">Solaris Operating System Version 11</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Sun ZFS Storage Appliance Kit (AK) Software" Type="Product Name">
               <Branch Name="8.8" Type="Product Version">
                  <FullProductName ProductID="P-10026V-8.8">Sun ZFS Storage Appliance Kit (AK) Software Version 8.8</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Tape General STA - StorageTek Tape Analytics SW Tool" Type="Product Name">
               <Branch Name="2.3" Type="Product Version">
                  <FullProductName ProductID="P-10085V-2.3">Tape General STA - StorageTek Tape Analytics SW Tool Version 2.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Fujitsu SPARC Servers Firmware" Type="Product Name">
               <Branch Name="Prior to XCP2400" Type="Product Version">
                  <FullProductName ProductID="P-10656V-Prior to XCP2400">Fujitsu SPARC Servers Firmware Version Prior to XCP2400</FullProductName>
               </Branch>
               <Branch Name="prior to XCP3100" Type="Product Version">
                  <FullProductName ProductID="P-10656V-prior to XCP3100">Fujitsu SPARC Servers Firmware Version prior to XCP3100</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Virtualization" Type="Product Family">
            <Branch Name="VM VirtualBox" Type="Product Name">
               <Branch Name="Prior to 6.1.24" Type="Product Version">
                  <FullProductName ProductID="P-8370V-Prior to 6.1.24">VM VirtualBox Version Prior to 6.1.24</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Secure Global Desktop" Type="Product Name">
               <Branch Name="5.6" Type="Product Version">
                  <FullProductName ProductID="P-8539V-5.6">Secure Global Desktop Version 5.6</FullProductName>
               </Branch>
            </Branch>
         </Branch>
      </Branch>
   </ProductTree>
   <Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0881</Title>
      <Notes>
         <Note Audience="All" Ordinal="1" Title="Details" Type="Details">Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: UI Infrastructure (Apache Xerces2 Java Parser)).   The supported version that is affected is 6.4.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Transportation Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Transportation Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0881</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1991V-6.4.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Transportation Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787997.1</URL>
            <ProductID>P-1991V-6.4.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0254</Title>
      <Notes>
         <Note Audience="All" Ordinal="2" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Third Party Tools (Apache Standard Taglibs)).  Supported versions that are affected are 10.3.6.0.0 and  12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as  unauthorized read access to a subset of Oracle WebLogic Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0254</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.3.6.0.0</ProductID>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-5242V-10.3.6.0.0</ProductID>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="3" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0762</Title>
      <Notes>
         <Note Audience="All" Ordinal="3" Title="Details" Type="Details">Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) product of Oracle Communications (component: Provisioning  (Apache Tomcat)).  Supported versions that are affected are 8.0.0-8.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router (DSR).  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Diameter Signaling Router (DSR) accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0762</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10899V-8.0.0-8.5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Diameter Signaling Router (DSR)</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787208.1</URL>
            <ProductID>P-10899V-8.0.0-8.5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="4" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-4429</Title>
      <Notes>
         <Note Audience="All" Ordinal="4" Title="Details" Type="Details">Vulnerability in the Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers product of Oracle Systems (component: XCP Firmware (glibc)).  Supported versions that are affected are Prior to XCP2400 and  prior to XCP3100. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-4429</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10656V-Prior to XCP2400</ProductID>
            <ProductID>P-10656V-prior to XCP3100</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Fujitsu SPARC Servers Firmware</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788472.1</URL>
            <ProductID>P-10656V-Prior to XCP2400</ProductID>
            <ProductID>P-10656V-prior to XCP3100</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="5" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-14735</Title>
      <Notes>
         <Note Audience="All" Ordinal="5" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework (AntiSamy)).   The supported version that is affected is 13.4.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Enterprise Manager Base Platform, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Enterprise Manager Base Platform accessible data as well as  unauthorized read access to a subset of Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-14735</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-13.4.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Enterprise Manager Base Platform</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-1370V-13.4.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="6" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-14735</Title>
      <Notes>
         <Note Audience="All" Ordinal="6" Title="Details" Type="Details">Vulnerability in the Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Security (AntiSamy)).  Supported versions that are affected are 11.1.2.4 and  11.2.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Infrastructure Technology.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Hyperion Infrastructure Technology, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Hyperion Infrastructure Technology accessible data as well as  unauthorized read access to a subset of Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-14735</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4392V-11.1.2.4</ProductID>
            <ProductID>P-4392V-11.2.5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Hyperion Infrastructure Technology</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-4392V-11.1.2.4</ProductID>
            <ProductID>P-4392V-11.2.5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="7" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-16931</Title>
      <Notes>
         <Note Audience="All" Ordinal="7" Title="Details" Type="Details">Vulnerability in the Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers product of Oracle Systems (component: XCP Firmware (libxml2)).  Supported versions that are affected are Prior to XCP2400 and  prior to XCP3100. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers.  Successful attacks of this vulnerability can result in takeover of Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-16931</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10656V-Prior to XCP2400</ProductID>
            <ProductID>P-10656V-prior to XCP3100</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Fujitsu SPARC Servers Firmware</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788472.1</URL>
            <ProductID>P-10656V-Prior to XCP2400</ProductID>
            <ProductID>P-10656V-prior to XCP3100</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="8" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5461</Title>
      <Notes>
         <Note Audience="All" Ordinal="8" Title="Details" Type="Details">Vulnerability in the Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers product of Oracle Systems (component: XCP Firmware (NSS)).  Supported versions that are affected are Prior to XCP2400 and  prior to XCP3100. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers.  Successful attacks of this vulnerability can result in takeover of Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5461</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10656V-Prior to XCP2400</ProductID>
            <ProductID>P-10656V-prior to XCP3100</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Fujitsu SPARC Servers Firmware</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788472.1</URL>
            <ProductID>P-10656V-Prior to XCP2400</ProductID>
            <ProductID>P-10656V-prior to XCP3100</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="9" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5637</Title>
      <Notes>
         <Note Audience="All" Ordinal="9" Title="Details" Type="Details">Vulnerability in the Siebel Core - Server Framework product of Oracle Siebel CRM (component: Cloud Gateway (Zookeeper)).  Supported versions that are affected are 21.5 and Prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Core - Server Framework.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel Core - Server Framework. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5637</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9001V-21.5 and Prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Siebel Core - Server Framework</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787995.1</URL>
            <ProductID>P-9001V-21.5 and Prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="10" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-9735</Title>
      <Notes>
         <Note Audience="All" Ordinal="10" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Configuration (Jetty)).   The supported version that is affected is 1.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-9735</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14277V-1.5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Policy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2791658.1</URL>
            <ProductID>P-14277V-1.5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="11" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2018-0739</Title>
      <Notes>
         <Note Audience="All" Ordinal="11" Title="Details" Type="Details">Vulnerability in the Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers product of Oracle Systems (component: XCP Firmware (OpenSSL)).  Supported versions that are affected are Prior to XCP2400 and  prior to XCP3100. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2018-0739</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10656V-Prior to XCP2400</ProductID>
            <ProductID>P-10656V-prior to XCP3100</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Fujitsu SPARC Servers Firmware</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788472.1</URL>
            <ProductID>P-10656V-Prior to XCP2400</ProductID>
            <ProductID>P-10656V-prior to XCP3100</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="12" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2018-15686</Title>
      <Notes>
         <Note Audience="All" Ordinal="12" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: Signaling (Calico)).   The supported version that is affected is 1.4.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Network Function Cloud Native Environment executes to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Function Cloud Native Environment. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2018-15686</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14125V-1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Network Function Cloud Native Environment</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2791656.1</URL>
            <ProductID>P-14125V-1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="13" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2018-7183</Title>
      <Notes>
         <Note Audience="All" Ordinal="13" Title="Details" Type="Details">Vulnerability in the Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers product of Oracle Systems (component: XCP Firmware (NTP)).  Supported versions that are affected are Prior to XCP2400 and  prior to XCP3100. Easily exploitable vulnerability allows unauthenticated attacker with network access via NTP to compromise Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers.  Successful attacks of this vulnerability can result in takeover of Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2018-7183</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10656V-Prior to XCP2400</ProductID>
            <ProductID>P-10656V-prior to XCP3100</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Fujitsu SPARC Servers Firmware</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788472.1</URL>
            <ProductID>P-10656V-Prior to XCP2400</ProductID>
            <ProductID>P-10656V-prior to XCP3100</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="14" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-0190</Title>
      <Notes>
         <Note Audience="All" Ordinal="14" Title="Details" Type="Details">Vulnerability in the Essbase product of Oracle Essbase (component: Infrastructure (OpenSSL)).   The supported version that is affected is 21.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Essbase.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Essbase. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-0190</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4379V-21.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Hyperion Essbase</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-4379V-21.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="15" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-0219</Title>
      <Notes>
         <Note Audience="All" Ordinal="15" Title="Details" Type="Details">Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Apache cordova-plugin-inappbrowser)).  Supported versions that are affected are 16.0.6, 
17.0.4, 
18.0.3 and 
19.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-0219</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11513V-16.0.6</ProductID>
            <ProductID>P-11513V-17.0.4</ProductID>
            <ProductID>P-11513V-18.0.3</ProductID>
            <ProductID>P-11513V-19.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Xstore Point of Service</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783353.1</URL>
            <ProductID>P-11513V-16.0.6</ProductID>
            <ProductID>P-11513V-17.0.4</ProductID>
            <ProductID>P-11513V-18.0.3</ProductID>
            <ProductID>P-11513V-19.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="16" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-0228</Title>
      <Notes>
         <Note Audience="All" Ordinal="16" Title="Details" Type="Details">Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Onboarding (Apache PDFbox)).  Supported versions that are affected are 14.2, 14.3 and  14.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Liquidity Management.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Liquidity Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-0228</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13304V-14.2</ProductID>
            <ProductID>P-13304V-14.3</ProductID>
            <ProductID>P-13304V-14.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Liquidity Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-13304V-14.2</ProductID>
            <ProductID>P-13304V-14.3</ProductID>
            <ProductID>P-13304V-14.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="17" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-10086</Title>
      <Notes>
         <Note Audience="All" Ordinal="17" Title="Details" Type="Details">Vulnerability in the Oracle Application Testing Suite product of Oracle Enterprise Manager (component: Load Testing for Web Apps (Apache Commons BeanUtils)).   The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Testing Suite.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Application Testing Suite accessible data as well as  unauthorized read access to a subset of Oracle Application Testing Suite accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Application Testing Suite. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-10086</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4622V-13.3.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Application Testing Suite</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-4622V-13.3.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="18" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-10086</Title>
      <Notes>
         <Note Audience="All" Ordinal="18" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Signaling (Apache Commons BeanUtils)).   The supported version that is affected is 1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Console accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Console accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-10086</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14250V-1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Console</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2791671.1</URL>
            <ProductID>P-14250V-1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="19" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-10086</Title>
      <Notes>
         <Note Audience="All" Ordinal="19" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Measurements (Apache Commons BeanUtils)).   The supported version that is affected is 1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Policy accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Policy accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-10086</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14277V-1.9.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Policy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2791658.1</URL>
            <ProductID>P-14277V-1.9.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="20" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-10086</Title>
      <Notes>
         <Note Audience="All" Ordinal="20" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Measurements (Apache Commons BeanUtils)).   The supported version that is affected is 1.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Unified Data Repository accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Unified Data Repository accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-10086</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14119V-1.6.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Unified Data Repository</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2791683.1</URL>
            <ProductID>P-14119V-1.6.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="21" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-10086</Title>
      <Notes>
         <Note Audience="All" Ordinal="21" Title="Details" Type="Details">Vulnerability in the Oracle Communications Evolved Communications Application Server product of Oracle Communications (component: Managing and Using Subscriber Data (Apache Commons BeanUtils)).   The supported version that is affected is 7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Evolved Communications Application Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Evolved Communications Application Server accessible data as well as  unauthorized read access to a subset of Oracle Communications Evolved Communications Application Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Evolved Communications Application Server. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-10086</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10994V-7.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Evolved Communications Application Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787205.1</URL>
            <ProductID>P-10994V-7.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="22" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-10086</Title>
      <Notes>
         <Note Audience="All" Ordinal="22" Title="Details" Type="Details">Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications Applications (component: Transformation for PDC (Apache Commons BeanUtils)).   The supported version that is affected is 12.0.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Pricing Design Center.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Pricing Design Center accessible data as well as  unauthorized read access to a subset of Oracle Communications Pricing Design Center accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Pricing Design Center. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-10086</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9437V-12.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Pricing Design Center</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2785183.1</URL>
            <ProductID>P-9437V-12.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="23" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-10086</Title>
      <Notes>
         <Note Audience="All" Ordinal="23" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Revenue Management and Billing Analytics product of Oracle Financial Services Applications (component: Dashboards (Apache Commons BeanUtils)).  Supported versions that are affected are 2.7.0 and  2.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Revenue Management and Billing Analytics.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Revenue Management and Billing Analytics accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Revenue Management and Billing Analytics accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Financial Services Revenue Management and Billing Analytics. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-10086</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11527V-2.7.0</ProductID>
            <ProductID>P-11527V-2.8.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Financial Services Revenue Management and Billing Analytics</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2767127.1</URL>
            <ProductID>P-11527V-2.7.0</ProductID>
            <ProductID>P-11527V-2.8.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="24" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-10086</Title>
      <Notes>
         <Note Audience="All" Ordinal="24" Title="Details" Type="Details">Vulnerability in the Real-Time Decisions (RTD) Solutions product of Oracle Fusion Middleware (component: WLS Deployment Template for RT (Apache Commons BeanUtils)).   The supported version that is affected is 3.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Real-Time Decisions (RTD) Solutions.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Real-Time Decisions (RTD) Solutions accessible data as well as  unauthorized read access to a subset of Real-Time Decisions (RTD) Solutions accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Real-Time Decisions (RTD) Solutions. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-10086</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4509V-3.2.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Real-Time Decisions (RTD) Solutions</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-4509V-3.2.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="25" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-10086</Title>
      <Notes>
         <Note Audience="All" Ordinal="25" Title="Details" Type="Details">Vulnerability in the Oracle Retail Merchandising System product of Oracle Retail Applications (component: Foundation (Apache Commons BeanUtils)).   The supported version that is affected is 15.0.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Merchandising System.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Retail Merchandising System accessible data as well as  unauthorized read access to a subset of Oracle Retail Merchandising System accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Merchandising System. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-10086</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1816V-15.0.3.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Merchandising System</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783353.1</URL>
            <ProductID>P-1816V-15.0.3.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="26" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-10086</Title>
      <Notes>
         <Note Audience="All" Ordinal="26" Title="Details" Type="Details">Vulnerability in the Oracle Retail Price Management product of Oracle Retail Applications (component: Manage Allocation (Apache Commons BeanUtils)).  Supported versions that are affected are 14.0, 14.1, 15.0 and  16.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Price Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Retail Price Management accessible data as well as  unauthorized read access to a subset of Oracle Retail Price Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Price Management. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-10086</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1824V-14.0</ProductID>
            <ProductID>P-1824V-14.1</ProductID>
            <ProductID>P-1824V-15.0</ProductID>
            <ProductID>P-1824V-16.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Price Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783353.1</URL>
            <ProductID>P-1824V-14.0</ProductID>
            <ProductID>P-1824V-14.1</ProductID>
            <ProductID>P-1824V-15.0</ProductID>
            <ProductID>P-1824V-16.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="27" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-10086</Title>
      <Notes>
         <Note Audience="All" Ordinal="27" Title="Details" Type="Details">Vulnerability in the Oracle Solaris Cluster product of Oracle Systems (component: Application Integration (Apache Commons BeanUtils)).   The supported version that is affected is 4.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Solaris Cluster.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Solaris Cluster accessible data as well as  unauthorized read access to a subset of Oracle Solaris Cluster accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Solaris Cluster. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-10086</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10005V-4.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Solaris Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788472.1</URL>
            <ProductID>P-10005V-4.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="28" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-10746</Title>
      <Notes>
         <Note Audience="All" Ordinal="28" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: Configuration (Kibana)).   The supported version that is affected is 1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Function Cloud Native Environment. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-10746</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14125V-1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Network Function Cloud Native Environment</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2791656.1</URL>
            <ProductID>P-14125V-1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="29" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-11358</Title>
      <Notes>
         <Note Audience="All" Ordinal="29" Title="Details" Type="Details">Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: UI Platform (jQuery)).   The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Identity Manager, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Identity Manager accessible data as well as  unauthorized read access to a subset of Identity Manager accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-11358</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1980V-12.2.1.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Identity Manager</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-1980V-12.2.1.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="30" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-12260</Title>
      <Notes>
         <Note Audience="All" Ordinal="30" Title="Details" Type="Details">Vulnerability in the Oracle Communications EAGLE Software product of Oracle Communications (component: Measurements (VxWorks)).  Supported versions that are affected are 46.6.0-46.8.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Software.  Successful attacks of this vulnerability can result in takeover of Oracle Communications EAGLE Software. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-12260</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10768V-46.6.0-46.8.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications EAGLE (Software)</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787243.1</URL>
            <ProductID>P-10768V-46.6.0-46.8.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="31" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-12399</Title>
      <Notes>
         <Note Audience="All" Ordinal="31" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Measurements (Apache Kafka)).   The supported version that is affected is 1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-12399</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14277V-1.9.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Policy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2791658.1</URL>
            <ProductID>P-14277V-1.9.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="32" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-12402</Title>
      <Notes>
         <Note Audience="All" Ordinal="32" Title="Details" Type="Details">Vulnerability in the Essbase product of Oracle Essbase (component: Infrastructure (Apache Commons Compress)).   The supported version that is affected is 21.2. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Essbase executes to compromise Essbase.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Essbase accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Essbase. CVSS 3.1 Base Score 4.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-12402</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4379V-21.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.1</BaseScore>
            <Vector>AV:A/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Hyperion Essbase</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-4379V-21.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="33" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-12402</Title>
      <Notes>
         <Note Audience="All" Ordinal="33" Title="Details" Type="Details">Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Oracle JDeveloper (Apache Commons Compress)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle JDeveloper. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-12402</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-807V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>JDeveloper</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-807V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="34" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-12415</Title>
      <Notes>
         <Note Audience="All" Ordinal="34" Title="Details" Type="Details">Security-in-Depth issue in the Oracle Database Migration Assistant for Unicode (Apache POI) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-12415</CVE>
      <ProductStatuses>
         <Status Type="Known Not Affected">
            <ProductID>P-5V-All Supported Versions</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Database - Enterprise Edition</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-5V-All Supported Versions</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="35" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-12415</Title>
      <Notes>
         <Note Audience="All" Ordinal="35" Title="Details" Type="Details">Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: OAM (Apache POI)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle JDeveloper executes to compromise Oracle JDeveloper.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-12415</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-807V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>JDeveloper</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-807V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="36" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-13990</Title>
      <Notes>
         <Note Audience="All" Ordinal="36" Title="Details" Type="Details">Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security  (Quartz)).  Supported versions that are affected are 9.2.5.3 and Prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Orchestrator.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Orchestrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-13990</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11681V-9.2.5.3 and Prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>JD Edwards EnterpriseOne Orchestrator</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787996.1</URL>
            <ProductID>P-11681V-9.2.5.3 and Prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="37" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17195</Title>
      <Notes>
         <Note Audience="All" Ordinal="37" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Nimbus JOSE+JWT)).   The supported version that is affected is 1.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17195</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14123V-1.7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Security Edge Protection Proxy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2791680.1</URL>
            <ProductID>P-14123V-1.7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="38" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17195</Title>
      <Notes>
         <Note Audience="All" Ordinal="38" Title="Details" Type="Details">Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications Applications (component: CNE (Nimbus JOSE+JWT)).   The supported version that is affected is 12.0.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Pricing Design Center.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Pricing Design Center. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17195</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9437V-12.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Pricing Design Center</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2785183.1</URL>
            <ProductID>P-9437V-12.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="39" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17195</Title>
      <Notes>
         <Note Audience="All" Ordinal="39" Title="Details" Type="Details">Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Runtime Java agent for ODI (Nimbus JOSE+JWT)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Data Integrator.  Successful attacks of this vulnerability can result in takeover of Oracle Data Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17195</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2196V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Data Integrator</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-2196V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="40" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17195</Title>
      <Notes>
         <Note Audience="All" Ordinal="40" Title="Details" Type="Details">Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security (Nimbus JOSE+JWT)).  Supported versions that are affected are 9.2.5.3 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Orchestrator.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Orchestrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17195</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11681V-9.2.5.3 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>JD Edwards EnterpriseOne Orchestrator</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787996.1</URL>
            <ProductID>P-11681V-9.2.5.3 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="41" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17195</Title>
      <Notes>
         <Note Audience="All" Ordinal="41" Title="Details" Type="Details">Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Inf SEC (Nimbus JOSE+JWT)).  Supported versions that are affected are 9.2.5.3 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17195</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4781V-9.2.5.3 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>JD Edwards EnterpriseOne Tools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787996.1</URL>
            <ProductID>P-4781V-9.2.5.3 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="42" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17195</Title>
      <Notes>
         <Note Audience="All" Ordinal="42" Title="Details" Type="Details">Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC (Nimbus JOSE+JWT)).  Supported versions that are affected are 9.2.5.3 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17195</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4781V-9.2.5.3 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>JD Edwards EnterpriseOne Tools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787996.1</URL>
            <ProductID>P-4781V-9.2.5.3 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="43" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17195</Title>
      <Notes>
         <Note Audience="All" Ordinal="43" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: REST Services (Nimbus JOSE+JWT)).  Supported versions that are affected are 8.58 and  8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17195</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>PeopleSoft Enterprise PT PeopleTools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788006.1</URL>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="44" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17195</Title>
      <Notes>
         <Note Audience="All" Ordinal="44" Title="Details" Type="Details">Vulnerability in Oracle Policy Automation (component: Hub (Nimbus JOSE+JWT)).  Supported versions that are affected are 12.2.0-12.2.22. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Policy Automation.  Successful attacks of this vulnerability can result in takeover of Oracle Policy Automation. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17195</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5624V-12.2.0-12.2.22</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Policy Automation</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2782105.1</URL>
            <ProductID>P-5624V-12.2.0-12.2.22</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="45" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17195</Title>
      <Notes>
         <Note Audience="All" Ordinal="45" Title="Details" Type="Details">Vulnerability in the Primavera Gateway product of Oracle Construction and Engineering (component: Admin (Nimbus JOSE+JWT)).  Supported versions that are affected are 18.8.0-18.8.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Gateway.  Successful attacks of this vulnerability can result in takeover of Primavera Gateway. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17195</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10605V-18.8.0-18.8.11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera Gateway</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783281.1</URL>
            <ProductID>P-10605V-18.8.0-18.8.11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="46" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17543</Title>
      <Notes>
         <Note Audience="All" Ordinal="46" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Compiling (LZ4)).  Supported versions that are affected are 5.7.34 and prior and  8.0.25 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in takeover of MySQL Server. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17543</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.34 and prior</ProductID>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-5.7.34 and prior</ProductID>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="47" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17545</Title>
      <Notes>
         <Note Audience="All" Ordinal="47" Title="Details" Type="Details">Vulnerability in the Oracle Spatial and Graph (GDAL) component of Oracle Database Server.  Supported versions that are affected are 12.2.0.1 and  19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session privilege with logon to the infrastructure where Oracle Spatial and Graph (GDAL) executes to compromise Oracle Spatial and Graph (GDAL).  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Spatial and Graph (GDAL). CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17545</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-619V-12.2.0.1</ProductID>
            <ProductID>P-619V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.4</BaseScore>
            <Vector>AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Spatial and Graph</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-619V-12.2.0.1</ProductID>
            <ProductID>P-619V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="48" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17566</Title>
      <Notes>
         <Note Audience="All" Ordinal="48" Title="Details" Type="Details">Vulnerability in the Oracle Communications Offline Mediation Controller product of Oracle Communications Applications (component: CN OCOMC (Apache Batik)).   The supported version that is affected is 12.0.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Offline Mediation Controller.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Offline Mediation Controller accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17566</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2269V-12.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Offline Mediation Controller</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2785182.1</URL>
            <ProductID>P-2269V-12.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="49" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17566</Title>
      <Notes>
         <Note Audience="All" Ordinal="49" Title="Details" Type="Details">Vulnerability in the Hyperion Financial Reporting product of Oracle Hyperion (component: Installation (Apache Batik)).  Supported versions that are affected are 11.1.2.4 and  11.2.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Financial Reporting.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17566</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8776V-11.1.2.4</ProductID>
            <ProductID>P-8776V-11.2.5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Hyperion Financial Reporting</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-8776V-11.1.2.4</ProductID>
            <ProductID>P-8776V-11.2.5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="50" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-2729</Title>
      <Notes>
         <Note Audience="All" Ordinal="50" Title="Details" Type="Details">Vulnerability in the Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration (Oracle WebLogic Server)).  Supported versions that are affected are 11.1.2.4 and  11.2.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in takeover of Hyperion Infrastructure Technology. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-2729</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4392V-11.1.2.4</ProductID>
            <ProductID>P-4392V-11.2.5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Hyperion Infrastructure Technology</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-4392V-11.1.2.4</ProductID>
            <ProductID>P-4392V-11.2.5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="51" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-2897</Title>
      <Notes>
         <Note Audience="All" Ordinal="51" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management).   The supported version that is affected is 13.4.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Enterprise Manager Base Platform accessible data as well as  unauthorized access to critical data or complete access to all Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-2897</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-13.4.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.4</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Enterprise Manager Base Platform</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-1370V-13.4.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="52" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-2897</Title>
      <Notes>
         <Note Audience="All" Ordinal="52" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: System Monitoring).   The supported version that is affected is 13.4.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Enterprise Manager Base Platform accessible data as well as  unauthorized access to critical data or complete access to all Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-2897</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-13.4.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.4</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Enterprise Manager Base Platform</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-1370V-13.4.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="53" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-3740</Title>
      <Notes>
         <Note Audience="All" Ordinal="53" Title="Details" Type="Details">Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Inventory Organizer (BSAFE Crypto-J)).  Supported versions that are affected are 7.3.2, 7.3.4, 7.3.5, 7.4.0 and  7.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Inventory Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-3740</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4516V-7.3.2</ProductID>
            <ProductID>P-4516V-7.3.4</ProductID>
            <ProductID>P-4516V-7.3.5</ProductID>
            <ProductID>P-4516V-7.4.0</ProductID>
            <ProductID>P-4516V-7.4.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Unified Inventory Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2785180.1</URL>
            <ProductID>P-4516V-7.3.2</ProductID>
            <ProductID>P-4516V-7.3.4</ProductID>
            <ProductID>P-4516V-7.3.5</ProductID>
            <ProductID>P-4516V-7.4.0</ProductID>
            <ProductID>P-4516V-7.4.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="54" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-3740</Title>
      <Notes>
         <Note Audience="All" Ordinal="54" Title="Details" Type="Details">Vulnerability in the StorageTek Tape Analytics SW Tool product of Oracle Systems (component: Software (BSAFE Crypto-J)).   The supported version that is affected is 2.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise StorageTek Tape Analytics SW Tool.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all StorageTek Tape Analytics SW Tool accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-3740</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10085V-2.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Tape General STA - StorageTek Tape Analytics SW Tool</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788472.1</URL>
            <ProductID>P-10085V-2.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="55" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-5064</Title>
      <Notes>
         <Note Audience="All" Ordinal="55" Title="Details" Type="Details">Vulnerability in the Big Data Spatial and Graph product of Oracle Big Data Graph (component: Big Data Graph (OpenCV)).   The supported version that is affected is Prior to 2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Big Data Spatial and Graph.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Big Data Spatial and Graph. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-5064</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11528V-Prior to 2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Big Data Spatial and Graph</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-11528V-Prior to 2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="56" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-5064</Title>
      <Notes>
         <Note Audience="All" Ordinal="56" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Application Service Level Mgmt (OpenCV)).   The supported version that is affected is 13.4.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-5064</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-13.4.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Enterprise Manager Base Platform</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-1370V-13.4.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="57" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-10543</Title>
      <Notes>
         <Note Audience="All" Ordinal="57" Title="Details" Type="Details">Vulnerability in the Oracle SD-WAN Edge product of Oracle Communications (component: Publications (Perl)).  Supported versions that are affected are 8.2, 9.0 and  9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SD-WAN Edge.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle SD-WAN Edge as well as  unauthorized update, insert or delete access to some of Oracle SD-WAN Edge accessible data and  unauthorized read access to a subset of Oracle SD-WAN Edge accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-10543</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13940V-8.2</ProductID>
            <ProductID>P-13940V-9.0</ProductID>
            <ProductID>P-13940V-9.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>SD-WAN Edge</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787240.1</URL>
            <ProductID>P-13940V-8.2</ProductID>
            <ProductID>P-13940V-9.0</ProductID>
            <ProductID>P-13940V-9.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="58" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-10683</Title>
      <Notes>
         <Note Audience="All" Ordinal="58" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Application Service Level Mgmt (dom4j)).   The supported version that is affected is 13.4.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in takeover of Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-10683</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-13.4.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Enterprise Manager Base Platform</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-1370V-13.4.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="59" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-10683</Title>
      <Notes>
         <Note Audience="All" Ordinal="59" Title="Details" Type="Details">Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Oracle JDeveloper (dom4j)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper.  Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-10683</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-807V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>JDeveloper</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-807V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="60" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-10683</Title>
      <Notes>
         <Note Audience="All" Ordinal="60" Title="Details" Type="Details">Vulnerability in the StorageTek Tape Analytics SW Tool product of Oracle Systems (component: Software (dom4j)).   The supported version that is affected is 2.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise StorageTek Tape Analytics SW Tool.  Successful attacks of this vulnerability can result in takeover of StorageTek Tape Analytics SW Tool. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-10683</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10085V-2.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Tape General STA - StorageTek Tape Analytics SW Tool</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788472.1</URL>
            <ProductID>P-10085V-2.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="61" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-10878</Title>
      <Notes>
         <Note Audience="All" Ordinal="61" Title="Details" Type="Details">Vulnerability in the Oracle Communications Offline Mediation Controller product of Oracle Communications Applications (component: UDC CORE (Perl)).   The supported version that is affected is 12.0.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP/IP to compromise Oracle Communications Offline Mediation Controller.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Offline Mediation Controller as well as  unauthorized update, insert or delete access to some of Oracle Communications Offline Mediation Controller accessible data and  unauthorized read access to a subset of Oracle Communications Offline Mediation Controller accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-10878</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2269V-12.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Offline Mediation Controller</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2785182.1</URL>
            <ProductID>P-2269V-12.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="62" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-10878</Title>
      <Notes>
         <Note Audience="All" Ordinal="62" Title="Details" Type="Details">Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications Applications (component: Transformation for PDC (Perl)).   The supported version that is affected is 12.0.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Pricing Design Center.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Pricing Design Center as well as  unauthorized update, insert or delete access to some of Oracle Communications Pricing Design Center accessible data and  unauthorized read access to a subset of Oracle Communications Pricing Design Center accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-10878</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9437V-12.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Pricing Design Center</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2785183.1</URL>
            <ProductID>P-9437V-12.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="63" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-10878</Title>
      <Notes>
         <Note Audience="All" Ordinal="63" Title="Details" Type="Details">Vulnerability in the Oracle Configuration Manager product of Oracle Enterprise Manager (component: Content Server (Perl)).   The supported version that is affected is 12.1.2.0.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configuration Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Configuration Manager as well as  unauthorized update, insert or delete access to some of Oracle Configuration Manager accessible data and  unauthorized read access to a subset of Oracle Configuration Manager accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-10878</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1967V-12.1.2.0.8</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Configuration Manager</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-1967V-12.1.2.0.8</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="64" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-10878</Title>
      <Notes>
         <Note Audience="All" Ordinal="64" Title="Details" Type="Details">Vulnerability in the Oracle SD-WAN Aware product of Oracle Communications (component: Monitoring (Perl)).  Supported versions that are affected are 8.2 and  9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SD-WAN Aware.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle SD-WAN Aware as well as  unauthorized update, insert or delete access to some of Oracle SD-WAN Aware accessible data and  unauthorized read access to a subset of Oracle SD-WAN Aware accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-10878</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13941V-8.2</ProductID>
            <ProductID>P-13941V-9.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>SD-WAN Aware</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787244.1</URL>
            <ProductID>P-13941V-8.2</ProductID>
            <ProductID>P-13941V-9.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="65" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-10878</Title>
      <Notes>
         <Note Audience="All" Ordinal="65" Title="Details" Type="Details">Security-in-Depth issue in the RDBMS (Perl) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-10878</CVE>
      <ProductStatuses>
         <Status Type="Known Not Affected">
            <ProductID>P-662V-All Supported Versions</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Universal Installer</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-662V-All Supported Versions</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="66" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="66" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Revenue Management and Billing Analytics product of Oracle Financial Services Applications (component: Dashboards (jQuery)).  Supported versions that are affected are 2.7.0 and  2.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Revenue Management and Billing Analytics.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Revenue Management and Billing Analytics, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Revenue Management and Billing Analytics accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Revenue Management and Billing Analytics accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11527V-2.7.0</ProductID>
            <ProductID>P-11527V-2.8.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Financial Services Revenue Management and Billing Analytics</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2767127.1</URL>
            <ProductID>P-11527V-2.7.0</ProductID>
            <ProductID>P-11527V-2.8.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="67" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11023</Title>
      <Notes>
         <Note Audience="All" Ordinal="67" Title="Details" Type="Details">Vulnerability in the OSS Support Tools product of Oracle Support Tools (component: Diagnostic Assistant (jQuery)).   The supported version that is affected is Prior to 2.12.41. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise OSS Support Tools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in OSS Support Tools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of OSS Support Tools accessible data as well as  unauthorized read access to a subset of OSS Support Tools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11023</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1330V-Prior to 2.12.41</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>OSS Support Tools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787969.1</URL>
            <ProductID>P-1330V-Prior to 2.12.41</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="68" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11612</Title>
      <Notes>
         <Note Audience="All" Ordinal="68" Title="Details" Type="Details">Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications Applications (component: HTTP GW (Netty)).   The supported version that is affected is 12.0.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in takeover of Oracle Communications BRM - Elastic Charging Engine. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11612</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9742V-12.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications BRM - Elastic Charging Engine</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2785183.1</URL>
            <ProductID>P-9742V-12.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="69" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11612</Title>
      <Notes>
         <Note Audience="All" Ordinal="69" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: KPI (Netty)).   The supported version that is affected is 1.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11612</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14117V-1.5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Service Communication Proxy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2791682.1</URL>
            <ProductID>P-14117V-1.5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="70" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11979</Title>
      <Notes>
         <Note Audience="All" Ordinal="70" Title="Details" Type="Details">Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Installation Issues (Apache Ant)).   The supported version that is affected is 6.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Agile Engineering Data Management accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11979</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4436V-6.2.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Agile Engineering Data Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787997.1</URL>
            <ProductID>P-4436V-6.2.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="71" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11979</Title>
      <Notes>
         <Note Audience="All" Ordinal="71" Title="Details" Type="Details">Vulnerability in the Oracle Banking Treasury Management product of Oracle Financial Services Applications (component: Capital Workflow (Apache Ant)).   The supported version that is affected is 14.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Treasury Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Treasury Management accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11979</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14133V-14.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Treasury Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-14133V-14.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="72" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11979</Title>
      <Notes>
         <Note Audience="All" Ordinal="72" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Private Banking product of Oracle Financial Services Applications (component: Order Management (Apache Ant)).  Supported versions that are affected are 12.0.0 and  12.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle FLEXCUBE Private Banking accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11979</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9110V-12.0.0</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>FLEXCUBE Private Banking</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-9110V-12.0.0</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="73" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11979</Title>
      <Notes>
         <Note Audience="All" Ordinal="73" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Rate Management (Apache Ant)).  Supported versions that are affected are 8.0.6-8.0.9, 8.1.0 and  8.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11979</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5680V-8.0.6-8.0.9</ProductID>
            <ProductID>P-5680V-8.1.0</ProductID>
            <ProductID>P-5680V-8.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Financial Services Analytical Applications Infrastructure</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787723.1</URL>
            <ProductID>P-5680V-8.0.6-8.0.9</ProductID>
            <ProductID>P-5680V-8.1.0</ProductID>
            <ProductID>P-5680V-8.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="74" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11979</Title>
      <Notes>
         <Note Audience="All" Ordinal="74" Title="Details" Type="Details">Vulnerability in the Oracle Retail Merchandising System product of Oracle Retail Applications (component: Procurement (Apache Ant)).   The supported version that is affected is 14.1.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Merchandising System.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Merchandising System accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11979</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1816V-14.1.3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Merchandising System</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783353.1</URL>
            <ProductID>P-1816V-14.1.3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="75" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11987</Title>
      <Notes>
         <Note Audience="All" Ordinal="75" Title="Details" Type="Details">Vulnerability in the Oracle Communications Offline Mediation Controller product of Oracle Communications Applications (component: UDC CORE (Apache Batik)).   The supported version that is affected is 12.0.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP/IP to compromise Oracle Communications Offline Mediation Controller.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Offline Mediation Controller accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11987</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2269V-12.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Offline Mediation Controller</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2785182.1</URL>
            <ProductID>P-2269V-12.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="76" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11987</Title>
      <Notes>
         <Note Audience="All" Ordinal="76" Title="Details" Type="Details">Vulnerability in the Oracle Enterprise Repository product of Oracle Fusion Middleware (component: Security Subsystem - 12c (Apache Batik)).   The supported version that is affected is 11.1.1.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Repository.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Enterprise Repository accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11987</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5326V-11.1.1.7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Enterprise Repository</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-5326V-11.1.1.7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="77" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11987</Title>
      <Notes>
         <Note Audience="All" Ordinal="77" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: General Ledger (Apache Batik)).  Supported versions that are affected are 14.1.0-14.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle FLEXCUBE Universal Banking accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11987</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9052V-14.1.0-14.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>FLEXCUBE Universal Banking</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-9052V-14.1.0-14.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="78" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11987</Title>
      <Notes>
         <Note Audience="All" Ordinal="78" Title="Details" Type="Details">Vulnerability in the Oracle Fusion Middleware MapViewer product of Oracle Fusion Middleware (component: Install (Apache Batik)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Fusion Middleware MapViewer.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Fusion Middleware MapViewer accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11987</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1215V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Fusion Middleware MapViewer</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-1215V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="79" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11987</Title>
      <Notes>
         <Note Audience="All" Ordinal="79" Title="Details" Type="Details">Vulnerability in the Oracle Retail Order Broker product of Oracle Retail Applications (component: Store Connect (Apache Batik)).  Supported versions that are affected are 15.0 and  16.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Order Broker.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Retail Order Broker accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11987</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11520V-15.0</ProductID>
            <ProductID>P-11520V-16.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Order Broker Cloud Service</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783353.1</URL>
            <ProductID>P-11520V-15.0</ProductID>
            <ProductID>P-11520V-16.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="80" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11987</Title>
      <Notes>
         <Note Audience="All" Ordinal="80" Title="Details" Type="Details">Vulnerability in the Oracle Retail Order Management System Cloud Service product of Oracle Retail Applications (component: Internal Operations (Apache Batik)).   The supported version that is affected is 19.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Order Management System Cloud Service.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Retail Order Management System Cloud Service accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11987</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11519V-19.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Order Management System Cloud Service</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783353.1</URL>
            <ProductID>P-11519V-19.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="81" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11987</Title>
      <Notes>
         <Note Audience="All" Ordinal="81" Title="Details" Type="Details">Security-in-Depth issue in the Oracle Spatial and Graph MapViewer (Apache Batik) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11987</CVE>
      <ProductStatuses>
         <Status Type="Known Not Affected">
            <ProductID>P-619V-All Supported Versions</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Spatial and Graph</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-619V-All Supported Versions</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="82" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11988</Title>
      <Notes>
         <Note Audience="All" Ordinal="82" Title="Details" Type="Details">Security-in-Depth issue in the Oracle Spatial and Graph MapViewer (Apache XMLGraphics Commons) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11988</CVE>
      <ProductStatuses>
         <Status Type="Known Not Affected">
            <ProductID>P-619V-All Supported Versions</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Spatial and Graph</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-619V-All Supported Versions</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="83" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11998</Title>
      <Notes>
         <Note Audience="All" Ordinal="83" Title="Details" Type="Details">Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) product of Oracle Communications (component: Provisioning (Apache ActiveMQ)).  Supported versions that are affected are 8.0.0-8.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router (DSR).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Signaling Router (DSR). CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11998</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10899V-8.0.0-8.5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Diameter Signaling Router (DSR)</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787208.1</URL>
            <ProductID>P-10899V-8.0.0-8.5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="84" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11998</Title>
      <Notes>
         <Note Audience="All" Ordinal="84" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Private Banking product of Oracle Financial Services Applications (component: Financial Planning (Apache ActiveMQ)).  Supported versions that are affected are 12.0.0 and  12.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking.  Successful attacks of this vulnerability can result in takeover of Oracle FLEXCUBE Private Banking. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11998</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9110V-12.0.0</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>FLEXCUBE Private Banking</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-9110V-12.0.0</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="85" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-13935</Title>
      <Notes>
         <Note Audience="All" Ordinal="85" Title="Details" Type="Details">Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Installation Issues (Apache Tomcat)).   The supported version that is affected is 6.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-13935</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4436V-6.2.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Agile Engineering Data Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787997.1</URL>
            <ProductID>P-4436V-6.2.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="86" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-13956</Title>
      <Notes>
         <Note Audience="All" Ordinal="86" Title="Details" Type="Details">Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Install, config, upgrade (Apache HttpClient)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Data Integrator.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Data Integrator accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-13956</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2196V-12.2.1.3.0</ProductID>
            <ProductID>P-2196V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Data Integrator</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-2196V-12.2.1.3.0</ProductID>
            <ProductID>P-2196V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="87" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-13956</Title>
      <Notes>
         <Note Audience="All" Ordinal="87" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Cloud Manager (Apache HttpClient)).  Supported versions that are affected are 8.57, 8.58 and  8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PT PeopleTools accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-13956</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>PeopleSoft Enterprise PT PeopleTools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788006.1</URL>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="88" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-13956</Title>
      <Notes>
         <Note Audience="All" Ordinal="88" Title="Details" Type="Details">Security-in-Depth issue in the Oracle Spatial and Graph MapViewer (Apache HttpClient) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-13956</CVE>
      <ProductStatuses>
         <Status Type="Known Not Affected">
            <ProductID>P-619V-All Supported Versions</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Spatial and Graph</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-619V-All Supported Versions</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="89" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14195</Title>
      <Notes>
         <Note Audience="All" Ordinal="89" Title="Details" Type="Details">Vulnerability in the Oracle Communications Instant Messaging Server product of Oracle Communications Applications (component: Managing Messages (jackson-databind)).   The supported version that is affected is 10.0.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Instant Messaging Server.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Instant Messaging Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14195</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8495V-10.0.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Instant Messaging Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2786444.1</URL>
            <ProductID>P-8495V-10.0.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="90" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-17521</Title>
      <Notes>
         <Note Audience="All" Ordinal="90" Title="Details" Type="Details">Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications Applications (component: Elastic charging controller (Apache Groovy)).  Supported versions that are affected are 11.3.0.9.0 and 
12.0.0.3.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications BRM - Elastic Charging Engine executes to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications BRM - Elastic Charging Engine accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-17521</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9742V-11.3.0.9.0</ProductID>
            <ProductID>P-9742V-12.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications BRM - Elastic Charging Engine</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2785183.1</URL>
            <ProductID>P-9742V-11.3.0.9.0</ProductID>
            <ProductID>P-9742V-12.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="91" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-17521</Title>
      <Notes>
         <Note Audience="All" Ordinal="91" Title="Details" Type="Details">Vulnerability in the Oracle Communications Evolved Communications Application Server product of Oracle Communications (component: Control Engine (Apache Groovy)).   The supported version that is affected is 7.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Evolved Communications Application Server executes to compromise Oracle Communications Evolved Communications Application Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Evolved Communications Application Server accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-17521</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10994V-7.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Evolved Communications Application Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787205.1</URL>
            <ProductID>P-10994V-7.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="92" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-17527</Title>
      <Notes>
         <Note Audience="All" Ordinal="92" Title="Details" Type="Details">Vulnerability in the Big Data Spatial and Graph product of Oracle Big Data Graph (component: Big Data Graph (Apache Tomcat)).   The supported version that is affected is Prior to 23.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Big Data Spatial and Graph.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Big Data Spatial and Graph accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-17527</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11528V-Prior to 23.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Big Data Spatial and Graph</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-11528V-Prior to 23.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="93" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-17527</Title>
      <Notes>
         <Note Audience="All" Ordinal="93" Title="Details" Type="Details">Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications Applications (component: Transformation for PDC (Apache Tomcat)).   The supported version that is affected is 12.0.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Pricing Design Center.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Pricing Design Center accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-17527</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9437V-12.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Pricing Design Center</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2785183.1</URL>
            <ProductID>P-9437V-12.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="94" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-17527</Title>
      <Notes>
         <Note Audience="All" Ordinal="94" Title="Details" Type="Details">Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Apache Tomcat)).  Supported versions that are affected are 16.0.6, 17.0.4, 18.0.3, 19.0.2 and  20.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Xstore Point of Service accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-17527</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11513V-16.0.6</ProductID>
            <ProductID>P-11513V-17.0.4</ProductID>
            <ProductID>P-11513V-18.0.3</ProductID>
            <ProductID>P-11513V-19.0.2</ProductID>
            <ProductID>P-11513V-20.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Xstore Point of Service</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783353.1</URL>
            <ProductID>P-11513V-16.0.6</ProductID>
            <ProductID>P-11513V-17.0.4</ProductID>
            <ProductID>P-11513V-18.0.3</ProductID>
            <ProductID>P-11513V-19.0.2</ProductID>
            <ProductID>P-11513V-20.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="95" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-17530</Title>
      <Notes>
         <Note Audience="All" Ordinal="95" Title="Details" Type="Details">Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications Applications (component: CNE (Apache Struts)).   The supported version that is affected is 12.0.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Pricing Design Center.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Pricing Design Center. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-17530</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9437V-12.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Pricing Design Center</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2785183.1</URL>
            <ProductID>P-9437V-12.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="96" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-1945</Title>
      <Notes>
         <Note Audience="All" Ordinal="96" Title="Details" Type="Details">Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Install, config, upgrade  (Apache Ant)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Data Integrator executes to compromise Oracle Data Integrator.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Data Integrator accessible data as well as  unauthorized access to critical data or complete access to all Oracle Data Integrator accessible data. CVSS 3.1 Base Score 6.3 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-1945</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2196V-12.2.1.3.0</ProductID>
            <ProductID>P-2196V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Data Integrator</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-2196V-12.2.1.3.0</ProductID>
            <ProductID>P-2196V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="97" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-1971</Title>
      <Notes>
         <Note Audience="All" Ordinal="97" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Discovery Framework (OpenSSL)).   The supported version that is affected is 13.4.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-1971</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-13.4.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Enterprise Manager Base Platform</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-1370V-13.4.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="98" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-24553</Title>
      <Notes>
         <Note Audience="All" Ordinal="98" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Signaling (Go)).   The supported version that is affected is 1.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Cloud Native Core Policy, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Policy accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-24553</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14277V-1.5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Policy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2791658.1</URL>
            <ProductID>P-14277V-1.5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="99" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-24750</Title>
      <Notes>
         <Note Audience="All" Ordinal="99" Title="Details" Type="Details">Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Onboarding  (jackson-databind)).  Supported versions that are affected are 14.2, 14.3 and  14.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Liquidity Management.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Liquidity Management. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-24750</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13304V-14.2</ProductID>
            <ProductID>P-13304V-14.3</ProductID>
            <ProductID>P-13304V-14.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Liquidity Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-13304V-14.2</ProductID>
            <ProductID>P-13304V-14.3</ProductID>
            <ProductID>P-13304V-14.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="100" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-24750</Title>
      <Notes>
         <Note Audience="All" Ordinal="100" Title="Details" Type="Details">Vulnerability in the Siebel Core - Server Framework product of Oracle Siebel CRM (component: Services (jackson-databind)).  Supported versions that are affected are 21.5 and Prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Core - Server Framework.  Successful attacks of this vulnerability can result in takeover of Siebel Core - Server Framework. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-24750</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9001V-21.5 and Prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Siebel Core - Server Framework</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787995.1</URL>
            <ProductID>P-9001V-21.5 and Prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="101" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-2555</Title>
      <Notes>
         <Note Audience="All" Ordinal="101" Title="Details" Type="Details">Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Installation Component (Oracle Coherence)).   The supported version that is affected is 11.1.2.3.0. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Access Manager executes to compromise Oracle Access Manager.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Access Manager accessible data as well as  unauthorized read access to a subset of Oracle Access Manager accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-2555</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5565V-11.1.2.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.1</BaseScore>
            <Vector>AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Access Manager</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-5565V-11.1.2.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="102" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-2555</Title>
      <Notes>
         <Note Audience="All" Ordinal="102" Title="Details" Type="Details">Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework (Coherence)).  Supported versions that are affected are 11.0.0, 11.1.0, 11.2.0 and  11.3.0-11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-2555</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9348V-11.0.0</ProductID>
            <ProductID>P-9348V-11.1.0</ProductID>
            <ProductID>P-9348V-11.2.0</ProductID>
            <ProductID>P-9348V-11.3.0-11.3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Commerce Platform</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2792990.1</URL>
            <ProductID>P-9348V-11.0.0</ProductID>
            <ProductID>P-9348V-11.1.0</ProductID>
            <ProductID>P-9348V-11.2.0</ProductID>
            <ProductID>P-9348V-11.3.0-11.3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="103" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-25638</Title>
      <Notes>
         <Note Audience="All" Ordinal="103" Title="Details" Type="Details">Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Segment (Hibernate)).   The supported version that is affected is 19.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Customer Management and Segmentation Foundation.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Customer Management and Segmentation Foundation accessible data as well as  unauthorized access to critical data or complete access to all Oracle Retail Customer Management and Segmentation Foundation accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-25638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13388V-19.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.4</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Customer Management and Segmentation Foundation</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783353.1</URL>
            <ProductID>P-13388V-19.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="104" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-25648</Title>
      <Notes>
         <Note Audience="All" Ordinal="104" Title="Details" Type="Details">Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications Applications (component: CNE (NSS)).   The supported version that is affected is 12.0.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Pricing Design Center.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Pricing Design Center. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-25648</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9437V-12.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Pricing Design Center</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2785183.1</URL>
            <ProductID>P-9437V-12.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="105" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-25649</Title>
      <Notes>
         <Note Audience="All" Ordinal="105" Title="Details" Type="Details">Vulnerability in the Oracle Banking Treasury Management product of Oracle Financial Services Applications (component: Accounting (jackson-databind)).   The supported version that is affected is 14.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Treasury Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Treasury Management accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-25649</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14133V-14.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Treasury Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-14133V-14.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="106" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-25649</Title>
      <Notes>
         <Note Audience="All" Ordinal="106" Title="Details" Type="Details">Security-in-Depth issue in the Big Data Spatial and Graph product of Oracle Big Data Graph (component: Big Data Graph (jackson-databind)). This vulnerability cannot be exploited in the context of this product.</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-25649</CVE>
      <ProductStatuses>
         <Status Type="Known Not Affected">
            <ProductID>P-11528V-All Supported Versions</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Big Data Spatial and Graph</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-11528V-All Supported Versions</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="107" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-25649</Title>
      <Notes>
         <Note Audience="All" Ordinal="107" Title="Details" Type="Details">Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework (jackson-databind)).  Supported versions that are affected are 11.2.0 and  11.3.0-11.3.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Platform. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-25649</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9348V-11.2.0</ProductID>
            <ProductID>P-9348V-11.3.0-11.3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Commerce Platform</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2792990.1</URL>
            <ProductID>P-9348V-11.2.0</ProductID>
            <ProductID>P-9348V-11.3.0-11.3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="108" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-25649</Title>
      <Notes>
         <Note Audience="All" Ordinal="108" Title="Details" Type="Details">Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Business Operation Center (jackson-databind)).  Supported versions that are affected are 7.5.0.23.0 and  12.0.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Billing and Revenue Management accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-25649</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2136V-7.5.0.23.0</ProductID>
            <ProductID>P-2136V-12.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Billing and Revenue Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2785183.1</URL>
            <ProductID>P-2136V-7.5.0.23.0</ProductID>
            <ProductID>P-2136V-12.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="109" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-25649</Title>
      <Notes>
         <Note Audience="All" Ordinal="109" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: UDR (jackson-databind)).   The supported version that is affected is 1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Unified Data Repository accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-25649</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14119V-1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Unified Data Repository</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2791683.1</URL>
            <ProductID>P-14119V-1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="110" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-25649</Title>
      <Notes>
         <Note Audience="All" Ordinal="110" Title="Details" Type="Details">Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications Applications (component: Common fns (jackson-databind)).   The supported version that is affected is 12.0.4.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Convergent Charging Controller.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Convergent Charging Controller accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-25649</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12985V-12.0.4.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Convergent Charging Controller</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2790722.1</URL>
            <ProductID>P-12985V-12.0.4.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="111" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-25649</Title>
      <Notes>
         <Note Audience="All" Ordinal="111" Title="Details" Type="Details">Vulnerability in the Oracle Communications Evolved Communications Application Server product of Oracle Communications (component: Session Design Center GUI (jackson-databind)).   The supported version that is affected is 7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Evolved Communications Application Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Evolved Communications Application Server accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-25649</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10994V-7.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Evolved Communications Application Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787205.1</URL>
            <ProductID>P-10994V-7.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="112" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-25649</Title>
      <Notes>
         <Note Audience="All" Ordinal="112" Title="Details" Type="Details">Vulnerability in the Oracle Communications Network Charging and Control product of Oracle Communications Applications (component: OUI (jackson-databind)).   The supported version that is affected is 12.0.4.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Charging and Control.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Network Charging and Control accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-25649</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4623V-12.0.4.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Network Charging and Control</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2790722.1</URL>
            <ProductID>P-4623V-12.0.4.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="113" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-25649</Title>
      <Notes>
         <Note Audience="All" Ordinal="113" Title="Details" Type="Details">Vulnerability in the Oracle Communications Services Gatekeeper product of Oracle Communications (component: OCSG Policy service (jackson-databind)).   The supported version that is affected is 7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Services Gatekeeper.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Services Gatekeeper accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-25649</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5381V-7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Services Gatekeeper</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787242.1</URL>
            <ProductID>P-5381V-7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="114" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-25649</Title>
      <Notes>
         <Note Audience="All" Ordinal="114" Title="Details" Type="Details">Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Media Resource (jackson-databind)).   The supported version that is affected is 7.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Inventory Management accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-25649</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4516V-7.4.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Unified Inventory Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2785180.1</URL>
            <ProductID>P-4516V-7.4.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="115" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-25649</Title>
      <Notes>
         <Note Audience="All" Ordinal="115" Title="Details" Type="Details">Vulnerability in the Oracle GoldenGate Application Adapters product of Oracle Fusion Middleware (component: Application Adapters   (jackson-databind)).   The supported version that is affected is 19.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GoldenGate Application Adapters.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle GoldenGate Application Adapters accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-25649</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5760V-19.1.0.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>GoldenGate Big Data and Application Adapters</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-5760V-19.1.0.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="116" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-25649</Title>
      <Notes>
         <Note Audience="All" Ordinal="116" Title="Details" Type="Details">Vulnerability in the Oracle Insurance Policy Administration product of Oracle Insurance Applications (component: Architecture (jackson-databind)).  Supported versions that are affected are 11.0.2 and  11.1.0-11.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Insurance Policy Administration accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-25649</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5279V-11.0.2</ProductID>
            <ProductID>P-5279V-11.1.0-11.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Insurance Policy Administration J2EE</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2784893.1</URL>
            <ProductID>P-5279V-11.0.2</ProductID>
            <ProductID>P-5279V-11.1.0-11.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="117" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-25649</Title>
      <Notes>
         <Note Audience="All" Ordinal="117" Title="Details" Type="Details">Vulnerability in the Oracle Insurance Rules Palette product of Oracle Insurance Applications (component: Architecture (jackson-databind)).  Supported versions that are affected are 11.0.2 and  11.1.0-11.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Rules Palette.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Insurance Rules Palette accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-25649</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5288V-11.0.2</ProductID>
            <ProductID>P-5288V-11.1.0-11.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Insurance Rules Palette</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2784893.1</URL>
            <ProductID>P-5288V-11.0.2</ProductID>
            <ProductID>P-5288V-11.1.0-11.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="118" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-25649</Title>
      <Notes>
         <Note Audience="All" Ordinal="118" Title="Details" Type="Details">Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security (jackson-databind)).  Supported versions that are affected are 9.2.5.3 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Orchestrator.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Orchestrator accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-25649</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11681V-9.2.5.3 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>JD Edwards EnterpriseOne Orchestrator</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787996.1</URL>
            <ProductID>P-11681V-9.2.5.3 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="119" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-25649</Title>
      <Notes>
         <Note Audience="All" Ordinal="119" Title="Details" Type="Details">Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics SEC (jackson-databind)).  Supported versions that are affected are 9.2.5.3 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-25649</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4781V-9.2.5.3 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>JD Edwards EnterpriseOne Tools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787996.1</URL>
            <ProductID>P-4781V-9.2.5.3 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="120" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-25649</Title>
      <Notes>
         <Note Audience="All" Ordinal="120" Title="Details" Type="Details">Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC (jackson-databind)).  Supported versions that are affected are 9.2.5.3 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-25649</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4781V-9.2.5.3 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>JD Edwards EnterpriseOne Tools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787996.1</URL>
            <ProductID>P-4781V-9.2.5.3 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="121" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-25649</Title>
      <Notes>
         <Note Audience="All" Ordinal="121" Title="Details" Type="Details">Vulnerability in the Primavera Gateway product of Oracle Construction and Engineering (component: Admin (jackson-databind)).  Supported versions that are affected are 17.12.0-17.12.11, 18.8.0-18.8.11, 19.12.0-19.12.10 and  20.12.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Gateway.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Primavera Gateway accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-25649</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10605V-17.12.0-17.12.11</ProductID>
            <ProductID>P-10605V-18.8.0-18.8.11</ProductID>
            <ProductID>P-10605V-19.12.0-19.12.10</ProductID>
            <ProductID>P-10605V-20.12.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera Gateway</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783281.1</URL>
            <ProductID>P-10605V-17.12.0-17.12.11</ProductID>
            <ProductID>P-10605V-18.8.0-18.8.11</ProductID>
            <ProductID>P-10605V-19.12.0-19.12.10</ProductID>
            <ProductID>P-10605V-20.12.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="122" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-25649</Title>
      <Notes>
         <Note Audience="All" Ordinal="122" Title="Details" Type="Details">Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Project Delivery (jackson-databind)).  Supported versions that are affected are 17.7-17.12, 18.8, 19.12 and  20.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Primavera Unifier executes to compromise Primavera Unifier.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera Unifier accessible data as well as  unauthorized read access to a subset of Primavera Unifier accessible data. CVSS 3.1 Base Score 3.9 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-25649</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10354V-17.7-17.12</ProductID>
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
            <ProductID>P-10354V-20.12</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.9</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera Unifier</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783281.1</URL>
            <ProductID>P-10354V-17.7-17.12</ProductID>
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
            <ProductID>P-10354V-20.12</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="123" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-25649</Title>
      <Notes>
         <Note Audience="All" Ordinal="123" Title="Details" Type="Details">Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (jackson-databind)).  Supported versions that are affected are 16.0.3.0, 
15.0.3.1 and 
14.1.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Service Backbone accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-25649</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10867V-16.0.3.0</ProductID>
            <ProductID>P-10867V-15.0.3.1</ProductID>
            <ProductID>P-10867V-14.1.3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Service Backbone</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783353.1</URL>
            <ProductID>P-10867V-16.0.3.0</ProductID>
            <ProductID>P-10867V-15.0.3.1</ProductID>
            <ProductID>P-10867V-14.1.3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="124" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-25649</Title>
      <Notes>
         <Note Audience="All" Ordinal="124" Title="Details" Type="Details">Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (jackson-databind)).  Supported versions that are affected are 16.0.6, 17.0.4, 18.0.3 and  19.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Xstore Point of Service accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-25649</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11513V-16.0.6</ProductID>
            <ProductID>P-11513V-17.0.4</ProductID>
            <ProductID>P-11513V-18.0.3</ProductID>
            <ProductID>P-11513V-19.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Xstore Point of Service</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783353.1</URL>
            <ProductID>P-11513V-16.0.6</ProductID>
            <ProductID>P-11513V-17.0.4</ProductID>
            <ProductID>P-11513V-18.0.3</ProductID>
            <ProductID>P-11513V-19.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="125" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-25649</Title>
      <Notes>
         <Note Audience="All" Ordinal="125" Title="Details" Type="Details">Security-in-Depth issue in the Oracle Spatial and Graph Network Data Model (jackson-databind) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-25649</CVE>
      <ProductStatuses>
         <Status Type="Known Not Affected">
            <ProductID>P-619V-All Supported Versions</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Spatial and Graph</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-619V-All Supported Versions</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="126" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-2604</Title>
      <Notes>
         <Note Audience="All" Ordinal="126" Title="Details" Type="Details">Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (Java SE)).   The supported version that is affected is 11.3.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-2604</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9633V-11.3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Commerce Guided Search / Oracle Commerce Experience Manager</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2792990.1</URL>
            <ProductID>P-9633V-11.3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="127" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-2604</Title>
      <Notes>
         <Note Audience="All" Ordinal="127" Title="Details" Type="Details">Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Tools and Frameworks (Java SE)).   The supported version that is affected is 11.3.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-2604</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9633V-11.3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Commerce Guided Search / Oracle Commerce Experience Manager</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2792990.1</URL>
            <ProductID>P-9633V-11.3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="128" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-26870</Title>
      <Notes>
         <Note Audience="All" Ordinal="128" Title="Details" Type="Details">Vulnerability in the Oracle Application Express Application Builder (DOMPurify) component of Oracle Database Server.   The supported version that is affected is Prior to 21.1.0.00.01. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Application Builder (DOMPurify).  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express Application Builder (DOMPurify), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Application Express Application Builder (DOMPurify) accessible data as well as  unauthorized read access to a subset of Oracle Application Express Application Builder (DOMPurify) accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-26870</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1348V-Prior to 21.1.0.00.01</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Application Express (APEX)</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-1348V-Prior to 21.1.0.00.01</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="129" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-27193</Title>
      <Notes>
         <Note Audience="All" Ordinal="129" Title="Details" Type="Details">Vulnerability in the Oracle Application Express (CKEditor) component of Oracle Database Server.   The supported version that is affected is Prior to 21.1.0.00.01. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express (CKEditor).  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express (CKEditor), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Application Express (CKEditor) accessible data as well as  unauthorized read access to a subset of Oracle Application Express (CKEditor) accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-27193</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1348V-Prior to 21.1.0.00.01</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Application Express (APEX)</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-1348V-Prior to 21.1.0.00.01</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="130" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-27193</Title>
      <Notes>
         <Note Audience="All" Ordinal="130" Title="Details" Type="Details">Vulnerability in the Oracle Banking Party Management product of Oracle Financial Services Applications (component: Web UI (CKEditor)).   The supported version that is affected is 2.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Party Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Party Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Banking Party Management accessible data as well as  unauthorized read access to a subset of Oracle Banking Party Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-27193</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13929V-2.7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Party Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787695.1</URL>
            <ProductID>P-13929V-2.7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="131" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-27193</Title>
      <Notes>
         <Note Audience="All" Ordinal="131" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Rate Management (CKEditor)).  Supported versions that are affected are 8.0.6-8.0.9, 8.1.0 and  8.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Analytical Applications Infrastructure, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Analytical Applications Infrastructure accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-27193</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5680V-8.0.6-8.0.9</ProductID>
            <ProductID>P-5680V-8.1.0</ProductID>
            <ProductID>P-5680V-8.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Financial Services Analytical Applications Infrastructure</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787723.1</URL>
            <ProductID>P-5680V-8.0.6-8.0.9</ProductID>
            <ProductID>P-5680V-8.1.0</ProductID>
            <ProductID>P-5680V-8.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="132" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-27216</Title>
      <Notes>
         <Note Audience="All" Ordinal="132" Title="Details" Type="Details">Vulnerability in the Oracle Communications Offline Mediation Controller product of Oracle Communications Applications (component: CN OCOMC (Eclipse Jetty)).   The supported version that is affected is 12.0.0.3.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Offline Mediation Controller executes to compromise Oracle Communications Offline Mediation Controller.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Offline Mediation Controller. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-27216</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2269V-12.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Offline Mediation Controller</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2785182.1</URL>
            <ProductID>P-2269V-12.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="133" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-27216</Title>
      <Notes>
         <Note Audience="All" Ordinal="133" Title="Details" Type="Details">Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications Applications (component: Transformation for PDC (Eclipse Jetty)).   The supported version that is affected is 12.0.0.3.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Pricing Design Center executes to compromise Oracle Communications Pricing Design Center.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Pricing Design Center. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-27216</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9437V-12.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Pricing Design Center</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2785183.1</URL>
            <ProductID>P-9437V-12.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="134" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-27216</Title>
      <Notes>
         <Note Audience="All" Ordinal="134" Title="Details" Type="Details">Vulnerability in the Oracle Communications Services Gatekeeper product of Oracle Communications (component: Call Control Common Service (Eclipse Jetty)).   The supported version that is affected is 7.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Services Gatekeeper executes to compromise Oracle Communications Services Gatekeeper.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Services Gatekeeper. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-27216</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5381V-7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Services Gatekeeper</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787242.1</URL>
            <ProductID>P-5381V-7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="135" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-27216</Title>
      <Notes>
         <Note Audience="All" Ordinal="135" Title="Details" Type="Details">Vulnerability in the Siebel Core - Automation product of Oracle Siebel CRM (component: Test Automation (Eclipse Jetty)).  Supported versions that are affected are 21.5 and Prior. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel Core - Automation executes to compromise Siebel Core - Automation.  Successful attacks of this vulnerability can result in takeover of Siebel Core - Automation. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-27216</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8988V-21.5 and Prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Siebel Core - Automation</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787995.1</URL>
            <ProductID>P-8988V-21.5 and Prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="136" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-27218</Title>
      <Notes>
         <Note Audience="All" Ordinal="136" Title="Details" Type="Details">Vulnerability in the Oracle Communications Services Gatekeeper product of Oracle Communications (component: Subscriber profile (Eclipse Jetty)).   The supported version that is affected is 7.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Services Gatekeeper.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Services Gatekeeper accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Services Gatekeeper. CVSS 3.1 Base Score 4.8 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-27218</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5381V-7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Services Gatekeeper</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787242.1</URL>
            <ProductID>P-5381V-7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="137" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-27218</Title>
      <Notes>
         <Note Audience="All" Ordinal="137" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Private Banking product of Oracle Financial Services Applications (component: Financial Planning (Eclipse Jetty)).  Supported versions that are affected are 12.0.0 and  12.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle FLEXCUBE Private Banking accessible data as well as  unauthorized access to critical data or complete access to all Oracle FLEXCUBE Private Banking accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle FLEXCUBE Private Banking. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-27218</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9110V-12.0.0</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.4</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>FLEXCUBE Private Banking</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-9110V-12.0.0</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="138" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-27844</Title>
      <Notes>
         <Note Audience="All" Ordinal="138" Title="Details" Type="Details">Security-in-Depth issue in the MapViewer (OWASP ESAPI)Oracle Spatial and Graph (OpenJPEG) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-27844</CVE>
      <ProductStatuses>
         <Status Type="Known Not Affected">
            <ProductID>P-619V-All Supported Versions</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Spatial and Graph</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-619V-All Supported Versions</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="139" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-28052</Title>
      <Notes>
         <Note Audience="All" Ordinal="139" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework (Bouncy Castle Java Library)).  Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-28052</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1696V-11.1.1.9.0</ProductID>
            <ProductID>P-1696V-12.2.1.3.0</ProductID>
            <ProductID>P-1696V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebCenter Portal</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-1696V-11.1.1.9.0</ProductID>
            <ProductID>P-1696V-12.2.1.3.0</ProductID>
            <ProductID>P-1696V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="140" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-28196</Title>
      <Notes>
         <Note Audience="All" Ordinal="140" Title="Details" Type="Details">Vulnerability in the Oracle Communications Offline Mediation Controller product of Oracle Communications Applications (component: NM Core (Kerberos)).   The supported version that is affected is 12.0.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Offline Mediation Controller.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Offline Mediation Controller. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-28196</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2269V-12.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Offline Mediation Controller</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2785182.1</URL>
            <ProductID>P-2269V-12.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="141" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-28196</Title>
      <Notes>
         <Note Audience="All" Ordinal="141" Title="Details" Type="Details">Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications Applications (component: Transformation for PDC (Kerberos)).   The supported version that is affected is 12.0.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Pricing Design Center.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Pricing Design Center. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-28196</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9437V-12.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Pricing Design Center</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2785183.1</URL>
            <ProductID>P-9437V-12.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="142" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-28196</Title>
      <Notes>
         <Note Audience="All" Ordinal="142" Title="Details" Type="Details">Security-in-Depth issue in the Oracle Database - Enterprise Edition (Kerberos) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-28196</CVE>
      <ProductStatuses>
         <Status Type="Known Not Affected">
            <ProductID>P-5V-All Supported Versions</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Database - Enterprise Edition</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-5V-All Supported Versions</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="143" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-28928</Title>
      <Notes>
         <Note Audience="All" Ordinal="143" Title="Details" Type="Details">Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: LLVM Interpreter (musl libc)).  Supported versions that are affected are Oracle GraalVM Enterprise Edition: 20.3.2 and  21.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GraalVM Enterprise Edition executes to compromise Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GraalVM Enterprise Edition. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-28928</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13497V-Oracle GraalVM Enterprise Edition:20.3.2</ProductID>
            <ProductID>P-13497V-Oracle GraalVM Enterprise Edition:21.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>GraalVM Enterprise Edition</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787003.1</URL>
            <ProductID>P-13497V-Oracle GraalVM Enterprise Edition:20.3.2</ProductID>
            <ProductID>P-13497V-Oracle GraalVM Enterprise Edition:21.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="144" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-29582</Title>
      <Notes>
         <Note Audience="All" Ordinal="144" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Signaling (Calico)).   The supported version that is affected is 1.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Cloud Native Core Network Slice Selection Function accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-29582</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14130V-1.2.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Network Slice Selection Function</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2791657.1</URL>
            <ProductID>P-14130V-1.2.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="145" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-35490</Title>
      <Notes>
         <Note Audience="All" Ordinal="145" Title="Details" Type="Details">Vulnerability in the Oracle Insurance Policy Administration J2EE product of Oracle Insurance Applications (component: Security Information (jackson-databind)).   The supported version that is affected is 11.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration J2EE.  Successful attacks of this vulnerability can result in takeover of Oracle Insurance Policy Administration J2EE. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-35490</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5279V-11.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Insurance Policy Administration J2EE</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2784893.1</URL>
            <ProductID>P-5279V-11.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="146" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-5258</Title>
      <Notes>
         <Note Audience="All" Ordinal="146" Title="Details" Type="Details">Vulnerability in the Oracle Communications Application Session Controller product of Oracle Communications (component: Signaling (dojo)).   The supported version that is affected is 3.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Application Session Controller.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Application Session Controller accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-5258</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10769V-3.9</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Application Session Controller</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787241.1</URL>
            <ProductID>P-10769V-3.9</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="147" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-5258</Title>
      <Notes>
         <Note Audience="All" Ordinal="147" Title="Details" Type="Details">Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications Applications (component: Server for PDC (dojo)).   The supported version that is affected is 12.0.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Pricing Design Center.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Pricing Design Center accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-5258</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9437V-12.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Pricing Design Center</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2785183.1</URL>
            <ProductID>P-9437V-12.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="148" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-5258</Title>
      <Notes>
         <Note Audience="All" Ordinal="148" Title="Details" Type="Details">Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Core UI (dojo)).  Supported versions that are affected are 17.7-17.12, 18.8, 19.12 and  20.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera Unifier accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-5258</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10354V-17.7-17.12</ProductID>
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
            <ProductID>P-10354V-20.12</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera Unifier</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783281.1</URL>
            <ProductID>P-10354V-17.7-17.12</ProductID>
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
            <ProductID>P-10354V-20.12</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="149" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-5398</Title>
      <Notes>
         <Note Audience="All" Ordinal="149" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Configuration (Spring Framework)).   The supported version that is affected is 1.5.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-5398</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14277V-1.5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Policy</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2791658.1</URL>
            <ProductID>P-14277V-1.5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="150" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-5398</Title>
      <Notes>
         <Note Audience="All" Ordinal="150" Title="Details" Type="Details">Vulnerability in the Oracle Retail Back Office product of Oracle Retail Applications (component: Pricing (Spring Framework)).   The supported version that is affected is 14.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Back Office.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Retail Back Office. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-5398</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2013V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Back Office</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783353.1</URL>
            <ProductID>P-2013V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="151" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-5398</Title>
      <Notes>
         <Note Audience="All" Ordinal="151" Title="Details" Type="Details">Vulnerability in the Oracle Retail Central Office product of Oracle Retail Applications (component: Transaction Tracker (Spring Framework)).   The supported version that is affected is 14.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Central Office.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Retail Central Office. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-5398</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2016V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Central Office</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783353.1</URL>
            <ProductID>P-2016V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="152" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-5398</Title>
      <Notes>
         <Note Audience="All" Ordinal="152" Title="Details" Type="Details">Vulnerability in the Oracle Retail Point-of-Service product of Oracle Retail Applications (component: Queue Management (Spring Framework)).   The supported version that is affected is 14.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Point-of-Service.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Retail Point-of-Service. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-5398</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2017V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Point-of-Service</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783353.1</URL>
            <ProductID>P-2017V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="153" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-5398</Title>
      <Notes>
         <Note Audience="All" Ordinal="153" Title="Details" Type="Details">Vulnerability in the Oracle Retail Returns Management product of Oracle Retail Applications (component: Main Dashboard (Spring Framework)).   The supported version that is affected is 14.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Returns Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Retail Returns Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-5398</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2020V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Returns Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783353.1</URL>
            <ProductID>P-2020V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="154" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-5413</Title>
      <Notes>
         <Note Audience="All" Ordinal="154" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Private Banking product of Oracle Financial Services Applications (component: Financial Planning  (Spring Integration)).  Supported versions that are affected are 12.0.0 and  12.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking.  Successful attacks of this vulnerability can result in takeover of Oracle FLEXCUBE Private Banking. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-5413</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9110V-12.0.0</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>FLEXCUBE Private Banking</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-9110V-12.0.0</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="155" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-5421</Title>
      <Notes>
         <Note Audience="All" Ordinal="155" Title="Details" Type="Details">Vulnerability in the Oracle Enterprise Data Quality product of Oracle Fusion Middleware (component: General (Spring Framework)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Data Quality.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Data Quality. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-5421</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9464V-12.2.1.3.0</ProductID>
            <ProductID>P-9464V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Enterprise Data Quality</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-9464V-12.2.1.3.0</ProductID>
            <ProductID>P-9464V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="156" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-5421</Title>
      <Notes>
         <Note Audience="All" Ordinal="156" Title="Details" Type="Details">Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Promotions (Spring Framework)).  Supported versions that are affected are 16.0-19.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Customer Management and Segmentation Foundation.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Customer Management and Segmentation Foundation. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-5421</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13388V-16.0-19.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Customer Management and Segmentation Foundation</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783353.1</URL>
            <ProductID>P-13388V-16.0-19.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="157" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-5421</Title>
      <Notes>
         <Note Audience="All" Ordinal="157" Title="Details" Type="Details">Vulnerability in the Oracle Retail Customer Engagement product of Oracle Retail Applications (component: Internal Operations  (Spring Framework)).  Supported versions that are affected are 16.0-19.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Customer Engagement.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Customer Engagement, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Customer Engagement accessible data as well as  unauthorized read access to a subset of Oracle Retail Customer Engagement accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-5421</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11518V-16.0-19.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Customer Management and Segmentation Foundation Cloud Service</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783353.1</URL>
            <ProductID>P-11518V-16.0-19.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="158" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-5421</Title>
      <Notes>
         <Note Audience="All" Ordinal="158" Title="Details" Type="Details">Vulnerability in the Oracle Retail Merchandising System product of Oracle Retail Applications (component: Foundation (Spring Framework)).   The supported version that is affected is 16.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Merchandising System.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Merchandising System. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-5421</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1816V-16.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Merchandising System</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783353.1</URL>
            <ProductID>P-1816V-16.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="159" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-5421</Title>
      <Notes>
         <Note Audience="All" Ordinal="159" Title="Details" Type="Details">Vulnerability in the StorageTek Tape Analytics SW Tool product of Oracle Systems (component: Software (Spring Framework)).   The supported version that is affected is 2.3. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise StorageTek Tape Analytics SW Tool.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in StorageTek Tape Analytics SW Tool, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all StorageTek Tape Analytics SW Tool accessible data as well as  unauthorized read access to a subset of StorageTek Tape Analytics SW Tool accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-5421</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10085V-2.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Tape General STA - StorageTek Tape Analytics SW Tool</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788472.1</URL>
            <ProductID>P-10085V-2.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="160" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-7017</Title>
      <Notes>
         <Note Audience="All" Ordinal="160" Title="Details" Type="Details">Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Balance Monitoring Manager (Kibana)).   The supported version that is affected is 12.0.0.3.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Billing and Revenue Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Billing and Revenue Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-7017</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2136V-12.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.7</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Billing and Revenue Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2785183.1</URL>
            <ProductID>P-2136V-12.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="161" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-7017</Title>
      <Notes>
         <Note Audience="All" Ordinal="161" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search (Kibana)).   The supported version that is affected is 8.58. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-7017</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.58</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.7</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>PeopleSoft Enterprise PT PeopleTools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788006.1</URL>
            <ProductID>P-5085V-8.58</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="162" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-7712</Title>
      <Notes>
         <Note Audience="All" Ordinal="162" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Regulatory Reporting with AgileREPORTER product of Oracle Financial Services Applications (component: Reports (Apache ZooKeeper)).   The supported version that is affected is 8.0.9.6.3. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Financial Services Regulatory Reporting with AgileREPORTER.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Regulatory Reporting with AgileREPORTER. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-7712</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13077V-8.0.9.6.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.2</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Financial Services Regulatory Reporting with AgileREPORTER</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2791194.1</URL>
            <ProductID>P-13077V-8.0.9.6.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="163" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-7733</Title>
      <Notes>
         <Note Audience="All" Ordinal="163" Title="Details" Type="Details">Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: Signaling (Kibana)).   The supported version that is affected is 1.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Function Cloud Native Environment. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-7733</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14125V-1.7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Cloud Native Core Network Function Cloud Native Environment</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2791656.1</URL>
            <ProductID>P-14125V-1.7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="164" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-7760</Title>
      <Notes>
         <Note Audience="All" Ordinal="164" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Express User Interface (CodeMirror) component of Oracle Database Server.   The supported version that is affected is 19c. Easily exploitable vulnerability allows low privileged attacker having User Account privilege with network access via HTTP to compromise Enterprise Manager Express User Interface (CodeMirror).  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Enterprise Manager Express User Interface (CodeMirror). CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-7760</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Database - Enterprise Edition</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-5V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="165" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-7760</Title>
      <Notes>
         <Note Audience="All" Ordinal="165" Title="Details" Type="Details">Vulnerability in the Essbase product of Oracle Essbase (component: Infrastructure (CodeMirror)).   The supported version that is affected is 21.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Essbase.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Essbase. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-7760</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4379V-21.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Hyperion Essbase</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-4379V-21.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="166" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-8203</Title>
      <Notes>
         <Note Audience="All" Ordinal="166" Title="Details" Type="Details">Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: DashBoard (Lodash)).  Supported versions that are affected are 14.2, 14.3 and  14.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Liquidity Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Liquidity Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Liquidity Management. CVSS 3.1 Base Score 7.4 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-8203</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13304V-14.2</ProductID>
            <ProductID>P-13304V-14.3</ProductID>
            <ProductID>P-13304V-14.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.4</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Liquidity Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-13304V-14.2</ProductID>
            <ProductID>P-13304V-14.3</ProductID>
            <ProductID>P-13304V-14.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="167" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-8203</Title>
      <Notes>
         <Note Audience="All" Ordinal="167" Title="Details" Type="Details">Security-in-Depth issue in the Big Data Spatial and Graph product of Oracle Big Data Graph (component: Big Data Graph (Lodash)). This vulnerability cannot be exploited in the context of this product.</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-8203</CVE>
      <ProductStatuses>
         <Status Type="Known Not Affected">
            <ProductID>P-11528V-All Supported Versions</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Big Data Spatial and Graph</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-11528V-All Supported Versions</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="168" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-8203</Title>
      <Notes>
         <Note Audience="All" Ordinal="168" Title="Details" Type="Details">Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Billing Care (Lodash)).  Supported versions that are affected are 7.5.0.23.0 and  
12.0.0.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Billing and Revenue Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 7.4 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-8203</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2136V-7.5.0.23.0</ProductID>
            <ProductID>P-2136V-12.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.4</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Billing and Revenue Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2785183.1</URL>
            <ProductID>P-2136V-7.5.0.23.0</ProductID>
            <ProductID>P-2136V-12.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="169" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-8203</Title>
      <Notes>
         <Note Audience="All" Ordinal="169" Title="Details" Type="Details">Vulnerability in the Primavera Gateway product of Oracle Construction and Engineering (component: Admin (Lodash)).  Supported versions that are affected are 17.12.0-17.12.11, 18.8.0-18.8.11, 19.12.0-19.12.10 and  20.12.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Gateway.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Primavera Gateway accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Primavera Gateway. CVSS 3.1 Base Score 7.4 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-8203</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10605V-17.12.0-17.12.11</ProductID>
            <ProductID>P-10605V-18.8.0-18.8.11</ProductID>
            <ProductID>P-10605V-19.12.0-19.12.10</ProductID>
            <ProductID>P-10605V-20.12.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.4</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera Gateway</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783281.1</URL>
            <ProductID>P-10605V-17.12.0-17.12.11</ProductID>
            <ProductID>P-10605V-18.8.0-18.8.11</ProductID>
            <ProductID>P-10605V-19.12.0-19.12.10</ProductID>
            <ProductID>P-10605V-20.12.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="170" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-8277</Title>
      <Notes>
         <Note Audience="All" Ordinal="170" Title="Details" Type="Details">Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Node.js)).  Supported versions that are affected are 16.0.6, 17.0.4, 18.0.3, 19.0.2 and  20.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-8277</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11513V-16.0.6</ProductID>
            <ProductID>P-11513V-17.0.4</ProductID>
            <ProductID>P-11513V-18.0.3</ProductID>
            <ProductID>P-11513V-19.0.2</ProductID>
            <ProductID>P-11513V-20.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Xstore Point of Service</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783353.1</URL>
            <ProductID>P-11513V-16.0.6</ProductID>
            <ProductID>P-11513V-17.0.4</ProductID>
            <ProductID>P-11513V-18.0.3</ProductID>
            <ProductID>P-11513V-19.0.2</ProductID>
            <ProductID>P-11513V-20.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="171" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-8285</Title>
      <Notes>
         <Note Audience="All" Ordinal="171" Title="Details" Type="Details">Vulnerability in the Essbase product of Oracle Essbase (component: Infrastructure (cURL)).   The supported version that is affected is 21.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Essbase.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Essbase. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-8285</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4379V-21.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Hyperion Essbase</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-4379V-21.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="172" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-8286</Title>
      <Notes>
         <Note Audience="All" Ordinal="172" Title="Details" Type="Details">Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Balances (cURL)).   The supported version that is affected is 12.0.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Billing and Revenue Management accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-8286</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2136V-12.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Billing and Revenue Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2785183.1</URL>
            <ProductID>P-2136V-12.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="173" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-8908</Title>
      <Notes>
         <Note Audience="All" Ordinal="173" Title="Details" Type="Details">Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Install, config, upgrade  (Guava)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Data Integrator executes to compromise Oracle Data Integrator.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Data Integrator accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-8908</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2196V-12.2.1.3.0</ProductID>
            <ProductID>P-2196V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.3</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Data Integrator</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-2196V-12.2.1.3.0</ProductID>
            <ProductID>P-2196V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="174" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-8908</Title>
      <Notes>
         <Note Audience="All" Ordinal="174" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search (Google Guava)).  Supported versions that are affected are 8.57, 8.58 and  8.59. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-8908</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.3</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>PeopleSoft Enterprise PT PeopleTools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788006.1</URL>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="175" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-8908</Title>
      <Notes>
         <Note Audience="All" Ordinal="175" Title="Details" Type="Details">Security-in-Depth issue in the Oracle Spatial and Graph MapViewer (Google Guava) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-8908</CVE>
      <ProductStatuses>
         <Status Type="Known Not Affected">
            <ProductID>P-619V-All Supported Versions</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Spatial and Graph</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-619V-All Supported Versions</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="176" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9484</Title>
      <Notes>
         <Note Audience="All" Ordinal="176" Title="Details" Type="Details">Vulnerability in the Oracle Communications Instant Messaging Server product of Oracle Communications Applications (component: Managing Messages (Apache Tomcat)).   The supported version that is affected is 10.0.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Instant Messaging Server executes to compromise Oracle Communications Instant Messaging Server.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Instant Messaging Server. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9484</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8495V-10.0.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.0</BaseScore>
            <Vector>AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Instant Messaging Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2786444.1</URL>
            <ProductID>P-8495V-10.0.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="177" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-20190</Title>
      <Notes>
         <Note Audience="All" Ordinal="177" Title="Details" Type="Details">Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manage (jackson-databind)).   The supported version that is affected is 11.3.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-20190</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9633V-11.3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Commerce Guided Search / Oracle Commerce Experience Manager</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2792990.1</URL>
            <ProductID>P-9633V-11.3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="178" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-20227</Title>
      <Notes>
         <Note Audience="All" Ordinal="178" Title="Details" Type="Details">Vulnerability in the Oracle Communications Network Charging and Control product of Oracle Communications Applications (component: Common fns (SQLite)).  Supported versions that are affected are 6.0.1.0 and  12.0.1.0-12.0.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Network Charging and Control executes to compromise Oracle Communications Network Charging and Control.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Charging and Control. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-20227</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4623V-6.0.1.0</ProductID>
            <ProductID>P-4623V-12.0.1.0-12.0.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Network Charging and Control</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2790722.1</URL>
            <ProductID>P-4623V-6.0.1.0</ProductID>
            <ProductID>P-4623V-12.0.1.0-12.0.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="179" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-21290</Title>
      <Notes>
         <Note Audience="All" Ordinal="179" Title="Details" Type="Details">Vulnerability in the Oracle Communications Design Studio product of Oracle Communications Applications (component: Modeling (Netty)).   The supported version that is affected is 7.4.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Design Studio executes to compromise Oracle Communications Design Studio.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Design Studio accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-21290</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2283V-7.4.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Design Studio</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2789906.1</URL>
            <ProductID>P-2283V-7.4.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="180" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-21290</Title>
      <Notes>
         <Note Audience="All" Ordinal="180" Title="Details" Type="Details">Vulnerability in the Oracle Hospitality Suite8 product of Oracle Hospitality Applications (component: Spa and Leisure (Netty)).  Supported versions that are affected are 8.13 and  8.14. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hospitality Suite8 executes to compromise Oracle Hospitality Suite8.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hospitality Suite8 accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-21290</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12614V-8.13</ProductID>
            <ProductID>P-12614V-8.14</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MICROS BellaVita</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2785669.1</URL>
            <ProductID>P-12614V-8.13</ProductID>
            <ProductID>P-12614V-8.14</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="181" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-21290</Title>
      <Notes>
         <Note Audience="All" Ordinal="181" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search (Netty)).  Supported versions that are affected are 8.57, 8.58 and  8.59. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-21290</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>PeopleSoft Enterprise PT PeopleTools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788006.1</URL>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="182" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-21345</Title>
      <Notes>
         <Note Audience="All" Ordinal="182" Title="Details" Type="Details">Vulnerability in the Oracle BAM (Business Activity Monitoring) product of Oracle Fusion Middleware (component: General (XStream)).  Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BAM (Business Activity Monitoring).  While the vulnerability is in Oracle BAM (Business Activity Monitoring), attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle BAM (Business Activity Monitoring). CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-21345</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1675V-11.1.1.9.0</ProductID>
            <ProductID>P-1675V-12.2.1.3.0</ProductID>
            <ProductID>P-1675V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.9</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>BAM (Business Activity Monitoring)</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-1675V-11.1.1.9.0</ProductID>
            <ProductID>P-1675V-12.2.1.3.0</ProductID>
            <ProductID>P-1675V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="183" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-21345</Title>
      <Notes>
         <Note Audience="All" Ordinal="183" Title="Details" Type="Details">Vulnerability in the Oracle Banking Enterprise Default Management product of Oracle Financial Services Applications (component: Collections (XStream)).  Supported versions that are affected are 2.10.0 and 
2.12.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Enterprise Default Management.  While the vulnerability is in Oracle Banking Enterprise Default Management, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Enterprise Default Management. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-21345</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13390V-2.10.0</ProductID>
            <ProductID>P-13390V-2.12.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.9</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Enterprise Default Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787695.1</URL>
            <ProductID>P-13390V-2.10.0</ProductID>
            <ProductID>P-13390V-2.12.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="184" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-21345</Title>
      <Notes>
         <Note Audience="All" Ordinal="184" Title="Details" Type="Details">Vulnerability in the Oracle Banking Platform product of Oracle Financial Services Applications (component: Collections (XStream)).  Supported versions that are affected are 2.4.0, 
2.7.1,
2.9.0 and 
2.12.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Platform.  While the vulnerability is in Oracle Banking Platform, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Platform. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-21345</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9178V-2.4.0</ProductID>
            <ProductID>P-9178V-2.7.1</ProductID>
            <ProductID>P-9178V-2.9.0</ProductID>
            <ProductID>P-9178V-2.12.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.9</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Banking Platform</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787695.1</URL>
            <ProductID>P-9178V-2.4.0</ProductID>
            <ProductID>P-9178V-2.7.1</ProductID>
            <ProductID>P-9178V-2.9.0</ProductID>
            <ProductID>P-9178V-2.12.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="185" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-21345</Title>
      <Notes>
         <Note Audience="All" Ordinal="185" Title="Details" Type="Details">Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications Applications (component: CN ECE (XStream)).   The supported version that is affected is 12.0.0.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  While the vulnerability is in Oracle Communications BRM - Elastic Charging Engine, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Communications BRM - Elastic Charging Engine. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-21345</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9742V-12.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.9</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications BRM - Elastic Charging Engine</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2785183.1</URL>
            <ProductID>P-9742V-12.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="186" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-21345</Title>
      <Notes>
         <Note Audience="All" Ordinal="186" Title="Details" Type="Details">Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Drools Ruleset (XStream)).  Supported versions that are affected are 7.3.2, 
7.3.4, 
7.3.5, 
7.4.0 and 
7.4.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  While the vulnerability is in Oracle Communications Unified Inventory Management, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-21345</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4516V-7.3.2</ProductID>
            <ProductID>P-4516V-7.3.4</ProductID>
            <ProductID>P-4516V-7.3.5</ProductID>
            <ProductID>P-4516V-7.4.0</ProductID>
            <ProductID>P-4516V-7.4.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.9</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Unified Inventory Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2785180.1</URL>
            <ProductID>P-4516V-7.3.2</ProductID>
            <ProductID>P-4516V-7.3.4</ProductID>
            <ProductID>P-4516V-7.3.5</ProductID>
            <ProductID>P-4516V-7.4.0</ProductID>
            <ProductID>P-4516V-7.4.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="187" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-21345</Title>
      <Notes>
         <Note Audience="All" Ordinal="187" Title="Details" Type="Details">Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (XStream)).  Supported versions that are affected are 16.0.6, 
17.0.4, 
18.0.3 and 
19.0.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  While the vulnerability is in Oracle Retail Xstore Point of Service, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-21345</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11513V-16.0.6</ProductID>
            <ProductID>P-11513V-17.0.4</ProductID>
            <ProductID>P-11513V-18.0.3</ProductID>
            <ProductID>P-11513V-19.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.9</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Xstore Point of Service</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783353.1</URL>
            <ProductID>P-11513V-16.0.6</ProductID>
            <ProductID>P-11513V-17.0.4</ProductID>
            <ProductID>P-11513V-18.0.3</ProductID>
            <ProductID>P-11513V-19.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="188" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-21345</Title>
      <Notes>
         <Note Audience="All" Ordinal="188" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework (XStream)).  Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal.  While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-21345</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1696V-11.1.1.9.0</ProductID>
            <ProductID>P-1696V-12.2.1.3.0</ProductID>
            <ProductID>P-1696V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.9</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebCenter Portal</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-1696V-11.1.1.9.0</ProductID>
            <ProductID>P-1696V-12.2.1.3.0</ProductID>
            <ProductID>P-1696V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="189" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-21409</Title>
      <Notes>
         <Note Audience="All" Ordinal="189" Title="Details" Type="Details">Vulnerability in the Primavera Gateway product of Oracle Construction and Engineering (component: Admin (Netty)).  Supported versions that are affected are 17.12.0-17.12.11, 18.8.0-18.8.11 and  19.12.0-19.12.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Gateway.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Primavera Gateway accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-21409</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10605V-17.12.0-17.12.11</ProductID>
            <ProductID>P-10605V-18.8.0-18.8.11</ProductID>
            <ProductID>P-10605V-19.12.0-19.12.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera Gateway</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783281.1</URL>
            <ProductID>P-10605V-17.12.0-17.12.11</ProductID>
            <ProductID>P-10605V-18.8.0-18.8.11</ProductID>
            <ProductID>P-10605V-19.12.0-19.12.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="190" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-22112</Title>
      <Notes>
         <Note Audience="All" Ordinal="190" Title="Details" Type="Details">Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: REST API (Spring Security)).   The supported version that is affected is 7.4.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-22112</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4516V-7.4.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Unified Inventory Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2785180.1</URL>
            <ProductID>P-4516V-7.4.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="191" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-22112</Title>
      <Notes>
         <Note Audience="All" Ordinal="191" Title="Details" Type="Details">Vulnerability in the Oracle Insurance Policy Administration product of Oracle Insurance Applications (component: Architecture (Spring Security)).  Supported versions that are affected are 11.2.0 and  11.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Insurance Policy Administration.  Successful attacks of this vulnerability can result in takeover of Oracle Insurance Policy Administration. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-22112</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5279V-11.2.0</ProductID>
            <ProductID>P-5279V-11.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Insurance Policy Administration J2EE</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2784893.1</URL>
            <ProductID>P-5279V-11.2.0</ProductID>
            <ProductID>P-5279V-11.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="192" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-22118</Title>
      <Notes>
         <Note Audience="All" Ordinal="192" Title="Details" Type="Details">Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration Bugs (Spring Framework)).  Supported versions that are affected are 16.0.3.0, 15.0.3.1 and  14.1.3.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Retail Financial Integration executes to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Financial Integration. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-22118</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10722V-16.0.3.0</ProductID>
            <ProductID>P-10722V-15.0.3.1</ProductID>
            <ProductID>P-10722V-14.1.3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Financial Integration</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783353.1</URL>
            <ProductID>P-10722V-16.0.3.0</ProductID>
            <ProductID>P-10722V-15.0.3.1</ProductID>
            <ProductID>P-10722V-14.1.3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="193" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-22118</Title>
      <Notes>
         <Note Audience="All" Ordinal="193" Title="Details" Type="Details">Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Spring Framework)).  Supported versions that are affected are 16.0.3.0, 
15.0.3.1 and 
14.1.3.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Retail Integration Bus executes to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-22118</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1807V-16.0.3.0</ProductID>
            <ProductID>P-1807V-15.0.3.1</ProductID>
            <ProductID>P-1807V-14.1.3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Integration Bus</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783353.1</URL>
            <ProductID>P-1807V-16.0.3.0</ProductID>
            <ProductID>P-1807V-15.0.3.1</ProductID>
            <ProductID>P-1807V-14.1.3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="194" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-22118</Title>
      <Notes>
         <Note Audience="All" Ordinal="194" Title="Details" Type="Details">Vulnerability in the Oracle Retail Order Broker product of Oracle Retail Applications (component: System Administration (Spring Framework)).   The supported version that is affected is 16.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Retail Order Broker executes to compromise Oracle Retail Order Broker.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Order Broker. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-22118</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11520V-16.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Order Broker Cloud Service</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783353.1</URL>
            <ProductID>P-11520V-16.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="195" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2244</Title>
      <Notes>
         <Note Audience="All" Ordinal="195" Title="Details" Type="Details">Vulnerability in the Essbase Analytic Provider Services product of Oracle Essbase (component: JAPI).   The supported version that is affected is 21.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Essbase Analytic Provider Services.  While the vulnerability is in Essbase Analytic Provider Services, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Essbase Analytic Provider Services. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2244</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4349V-21.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Hyperion Analytic Provider Services</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-4349V-21.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="196" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-22884</Title>
      <Notes>
         <Note Audience="All" Ordinal="196" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: JS module (Node.js)).  Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-22884</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8479V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="197" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-22884</Title>
      <Notes>
         <Note Audience="All" Ordinal="197" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search  (Node.js)).  Supported versions that are affected are 8.58 and  8.59. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-22884</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>PeopleSoft Enterprise PT PeopleTools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788006.1</URL>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="198" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-22901</Title>
      <Notes>
         <Note Audience="All" Ordinal="198" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Packaging (curl)).  Supported versions that are affected are 5.7.34 and prior and  8.0.25 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in takeover of MySQL Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-22901</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.34 and prior</ProductID>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-5.7.34 and prior</ProductID>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="199" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2323</Title>
      <Notes>
         <Note Audience="All" Ordinal="199" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Flex-Branch).  Supported versions that are affected are 12.3, 12.4, 14.0-14.4 and . Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle FLEXCUBE Universal Banking accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2323</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9052V-12.3</ProductID>
            <ProductID>P-9052V-12.4</ProductID>
            <ProductID>P-9052V-14.0-14.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>FLEXCUBE Universal Banking</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-9052V-12.3</ProductID>
            <ProductID>P-9052V-12.4</ProductID>
            <ProductID>P-9052V-14.0-14.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="200" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2324</Title>
      <Notes>
         <Note Audience="All" Ordinal="200" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Loans And Deposits).  Supported versions that are affected are 12.0-12.4, 
14.0-14.4 and . Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle FLEXCUBE Universal Banking accessible data as well as  unauthorized read access to a subset of Oracle FLEXCUBE Universal Banking accessible data. CVSS 3.1 Base Score 4.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2324</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9052V-12.0-12.4</ProductID>
            <ProductID>P-9052V-14.0-14.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.6</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>FLEXCUBE Universal Banking</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-9052V-12.0-12.4</ProductID>
            <ProductID>P-9052V-14.0-14.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="201" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2326</Title>
      <Notes>
         <Note Audience="All" Ordinal="201" Title="Details" Type="Details">Vulnerability in the Database Vault component of Oracle Database Server.  Supported versions that are affected are 12.2.0.1 and  19c. Easily exploitable vulnerability allows high privileged attacker having DBA privilege with network access via Oracle Net to compromise Database Vault.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Database Vault accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2326</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.7</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Database - Enterprise Edition</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="202" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2328</Title>
      <Notes>
         <Note Audience="All" Ordinal="202" Title="Details" Type="Details">Vulnerability in the Oracle Text component of Oracle Database Server.  Supported versions that are affected are 12.1.0.2, 12.2.0.1 and  19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Procedure, Alter Any Table privilege with network access via Oracle Net to compromise Oracle Text.  Successful attacks of this vulnerability can result in takeover of Oracle Text. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2328</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-211V-12.1.0.2</ProductID>
            <ProductID>P-211V-12.2.0.1</ProductID>
            <ProductID>P-211V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.2</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Text</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-211V-12.1.0.2</ProductID>
            <ProductID>P-211V-12.2.0.1</ProductID>
            <ProductID>P-211V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="203" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2329</Title>
      <Notes>
         <Note Audience="All" Ordinal="203" Title="Details" Type="Details">Vulnerability in the Oracle XML DB component of Oracle Database Server.  Supported versions that are affected are 12.1.0.2, 12.2.0.1 and  19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Procedure, Create Public Synonym privilege with network access via Oracle Net to compromise Oracle XML DB.  Successful attacks of this vulnerability can result in takeover of Oracle XML DB. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2329</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.2</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Database - Enterprise Edition</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="204" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2330</Title>
      <Notes>
         <Note Audience="All" Ordinal="204" Title="Details" Type="Details">Vulnerability in the Core RDBMS component of Oracle Database Server.   The supported version that is affected is 19c. Easily exploitable vulnerability allows low privileged attacker having Create Table privilege with network access via Oracle Net to compromise Core RDBMS.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Core RDBMS. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2330</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Database - Enterprise Edition</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-5V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="205" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2333</Title>
      <Notes>
         <Note Audience="All" Ordinal="205" Title="Details" Type="Details">Vulnerability in the Oracle XML DB component of Oracle Database Server.  Supported versions that are affected are 12.1.0.2, 12.2.0.1 and  19c. Easily exploitable vulnerability allows high privileged attacker having Alter User privilege with network access via Oracle Net to compromise Oracle XML DB.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle XML DB accessible data. CVSS 3.1 Base Score 4.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2333</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Database - Enterprise Edition</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="206" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-23336</Title>
      <Notes>
         <Note Audience="All" Ordinal="206" Title="Details" Type="Details">Security-in-Depth issue in the RDBMS (Python) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-23336</CVE>
      <ProductStatuses>
         <Status Type="Known Not Affected">
            <ProductID>P-5V-All Supported Versions</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Database - Enterprise Edition</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-5V-All Supported Versions</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="207" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2334</Title>
      <Notes>
         <Note Audience="All" Ordinal="207" Title="Details" Type="Details">Vulnerability in the Oracle Database - Enterprise Edition Data Redaction component of Oracle Database Server.  Supported versions that are affected are 12.1.0.2, 12.2.0.1 and  19c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Database - Enterprise Edition Data Redaction.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Database - Enterprise Edition Data Redaction accessible data. CVSS 3.1 Base Score 3.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2334</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Database - Enterprise Edition</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="208" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2335</Title>
      <Notes>
         <Note Audience="All" Ordinal="208" Title="Details" Type="Details">Vulnerability in the Oracle Database - Enterprise Edition Data Redaction component of Oracle Database Server.  Supported versions that are affected are 12.1.0.2, 12.2.0.1 and  19c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Database - Enterprise Edition Data Redaction.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Database - Enterprise Edition Data Redaction accessible data. CVSS 3.1 Base Score 3.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2335</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Database - Enterprise Edition</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="209" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2336</Title>
      <Notes>
         <Note Audience="All" Ordinal="209" Title="Details" Type="Details">Vulnerability in the Oracle Database - Enterprise Edition Data Redaction component of Oracle Database Server.  Supported versions that are affected are 12.1.0.2, 12.2.0.1 and  19c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Database - Enterprise Edition Data Redaction.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Database - Enterprise Edition Data Redaction accessible data. CVSS 3.1 Base Score 3.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2336</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Database - Enterprise Edition</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="210" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2337</Title>
      <Notes>
         <Note Audience="All" Ordinal="210" Title="Details" Type="Details">Vulnerability in the Oracle XML DB component of Oracle Database Server.  Supported versions that are affected are 12.1.0.2, 12.2.0.1 and  19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Procedure, Create Public Synonym privilege with network access via Oracle Net to compromise Oracle XML DB.  Successful attacks of this vulnerability can result in takeover of Oracle XML DB. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2337</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.2</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Database - Enterprise Edition</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="211" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2338</Title>
      <Notes>
         <Note Audience="All" Ordinal="211" Title="Details" Type="Details">Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Email Marketing Stand-Alone).  Supported versions that are affected are 21.5 and Prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel Apps - Marketing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel Apps - Marketing accessible data as well as  unauthorized read access to a subset of Siebel Apps - Marketing accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2338</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8974V-21.5 and Prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Siebel Apps - Marketing</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787995.1</URL>
            <ProductID>P-8974V-21.5 and Prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="212" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2339</Title>
      <Notes>
         <Note Audience="All" Ordinal="212" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL).  Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2339</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="213" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2340</Title>
      <Notes>
         <Note Audience="All" Ordinal="213" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Memcached).  Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 2.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2340</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.7</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="214" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2341</Title>
      <Notes>
         <Note Audience="All" Ordinal="214" Title="Details" Type="Details">Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking).  Supported versions that are affected are Java SE: 7u301, 8u291, 11.0.11, 16.0.1; Oracle GraalVM Enterprise Edition: 20.3.2 and  21.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Java SE, Oracle GraalVM Enterprise Edition accessible data.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2341</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE:7u301</ProductID>
            <ProductID>P-856V-Java SE:8u291</ProductID>
            <ProductID>P-856V-Java SE:11.0.11</ProductID>
            <ProductID>P-856V-Java SE:16.0.1</ProductID>
            <ProductID>P-13497V-Oracle GraalVM Enterprise Edition:20.3.2</ProductID>
            <ProductID>P-13497V-Oracle GraalVM Enterprise Edition:21.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Java SE JDK and JRE</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787003.1</URL>
            <ProductID>P-856V-Java SE:7u301</ProductID>
            <ProductID>P-856V-Java SE:8u291</ProductID>
            <ProductID>P-856V-Java SE:11.0.11</ProductID>
            <ProductID>P-856V-Java SE:16.0.1</ProductID>
            <ProductID>P-13497V-Oracle GraalVM Enterprise Edition:20.3.2</ProductID>
            <ProductID>P-13497V-Oracle GraalVM Enterprise Edition:21.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="215" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2342</Title>
      <Notes>
         <Note Audience="All" Ordinal="215" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 5.7.34 and prior and  8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2342</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.34 and prior</ProductID>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-5.7.34 and prior</ProductID>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="216" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2343</Title>
      <Notes>
         <Note Audience="All" Ordinal="216" Title="Details" Type="Details">Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer).  Supported versions that are affected are 12.1.3 and  12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Workflow.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Workflow accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2343</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-174V-12.1.3</ProductID>
            <ProductID>P-174V-12.2.3-12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Workflow</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2770321.1</URL>
            <ProductID>P-174V-12.1.3</ProductID>
            <ProductID>P-174V-12.2.3-12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="217" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2344</Title>
      <Notes>
         <Note Audience="All" Ordinal="217" Title="Details" Type="Details">Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2344</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2545V-3.7.1.0</ProductID>
            <ProductID>P-2545V-12.1.3.0.0</ProductID>
            <ProductID>P-2545V-12.2.1.3.0</ProductID>
            <ProductID>P-2545V-12.2.1.4.0</ProductID>
            <ProductID>P-2545V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Coherence</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-2545V-3.7.1.0</ProductID>
            <ProductID>P-2545V-12.1.3.0.0</ProductID>
            <ProductID>P-2545V-12.2.1.3.0</ProductID>
            <ProductID>P-2545V-12.2.1.4.0</ProductID>
            <ProductID>P-2545V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="218" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2345</Title>
      <Notes>
         <Note Audience="All" Ordinal="218" Title="Details" Type="Details">Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Tools and Frameworks).   The supported version that is affected is 11.3.1.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as  unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2345</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9633V-11.3.1.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Commerce Guided Search / Oracle Commerce Experience Manager</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2792990.1</URL>
            <ProductID>P-9633V-11.3.1.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="219" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2346</Title>
      <Notes>
         <Note Audience="All" Ordinal="219" Title="Details" Type="Details">Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Tools and Frameworks).   The supported version that is affected is 11.3.1.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as  unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2346</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9633V-11.3.1.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Commerce Guided Search / Oracle Commerce Experience Manager</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2792990.1</URL>
            <ProductID>P-9633V-11.3.1.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="220" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2347</Title>
      <Notes>
         <Note Audience="All" Ordinal="220" Title="Details" Type="Details">Vulnerability in the Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management).   The supported version that is affected is 11.2.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Infrastructure Technology.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Hyperion Infrastructure Technology accessible data as well as  unauthorized update, insert or delete access to some of Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2347</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4392V-11.2.5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.2</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Hyperion Infrastructure Technology</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-4392V-11.2.5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="221" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2348</Title>
      <Notes>
         <Note Audience="All" Ordinal="221" Title="Details" Type="Details">Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Tools and Frameworks).   The supported version that is affected is 11.3.1.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2348</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9633V-11.3.1.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Commerce Guided Search / Oracle Commerce Experience Manager</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2792990.1</URL>
            <ProductID>P-9633V-11.3.1.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="222" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2349</Title>
      <Notes>
         <Note Audience="All" Ordinal="222" Title="Details" Type="Details">Vulnerability in the Hyperion Essbase Administration Services product of Oracle Essbase (component: EAS Console).  Supported versions that are affected are 11.1.2.4 and  21.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Essbase Administration Services.  While the vulnerability is in Hyperion Essbase Administration Services, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Hyperion Essbase Administration Services accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2349</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4380V-11.1.2.4</ProductID>
            <ProductID>P-4380V-21.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Hyperion Essbase Administration Services</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-4380V-11.1.2.4</ProductID>
            <ProductID>P-4380V-21.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="223" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2350</Title>
      <Notes>
         <Note Audience="All" Ordinal="223" Title="Details" Type="Details">Vulnerability in the Hyperion Essbase Administration Services product of Oracle Essbase (component: EAS Console).  Supported versions that are affected are 11.1.2.4 and  21.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Essbase Administration Services.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Hyperion Essbase Administration Services accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2350</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4380V-11.1.2.4</ProductID>
            <ProductID>P-4380V-21.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Hyperion Essbase Administration Services</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-4380V-11.1.2.4</ProductID>
            <ProductID>P-4380V-21.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="224" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2351</Title>
      <Notes>
         <Note Audience="All" Ordinal="224" Title="Details" Type="Details">Vulnerability in the Advanced Networking Option component of Oracle Database Server.  Supported versions that are affected are 12.1.0.2, 12.2.0.1 and  19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Advanced Networking Option, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Advanced Networking Option.  Note: The July 2021 Critical Patch Update introduces a number of Native Network Encryption changes to deal with vulnerability CVE-2021-2351 and prevent the use of weaker ciphers.  Customers should review: “Changes in Native Network Encryption with the July 2021 Critical Patch Update” (&lt;a href="https://support.oracle.com/rs?type=doc&amp;id=2791571.1"&gt;Doc ID 2791571.1&lt;/a&gt;). CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2351</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-219V-12.1.0.2</ProductID>
            <ProductID>P-219V-12.2.0.1</ProductID>
            <ProductID>P-219V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Advanced Networking Option</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-219V-12.1.0.2</ProductID>
            <ProductID>P-219V-12.2.0.1</ProductID>
            <ProductID>P-219V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="225" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2352</Title>
      <Notes>
         <Note Audience="All" Ordinal="225" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL).  Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2352</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="226" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2353</Title>
      <Notes>
         <Note Audience="All" Ordinal="226" Title="Details" Type="Details">Vulnerability in the Siebel Core - Server Framework product of Oracle Siebel CRM (component: Loging).  Supported versions that are affected are 21.5 and Prior. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Siebel Core - Server Framework executes to compromise Siebel Core - Server Framework.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel Core - Server Framework accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2353</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9001V-21.5 and Prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.4</BaseScore>
            <Vector>AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Siebel Core - Server Framework</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787995.1</URL>
            <ProductID>P-9001V-21.5 and Prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="227" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2354</Title>
      <Notes>
         <Note Audience="All" Ordinal="227" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Federated).  Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2354</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="228" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2355</Title>
      <Notes>
         <Note Audience="All" Ordinal="228" Title="Details" Type="Details">Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration).  Supported versions that are affected are 12.1.1-12.1.3 and  12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Marketing accessible data as well as  unauthorized access to critical data or complete access to all Oracle Marketing accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2355</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-229V-12.1.1-12.1.3</ProductID>
            <ProductID>P-229V-12.2.3-12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Marketing</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2770321.1</URL>
            <ProductID>P-229V-12.1.1-12.1.3</ProductID>
            <ProductID>P-229V-12.2.3-12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="229" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2356</Title>
      <Notes>
         <Note Audience="All" Ordinal="229" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are 5.7.34 and prior and  8.0.25 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.9 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2356</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.34 and prior</ProductID>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-5.7.34 and prior</ProductID>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="230" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2357</Title>
      <Notes>
         <Note Audience="All" Ordinal="230" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2357</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="231" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2358</Title>
      <Notes>
         <Note Audience="All" Ordinal="231" Title="Details" Type="Details">Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Rest interfaces for Access Mgr).   The supported version that is affected is 11.1.2.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Access Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 4.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2358</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5565V-11.1.2.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Access Manager</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-5565V-11.1.2.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="232" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2359</Title>
      <Notes>
         <Note Audience="All" Ordinal="232" Title="Details" Type="Details">Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration).  Supported versions that are affected are 12.1.1-12.1.3 and  12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Marketing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Marketing accessible data as well as  unauthorized update, insert or delete access to some of Oracle Marketing accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2359</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-229V-12.1.1-12.1.3</ProductID>
            <ProductID>P-229V-12.2.3-12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Marketing</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2770321.1</URL>
            <ProductID>P-229V-12.1.1-12.1.3</ProductID>
            <ProductID>P-229V-12.2.3-12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="233" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2360</Title>
      <Notes>
         <Note Audience="All" Ordinal="233" Title="Details" Type="Details">Vulnerability in the Oracle Approvals Management product of Oracle E-Business Suite (component: AME Page rendering).  Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Approvals Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Approvals Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Approvals Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2360</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1168V-12.1.1-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Approvals Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2770321.1</URL>
            <ProductID>P-1168V-12.1.1-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="234" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2361</Title>
      <Notes>
         <Note Audience="All" Ordinal="234" Title="Details" Type="Details">Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: SDK client integration).  Supported versions that are affected are 12.1.1-12.1.3 and  12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Inbound Telephony.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Advanced Inbound Telephony accessible data as well as  unauthorized access to critical data or complete access to all Oracle Advanced Inbound Telephony accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2361</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-265V-12.1.1-12.1.3</ProductID>
            <ProductID>P-265V-12.2.3-12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Advanced Inbound Telephony</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2770321.1</URL>
            <ProductID>P-265V-12.1.1-12.1.3</ProductID>
            <ProductID>P-265V-12.2.3-12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="235" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2362</Title>
      <Notes>
         <Note Audience="All" Ordinal="235" Title="Details" Type="Details">Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Wireless).  Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Field Service accessible data as well as  unauthorized access to critical data or complete access to all Oracle Field Service accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2362</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-747V-12.1.1-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Field Service</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2770321.1</URL>
            <ProductID>P-747V-12.1.1-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="236" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2363</Title>
      <Notes>
         <Note Audience="All" Ordinal="236" Title="Details" Type="Details">Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization).  Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials (International).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Public Sector Financials (International) accessible data as well as  unauthorized access to critical data or complete access to all Oracle Public Sector Financials (International) accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2363</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-26V-12.1.1-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Public Sector Financials (International)</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2770321.1</URL>
            <ProductID>P-26V-12.1.1-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="237" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2364</Title>
      <Notes>
         <Note Audience="All" Ordinal="237" Title="Details" Type="Details">Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Accounts).  Supported versions that are affected are 12.1.1-12.1.3 and  12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSupplier Portal.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle iSupplier Portal accessible data as well as  unauthorized access to critical data or complete access to all Oracle iSupplier Portal accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2364</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-208V-12.1.1-12.1.3</ProductID>
            <ProductID>P-208V-12.2.3-12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>iSupplier Portal</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2770321.1</URL>
            <ProductID>P-208V-12.1.1-12.1.3</ProductID>
            <ProductID>P-208V-12.2.3-12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="238" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2365</Title>
      <Notes>
         <Note Audience="All" Ordinal="238" Title="Details" Type="Details">Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: People Management).  Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Human Resources.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Human Resources accessible data as well as  unauthorized access to critical data or complete access to all Oracle Human Resources accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2365</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-507V-12.1.1-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Human Resources</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2770321.1</URL>
            <ProductID>P-507V-12.1.1-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="239" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2366</Title>
      <Notes>
         <Note Audience="All" Ordinal="239" Title="Details" Type="Details">Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access).  Supported versions that are affected are 17.12.0-17.12.20, 18.8.0-18.8.23,  19.12.0-19.12.14 and  20.12.0-20.12.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management.  While the vulnerability is in Primavera P6 Enterprise Project Portfolio Management, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera P6 Enterprise Project Portfolio Management accessible data as well as  unauthorized read access to a subset of Primavera P6 Enterprise Project Portfolio Management accessible data. CVSS 3.1 Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2366</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5579V-17.12.0-17.12.20</ProductID>
            <ProductID>P-5579V-18.8.0-18.8.23</ProductID>
            <ProductID>P-5579V-19.12.0-19.12.14</ProductID>
            <ProductID>P-5579V-20.12.0-20.12.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera P6 Enterprise Project Portfolio Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783281.1</URL>
            <ProductID>P-5579V-17.12.0-17.12.20</ProductID>
            <ProductID>P-5579V-18.8.0-18.8.23</ProductID>
            <ProductID>P-5579V-19.12.0-19.12.14</ProductID>
            <ProductID>P-5579V-20.12.0-20.12.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="240" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2367</Title>
      <Notes>
         <Note Audience="All" Ordinal="240" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2367</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="241" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2368</Title>
      <Notes>
         <Note Audience="All" Ordinal="241" Title="Details" Type="Details">Vulnerability in the Siebel CRM product of Oracle Siebel CRM (component: Siebel Core - Server Infrastructure).  Supported versions that are affected are 21.5 and Prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2368</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9001V-21.5 and Prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Siebel Core - Server Framework</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787995.1</URL>
            <ProductID>P-9001V-21.5 and Prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="242" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2369</Title>
      <Notes>
         <Note Audience="All" Ordinal="242" Title="Details" Type="Details">Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Library).  Supported versions that are affected are Java SE: 7u301, 8u291, 11.0.11, 16.0.1; Oracle GraalVM Enterprise Edition: 20.3.2 and  21.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Java SE, Oracle GraalVM Enterprise Edition accessible data.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2369</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE:7u301</ProductID>
            <ProductID>P-856V-Java SE:8u291</ProductID>
            <ProductID>P-856V-Java SE:11.0.11</ProductID>
            <ProductID>P-856V-Java SE:16.0.1</ProductID>
            <ProductID>P-13497V-Oracle GraalVM Enterprise Edition:20.3.2</ProductID>
            <ProductID>P-13497V-Oracle GraalVM Enterprise Edition:21.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Java SE JDK and JRE</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787003.1</URL>
            <ProductID>P-856V-Java SE:7u301</ProductID>
            <ProductID>P-856V-Java SE:8u291</ProductID>
            <ProductID>P-856V-Java SE:11.0.11</ProductID>
            <ProductID>P-856V-Java SE:16.0.1</ProductID>
            <ProductID>P-13497V-Oracle GraalVM Enterprise Edition:20.3.2</ProductID>
            <ProductID>P-13497V-Oracle GraalVM Enterprise Edition:21.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="243" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2370</Title>
      <Notes>
         <Note Audience="All" Ordinal="243" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML).  Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2370</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="244" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2371</Title>
      <Notes>
         <Note Audience="All" Ordinal="244" Title="Details" Type="Details">Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2371</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2545V-3.7.1.0</ProductID>
            <ProductID>P-2545V-12.1.3.0.0</ProductID>
            <ProductID>P-2545V-12.2.1.3.0</ProductID>
            <ProductID>P-2545V-12.2.1.4.0</ProductID>
            <ProductID>P-2545V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Coherence</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-2545V-3.7.1.0</ProductID>
            <ProductID>P-2545V-12.1.3.0.0</ProductID>
            <ProductID>P-2545V-12.2.1.3.0</ProductID>
            <ProductID>P-2545V-12.2.1.4.0</ProductID>
            <ProductID>P-2545V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="245" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2372</Title>
      <Notes>
         <Note Audience="All" Ordinal="245" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 5.7.34 and prior and  8.0.25 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2372</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.34 and prior</ProductID>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.4</BaseScore>
            <Vector>AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-5.7.34 and prior</ProductID>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="246" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2373</Title>
      <Notes>
         <Note Audience="All" Ordinal="246" Title="Details" Type="Details">Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime).  Supported versions that are affected are 9.2.5.3 and Prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as  unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2373</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4781V-9.2.5.3 and Prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>JD Edwards EnterpriseOne Tools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787996.1</URL>
            <ProductID>P-4781V-9.2.5.3 and Prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="247" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2374</Title>
      <Notes>
         <Note Audience="All" Ordinal="247" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.25 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.1 Base Score 4.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2374</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.1</BaseScore>
            <Vector>AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="248" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2375</Title>
      <Notes>
         <Note Audience="All" Ordinal="248" Title="Details" Type="Details">Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime).  Supported versions that are affected are 9.2.5.3 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as  unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2375</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4781V-9.2.5.3 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>JD Edwards EnterpriseOne Tools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787996.1</URL>
            <ProductID>P-4781V-9.2.5.3 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="249" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2376</Title>
      <Notes>
         <Note Audience="All" Ordinal="249" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services).  Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2376</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.3.6.0.0</ProductID>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-5242V-10.3.6.0.0</ProductID>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="250" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2377</Title>
      <Notes>
         <Note Audience="All" Ordinal="250" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR).  Supported versions that are affected are 8.57, 8.58 and  8.59. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2377</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>PeopleSoft Enterprise PT PeopleTools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788006.1</URL>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="251" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2378</Title>
      <Notes>
         <Note Audience="All" Ordinal="251" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2378</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.3.6.0.0</ProductID>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-5242V-10.3.6.0.0</ProductID>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="252" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2380</Title>
      <Notes>
         <Note Audience="All" Ordinal="252" Title="Details" Type="Details">Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments / File Upload).  Supported versions that are affected are 12.1.3 and  12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Applications Framework accessible data as well as  unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2380</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1472V-12.1.3</ProductID>
            <ProductID>P-1472V-12.2.3-12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.6</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Applications Framework</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2770321.1</URL>
            <ProductID>P-1472V-12.1.3</ProductID>
            <ProductID>P-1472V-12.2.3-12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="253" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2381</Title>
      <Notes>
         <Note Audience="All" Ordinal="253" Title="Details" Type="Details">Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel).   The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Solaris accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Solaris. CVSS 3.1 Base Score 3.9 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2381</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.9</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Solaris Operating System</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788472.1</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="254" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2382</Title>
      <Notes>
         <Note Audience="All" Ordinal="254" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Security).  Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2382</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.3.6.0.0</ProductID>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-5242V-10.3.6.0.0</ProductID>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="255" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2383</Title>
      <Notes>
         <Note Audience="All" Ordinal="255" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2383</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="256" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2384</Title>
      <Notes>
         <Note Audience="All" Ordinal="256" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2384</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="257" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2385</Title>
      <Notes>
         <Note Audience="All" Ordinal="257" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are 5.7.34 and prior and  8.0.25 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.0 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2385</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.34 and prior</ProductID>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.0</BaseScore>
            <Vector>AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-5.7.34 and prior</ProductID>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="258" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2386</Title>
      <Notes>
         <Note Audience="All" Ordinal="258" Title="Details" Type="Details">Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access).  Supported versions that are affected are 20.12.0-20.12.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Primavera P6 Enterprise Project Portfolio Management accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2386</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5579V-20.12.0-20.12.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera P6 Enterprise Project Portfolio Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783281.1</URL>
            <ProductID>P-5579V-20.12.0-20.12.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="259" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2387</Title>
      <Notes>
         <Note Audience="All" Ordinal="259" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2387</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="260" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2388</Title>
      <Notes>
         <Note Audience="All" Ordinal="260" Title="Details" Type="Details">Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot).  Supported versions that are affected are Java SE: 8u291, 11.0.11, 16.0.1; Oracle GraalVM Enterprise Edition: 20.3.2 and  21.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Java SE, Oracle GraalVM Enterprise Edition.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2388</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE:8u291</ProductID>
            <ProductID>P-856V-Java SE:11.0.11</ProductID>
            <ProductID>P-856V-Java SE:16.0.1</ProductID>
            <ProductID>P-13497V-Oracle GraalVM Enterprise Edition:20.3.2</ProductID>
            <ProductID>P-13497V-Oracle GraalVM Enterprise Edition:21.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Java SE JDK and JRE</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787003.1</URL>
            <ProductID>P-856V-Java SE:8u291</ProductID>
            <ProductID>P-856V-Java SE:11.0.11</ProductID>
            <ProductID>P-856V-Java SE:16.0.1</ProductID>
            <ProductID>P-13497V-Oracle GraalVM Enterprise Edition:20.3.2</ProductID>
            <ProductID>P-13497V-Oracle GraalVM Enterprise Edition:21.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="261" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2389</Title>
      <Notes>
         <Note Audience="All" Ordinal="261" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 5.7.34 and prior and  8.0.25 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2389</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.34 and prior</ProductID>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-5.7.34 and prior</ProductID>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="262" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2390</Title>
      <Notes>
         <Note Audience="All" Ordinal="262" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 5.7.34 and prior and  8.0.25 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2390</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.34 and prior</ProductID>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-5.7.34 and prior</ProductID>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="263" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2391</Title>
      <Notes>
         <Note Audience="All" Ordinal="263" Title="Details" Type="Details">Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Scheduler).  Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2391</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1479V-5.5.0.0.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
            <ProductID>P-1479V-12.2.1.3.0</ProductID>
            <ProductID>P-1479V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>BI Publisher (formerly XML Publisher)</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-1479V-5.5.0.0.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
            <ProductID>P-1479V-12.2.1.3.0</ProductID>
            <ProductID>P-1479V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="264" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2392</Title>
      <Notes>
         <Note Audience="All" Ordinal="264" Title="Details" Type="Details">Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security).  Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2392</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1479V-5.5.0.0.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
            <ProductID>P-1479V-12.2.1.3.0</ProductID>
            <ProductID>P-1479V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>BI Publisher (formerly XML Publisher)</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-1479V-5.5.0.0.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
            <ProductID>P-1479V-12.2.1.3.0</ProductID>
            <ProductID>P-1479V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="265" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2393</Title>
      <Notes>
         <Note Audience="All" Ordinal="265" Title="Details" Type="Details">Vulnerability in the Oracle E-Records product of Oracle E-Business Suite (component: E-signatures).  Supported versions that are affected are 12.1.1-12.1.3 and  12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle E-Records.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle E-Records accessible data as well as  unauthorized access to critical data or complete access to all Oracle E-Records accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2393</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1325V-12.1.1-12.1.3</ProductID>
            <ProductID>P-1325V-12.2.3-12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>E-Records</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2770321.1</URL>
            <ProductID>P-1325V-12.1.1-12.1.3</ProductID>
            <ProductID>P-1325V-12.2.3-12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="266" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2394</Title>
      <Notes>
         <Note Audience="All" Ordinal="266" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2394</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.3.6.0.0</ProductID>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-5242V-10.3.6.0.0</ProductID>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="267" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2395</Title>
      <Notes>
         <Note Audience="All" Ordinal="267" Title="Details" Type="Details">Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (component: iCare, Configuration).   The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Reporting and Analytics.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hospitality Reporting and Analytics accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hospitality Reporting and Analytics accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2395</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11599V-9.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Hospitality Reporting and Analytics</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2780088.1</URL>
            <ProductID>P-11599V-9.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="268" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2396</Title>
      <Notes>
         <Note Audience="All" Ordinal="268" Title="Details" Type="Details">Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO).  Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2396</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1479V-5.5.0.0.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
            <ProductID>P-1479V-12.2.1.3.0</ProductID>
            <ProductID>P-1479V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>BI Publisher (formerly XML Publisher)</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-1479V-5.5.0.0.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
            <ProductID>P-1479V-12.2.1.3.0</ProductID>
            <ProductID>P-1479V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="269" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2397</Title>
      <Notes>
         <Note Audience="All" Ordinal="269" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2397</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.3.6.0.0</ProductID>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-5242V-10.3.6.0.0</ProductID>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="270" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2398</Title>
      <Notes>
         <Note Audience="All" Ordinal="270" Title="Details" Type="Details">Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Region Mapping).  Supported versions that are affected are 12.1.1-12.1.3 and  12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Advanced Outbound Telephony accessible data as well as  unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2398</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-785V-12.1.1-12.1.3</ProductID>
            <ProductID>P-785V-12.2.3-12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Advanced Outbound Telephony</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2770321.1</URL>
            <ProductID>P-785V-12.1.1-12.1.3</ProductID>
            <ProductID>P-785V-12.2.3-12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="271" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2399</Title>
      <Notes>
         <Note Audience="All" Ordinal="271" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL).  Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2399</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="272" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2400</Title>
      <Notes>
         <Note Audience="All" Ordinal="272" Title="Details" Type="Details">Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO).  Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2400</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1479V-5.5.0.0.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
            <ProductID>P-1479V-12.2.1.3.0</ProductID>
            <ProductID>P-1479V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>BI Publisher (formerly XML Publisher)</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-1479V-5.5.0.0.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
            <ProductID>P-1479V-12.2.1.3.0</ProductID>
            <ProductID>P-1479V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="273" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2401</Title>
      <Notes>
         <Note Audience="All" Ordinal="273" Title="Details" Type="Details">Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO).  Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2401</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1479V-5.5.0.0.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
            <ProductID>P-1479V-12.2.1.3.0</ProductID>
            <ProductID>P-1479V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>BI Publisher (formerly XML Publisher)</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-1479V-5.5.0.0.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
            <ProductID>P-1479V-12.2.1.3.0</ProductID>
            <ProductID>P-1479V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="274" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2402</Title>
      <Notes>
         <Note Audience="All" Ordinal="274" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Locking).  Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2402</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="275" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2403</Title>
      <Notes>
         <Note Audience="All" Ordinal="275" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2403</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.3.6.0.0</ProductID>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>WebLogic Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-5242V-10.3.6.0.0</ProductID>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="276" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2404</Title>
      <Notes>
         <Note Audience="All" Ordinal="276" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise HCM Candidate Gateway product of Oracle PeopleSoft (component: e-mail notification).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Candidate Gateway.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise HCM Candidate Gateway accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise HCM Candidate Gateway accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2404</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5043V-9.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>PeopleSoft Enterprise HCM Candidate Gateway</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788006.1</URL>
            <ProductID>P-5043V-9.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="277" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2405</Title>
      <Notes>
         <Note Audience="All" Ordinal="277" Title="Details" Type="Details">Vulnerability in the Oracle Engineering product of Oracle E-Business Suite (component: Change Management).  Supported versions that are affected are 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Engineering.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Engineering accessible data as well as  unauthorized access to critical data or complete access to all Oracle Engineering accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2405</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-532V-12.2.3-12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Engineering</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2770321.1</URL>
            <ProductID>P-532V-12.2.3-12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="278" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2406</Title>
      <Notes>
         <Note Audience="All" Ordinal="278" Title="Details" Type="Details">Vulnerability in the Oracle Collaborative Planning product of Oracle E-Business Suite (component: User Interface).  Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Collaborative Planning.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Collaborative Planning accessible data as well as  unauthorized access to critical data or complete access to all Oracle Collaborative Planning accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2406</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1037V-12.1.1-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Collaborative Planning</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2770321.1</URL>
            <ProductID>P-1037V-12.1.1-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="279" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2407</Title>
      <Notes>
         <Note Audience="All" Ordinal="279" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal).  Supported versions that are affected are 8.57, 8.58 and  8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2407</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>PeopleSoft Enterprise PT PeopleTools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788006.1</URL>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="280" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2408</Title>
      <Notes>
         <Note Audience="All" Ordinal="280" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Notification Configuration).   The supported version that is affected is 8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PT PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PT PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PT PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2408</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.59</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>PeopleSoft Enterprise PT PeopleTools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788006.1</URL>
            <ProductID>P-5085V-8.59</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="281" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2409</Title>
      <Notes>
         <Note Audience="All" Ordinal="281" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is Prior to 6.1.24. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2409</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-Prior to 6.1.24</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>VM VirtualBox</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788251.1</URL>
            <ProductID>P-8370V-Prior to 6.1.24</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="282" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2410</Title>
      <Notes>
         <Note Audience="All" Ordinal="282" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2410</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="283" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2411</Title>
      <Notes>
         <Note Audience="All" Ordinal="283" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: JS module).  Supported versions that are affected are 8.0.25 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Cluster. CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2411</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Cluster</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8479V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="284" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2412</Title>
      <Notes>
         <Note Audience="All" Ordinal="284" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2412</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="285" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-24122</Title>
      <Notes>
         <Note Audience="All" Ordinal="285" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files &amp; Attachments  (Apache Tomcat)).  Supported versions that are affected are 9.3.3 and  9.3.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-24122</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.3</ProductID>
            <ProductID>P-4461V-9.3.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Agile PLM Framework</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787997.1</URL>
            <ProductID>P-4461V-9.3.3</ProductID>
            <ProductID>P-4461V-9.3.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="286" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2415</Title>
      <Notes>
         <Note Audience="All" Ordinal="286" Title="Details" Type="Details">Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Timecard).  Supported versions that are affected are 12.1.1-12.1.3 and  12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Time and Labor accessible data as well as  unauthorized access to critical data or complete access to all Oracle Time and Labor accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2415</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-311V-12.1.1-12.1.3</ProductID>
            <ProductID>P-311V-12.2.3-12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Time and Labor</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2770321.1</URL>
            <ProductID>P-311V-12.1.1-12.1.3</ProductID>
            <ProductID>P-311V-12.2.3-12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="287" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2417</Title>
      <Notes>
         <Note Audience="All" Ordinal="287" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GIS).  Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as  unauthorized update, insert or delete access to some of MySQL Server accessible data and  unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2417</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.0</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="288" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2418</Title>
      <Notes>
         <Note Audience="All" Ordinal="288" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2418</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="289" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2419</Title>
      <Notes>
         <Note Audience="All" Ordinal="289" Title="Details" Type="Details">Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters).   The supported version that is affected is 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology.  Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS Base Score depend on the software that uses Outside In Technology. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology, but if data is not received over a network the CVSS score may be lower. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2419</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Outside In Technology</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-2276V-8.5.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="290" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2420</Title>
      <Notes>
         <Note Audience="All" Ordinal="290" Title="Details" Type="Details">Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters).   The supported version that is affected is 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology.  Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS Base Score depend on the software that uses Outside In Technology. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology, but if data is not received over a network the CVSS score may be lower. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2420</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Outside In Technology</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-2276V-8.5.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="291" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2421</Title>
      <Notes>
         <Note Audience="All" Ordinal="291" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Interfaces).  Supported versions that are affected are 9.0 and  9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2421</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5183V-9.0</ProductID>
            <ProductID>P-5183V-9.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>PeopleSoft Enterprise CS Campus Community</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788006.1</URL>
            <ProductID>P-5183V-9.0</ProductID>
            <ProductID>P-5183V-9.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="292" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2422</Title>
      <Notes>
         <Note Audience="All" Ordinal="292" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS).  Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2422</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="293" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2423</Title>
      <Notes>
         <Note Audience="All" Ordinal="293" Title="Details" Type="Details">Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters).   The supported version that is affected is 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology.  Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS Base Score depend on the software that uses Outside In Technology. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology, but if data is not received over a network the CVSS score may be lower. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2423</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Outside In Technology</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-2276V-8.5.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="294" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2424</Title>
      <Notes>
         <Note Audience="All" Ordinal="294" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure).  Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2424</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="295" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2425</Title>
      <Notes>
         <Note Audience="All" Ordinal="295" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2425</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="296" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2426</Title>
      <Notes>
         <Note Audience="All" Ordinal="296" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2426</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="297" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2427</Title>
      <Notes>
         <Note Audience="All" Ordinal="297" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2427</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="298" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2428</Title>
      <Notes>
         <Note Audience="All" Ordinal="298" Title="Details" Type="Details">Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2428</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2545V-12.1.3.0.0</ProductID>
            <ProductID>P-2545V-12.2.1.3.0</ProductID>
            <ProductID>P-2545V-12.2.1.4.0</ProductID>
            <ProductID>P-2545V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Coherence</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-2545V-12.1.3.0.0</ProductID>
            <ProductID>P-2545V-12.2.1.3.0</ProductID>
            <ProductID>P-2545V-12.2.1.4.0</ProductID>
            <ProductID>P-2545V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="299" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2429</Title>
      <Notes>
         <Note Audience="All" Ordinal="299" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.25 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2429</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="300" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2430</Title>
      <Notes>
         <Note Audience="All" Ordinal="300" Title="Details" Type="Details">Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters).   The supported version that is affected is 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology.  Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS Base Score depend on the software that uses Outside In Technology. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology, but if data is not received over a network the CVSS score may be lower. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2430</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Outside In Technology</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-2276V-8.5.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="301" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2431</Title>
      <Notes>
         <Note Audience="All" Ordinal="301" Title="Details" Type="Details">Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters).   The supported version that is affected is 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology.  Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS Base Score depend on the software that uses Outside In Technology. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology, but if data is not received over a network the CVSS score may be lower. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2431</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Outside In Technology</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-2276V-8.5.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="302" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2432</Title>
      <Notes>
         <Note Audience="All" Ordinal="302" Title="Details" Type="Details">Vulnerability in the Java SE product of Oracle Java SE (component: JNDI).   The supported version that is affected is Java SE: 7u301. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2432</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE:7u301</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Java SE JDK and JRE</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787003.1</URL>
            <ProductID>P-856V-Java SE:7u301</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="303" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2433</Title>
      <Notes>
         <Note Audience="All" Ordinal="303" Title="Details" Type="Details">Vulnerability in the Essbase Analytic Provider Services product of Oracle Essbase (component: Web Services).  Supported versions that are affected are 11.1.2.4 and  21.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Essbase Analytic Provider Services.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Essbase Analytic Provider Services. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2433</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4349V-11.1.2.4</ProductID>
            <ProductID>P-4349V-21.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Hyperion Analytic Provider Services</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-4349V-11.1.2.4</ProductID>
            <ProductID>P-4349V-21.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="304" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2434</Title>
      <Notes>
         <Note Audience="All" Ordinal="304" Title="Details" Type="Details">Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Application Service).  Supported versions that are affected are 12.1.3 and  12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Web Applications Desktop Integrator accessible data as well as  unauthorized access to critical data or complete access to all Oracle Web Applications Desktop Integrator accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2434</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1171V-12.1.3</ProductID>
            <ProductID>P-1171V-12.2.3-12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Web Applications Desktop Integrator</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2770321.1</URL>
            <ProductID>P-1171V-12.1.3</ProductID>
            <ProductID>P-1171V-12.2.3-12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="305" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2435</Title>
      <Notes>
         <Note Audience="All" Ordinal="305" Title="Details" Type="Details">Vulnerability in the Essbase Analytic Provider Services product of Oracle Essbase (component: JAPI).   The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Essbase Analytic Provider Services.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Essbase Analytic Provider Services accessible data as well as  unauthorized access to critical data or complete access to all Essbase Analytic Provider Services accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2435</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4349V-11.1.2.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Hyperion Analytic Provider Services</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-4349V-11.1.2.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="306" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2436</Title>
      <Notes>
         <Note Audience="All" Ordinal="306" Title="Details" Type="Details">Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Framework).  Supported versions that are affected are 12.1.1-12.1.3 and  12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Common Applications, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Common Applications accessible data as well as  unauthorized update, insert or delete access to some of Oracle Common Applications accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2436</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1198V-12.1.1-12.1.3</ProductID>
            <ProductID>P-1198V-12.2.3-12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Common Applications</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2770321.1</URL>
            <ProductID>P-1198V-12.1.1-12.1.3</ProductID>
            <ProductID>P-1198V-12.2.3-12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="307" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2437</Title>
      <Notes>
         <Note Audience="All" Ordinal="307" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2437</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="308" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2438</Title>
      <Notes>
         <Note Audience="All" Ordinal="308" Title="Details" Type="Details">Vulnerability in the Java VM component of Oracle Database Server.  Supported versions that are affected are 12.1.0.2, 12.2.0.1 and  19c. Easily exploitable vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to compromise Java VM.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java VM. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2438</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Database - Enterprise Edition</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="309" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2439</Title>
      <Notes>
         <Note Audience="All" Ordinal="309" Title="Details" Type="Details">Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (component: UI and Visualization).  Supported versions that are affected are 11.1.2.4 and  11.2.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion BI+.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Hyperion BI+ accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2439</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4361V-11.1.2.4</ProductID>
            <ProductID>P-4361V-11.2.5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Hyperion BI+</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-4361V-11.1.2.4</ProductID>
            <ProductID>P-4361V-11.2.5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="310" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2440</Title>
      <Notes>
         <Note Audience="All" Ordinal="310" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML).  Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2440</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="311" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2441</Title>
      <Notes>
         <Note Audience="All" Ordinal="311" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2441</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-8.0.25 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="312" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2442</Title>
      <Notes>
         <Note Audience="All" Ordinal="312" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is Prior to 6.1.24. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2442</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-Prior to 6.1.24</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.0</BaseScore>
            <Vector>AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>VM VirtualBox</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788251.1</URL>
            <ProductID>P-8370V-Prior to 6.1.24</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="313" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2443</Title>
      <Notes>
         <Note Audience="All" Ordinal="313" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is Prior to 6.1.24. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as  unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and  unauthorized read access to a subset of Oracle VM VirtualBox accessible data.  Note: This vulnerability applies to Solaris x86 and Linux systems only. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2443</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-Prior to 6.1.24</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.3</BaseScore>
            <Vector>AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>VM VirtualBox</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788251.1</URL>
            <ProductID>P-8370V-Prior to 6.1.24</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="314" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2444</Title>
      <Notes>
         <Note Audience="All" Ordinal="314" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2444</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.23 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Server</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8478V-8.0.23 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="315" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2445</Title>
      <Notes>
         <Note Audience="All" Ordinal="315" Title="Details" Type="Details">Vulnerability in the Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management).   The supported version that is affected is 11.2.5.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Infrastructure Technology.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Hyperion Infrastructure Technology accessible data as well as  unauthorized access to critical data or complete access to all Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2445</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4392V-11.2.5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.7</BaseScore>
            <Vector>AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Hyperion Infrastructure Technology</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-4392V-11.2.5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="316" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2446</Title>
      <Notes>
         <Note Audience="All" Ordinal="316" Title="Details" Type="Details">Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Client).   The supported version that is affected is 5.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Secure Global Desktop.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Secure Global Desktop, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Secure Global Desktop. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2446</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8539V-5.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Secure Global Desktop</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788251.1</URL>
            <ProductID>P-8539V-5.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="317" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2447</Title>
      <Notes>
         <Note Audience="All" Ordinal="317" Title="Details" Type="Details">Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Server).   The supported version that is affected is 5.6. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Secure Global Desktop.  While the vulnerability is in Oracle Secure Global Desktop, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Secure Global Desktop. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2447</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8539V-5.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.9</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Secure Global Desktop</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788251.1</URL>
            <ProductID>P-8539V-5.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="318" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2448</Title>
      <Notes>
         <Note Audience="All" Ordinal="318" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Crime and Compliance Investigation Hub product of Oracle Financial Services Applications (component: Reports).   The supported version that is affected is 20.1.2. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Financial Services Crime and Compliance Investigation Hub executes to compromise Oracle Financial Services Crime and Compliance Investigation Hub.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Crime and Compliance Investigation Hub, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Crime and Compliance Investigation Hub accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Crime and Compliance Investigation Hub accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2448</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13964V-20.1.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Financial Services Crime and Compliance Investigation Hub</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2792414.1</URL>
            <ProductID>P-13964V-20.1.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="319" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2449</Title>
      <Notes>
         <Note Audience="All" Ordinal="319" Title="Details" Type="Details">Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters).   The supported version that is affected is 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology.  Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS Base Score depend on the software that uses Outside In Technology. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology, but if data is not received over a network the CVSS score may be lower. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2449</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Outside In Technology</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-2276V-8.5.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="320" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2450</Title>
      <Notes>
         <Note Audience="All" Ordinal="320" Title="Details" Type="Details">Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters).   The supported version that is affected is 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology.  Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS Base Score depend on the software that uses Outside In Technology. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology, but if data is not received over a network the CVSS score may be lower. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2450</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Outside In Technology</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-2276V-8.5.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="321" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2451</Title>
      <Notes>
         <Note Audience="All" Ordinal="321" Title="Details" Type="Details">Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters).   The supported version that is affected is 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology.  Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS Base Score depend on the software that uses Outside In Technology. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology, but if data is not received over a network the CVSS score may be lower. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2451</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Outside In Technology</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-2276V-8.5.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="322" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2452</Title>
      <Notes>
         <Note Audience="All" Ordinal="322" Title="Details" Type="Details">Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters).   The supported version that is affected is 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology.  Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS Base Score depend on the software that uses Outside In Technology. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology, but if data is not received over a network the CVSS score may be lower. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2452</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Outside In Technology</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-2276V-8.5.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="323" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2453</Title>
      <Notes>
         <Note Audience="All" Ordinal="323" Title="Details" Type="Details">Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters).   The supported version that is affected is 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology.  Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS Base Score depend on the software that uses Outside In Technology. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology, but if data is not received over a network the CVSS score may be lower. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2453</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Outside In Technology</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-2276V-8.5.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="324" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2454</Title>
      <Notes>
         <Note Audience="All" Ordinal="324" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is Prior to 6.1.24. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2454</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-Prior to 6.1.24</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.0</BaseScore>
            <Vector>AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>VM VirtualBox</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788251.1</URL>
            <ProductID>P-8370V-Prior to 6.1.24</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="325" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2455</Title>
      <Notes>
         <Note Audience="All" Ordinal="325" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Person Search).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Shared Components.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise HCM Shared Components accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise HCM Shared Components accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2455</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8943V-9.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>PeopleSoft Enterprise HCM Shared Components</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788006.1</URL>
            <ProductID>P-8943V-9.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="326" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2456</Title>
      <Notes>
         <Note Audience="All" Ordinal="326" Title="Details" Type="Details">Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2456</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2025V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Business Intelligence Enterprise Edition</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-2025V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="327" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2457</Title>
      <Notes>
         <Note Audience="All" Ordinal="327" Title="Details" Type="Details">Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Request Management &amp; Workflow).   The supported version that is affected is 11.1.2.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Identity Manager accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2457</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1980V-11.1.2.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Identity Manager</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-1980V-11.1.2.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="328" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2458</Title>
      <Notes>
         <Note Audience="All" Ordinal="328" Title="Details" Type="Details">Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Identity Console).  Supported versions that are affected are 11.1.2.2.0, 11.1.2.3.0, 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Identity Manager, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Identity Manager accessible data as well as  unauthorized update, insert or delete access to some of Identity Manager accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2458</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1980V-11.1.2.2.0</ProductID>
            <ProductID>P-1980V-11.1.2.3.0</ProductID>
            <ProductID>P-1980V-12.2.1.3.0</ProductID>
            <ProductID>P-1980V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.6</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Identity Manager</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-1980V-11.1.2.2.0</ProductID>
            <ProductID>P-1980V-11.1.2.3.0</ProductID>
            <ProductID>P-1980V-12.2.1.3.0</ProductID>
            <ProductID>P-1980V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="329" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2460</Title>
      <Notes>
         <Note Audience="All" Ordinal="329" Title="Details" Type="Details">Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server.   The supported version that is affected is Prior to 21.1.0.00.04. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Data Reporter.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express Data Reporter, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Application Express Data Reporter accessible data as well as  unauthorized read access to a subset of Oracle Application Express Data Reporter accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2460</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1348V-Prior to 21.1.0.00.04</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Application Express (APEX)</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-1348V-Prior to 21.1.0.00.04</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="330" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2462</Title>
      <Notes>
         <Note Audience="All" Ordinal="330" Title="Details" Type="Details">Vulnerability in the Oracle Commerce Service Center product of Oracle Commerce (component: Commerce Service Center).  Supported versions that are affected are 11.0.0, 11.1.0, 11.2.0 and  11.3.0-11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Service Center.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Service Center, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Commerce Service Center accessible data as well as  unauthorized read access to a subset of Oracle Commerce Service Center accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2462</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9351V-11.0.0</ProductID>
            <ProductID>P-9351V-11.1.0</ProductID>
            <ProductID>P-9351V-11.2.0</ProductID>
            <ProductID>P-9351V-11.3.0-11.3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Commerce Service Center</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2792990.1</URL>
            <ProductID>P-9351V-11.0.0</ProductID>
            <ProductID>P-9351V-11.1.0</ProductID>
            <ProductID>P-9351V-11.2.0</ProductID>
            <ProductID>P-9351V-11.3.0-11.3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="331" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-2463</Title>
      <Notes>
         <Note Audience="All" Ordinal="331" Title="Details" Type="Details">Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework).  Supported versions that are affected are 11.0.0, 11.1.0, 11.2.0 and  11.3.0-11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-2463</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9348V-11.0.0</ProductID>
            <ProductID>P-9348V-11.1.0</ProductID>
            <ProductID>P-9348V-11.2.0</ProductID>
            <ProductID>P-9348V-11.3.0-11.3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Commerce Platform</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2792990.1</URL>
            <ProductID>P-9348V-11.0.0</ProductID>
            <ProductID>P-9348V-11.1.0</ProductID>
            <ProductID>P-9348V-11.2.0</ProductID>
            <ProductID>P-9348V-11.3.0-11.3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="332" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-25122</Title>
      <Notes>
         <Note Audience="All" Ordinal="332" Title="Details" Type="Details">Vulnerability in the Instantis EnterpriseTrack product of Oracle Construction and Engineering (component: HTTP Server (Apache Tomcat)).  Supported versions that are affected are 17.1, 17.2 and  17.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Instantis EnterpriseTrack.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Instantis EnterpriseTrack accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-25122</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10563V-17.1</ProductID>
            <ProductID>P-10563V-17.2</ProductID>
            <ProductID>P-10563V-17.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Instantis EnterpriseTrack</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783281.1</URL>
            <ProductID>P-10563V-17.1</ProductID>
            <ProductID>P-10563V-17.2</ProductID>
            <ProductID>P-10563V-17.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="333" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-25122</Title>
      <Notes>
         <Note Audience="All" Ordinal="333" Title="Details" Type="Details">Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server (Apache Tomcat)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Managed File Transfer.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Managed File Transfer accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-25122</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10198V-12.2.1.3.0</ProductID>
            <ProductID>P-10198V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Managed File Transfer</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-10198V-12.2.1.3.0</ProductID>
            <ProductID>P-10198V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="334" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-25122</Title>
      <Notes>
         <Note Audience="All" Ordinal="334" Title="Details" Type="Details">Vulnerability in the MySQL Enterprise Monitor product of Oracle MySQL (component: Monitoring: General (Apache Tomcat)).  Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS/2 to compromise MySQL Enterprise Monitor.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all MySQL Enterprise Monitor accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-25122</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8480V-8.0.23 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Enterprise Monitor</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8480V-8.0.23 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="335" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-26117</Title>
      <Notes>
         <Note Audience="All" Ordinal="335" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Private Banking product of Oracle Financial Services Applications (component: Financial Planning  (Apache ActiveMQ)).  Supported versions that are affected are 12.0.0 and  12.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking.  Successful attacks of this vulnerability can result in takeover of Oracle FLEXCUBE Private Banking. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-26117</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9110V-12.0.0</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>FLEXCUBE Private Banking</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com</URL>
            <ProductID>P-9110V-12.0.0</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="336" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-26272</Title>
      <Notes>
         <Note Audience="All" Ordinal="336" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security (CKEditor)).  Supported versions that are affected are 9.3.5 and  9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile PLM. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-26272</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.5</ProductID>
            <ProductID>P-4461V-9.3.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Agile PLM Framework</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787997.1</URL>
            <ProductID>P-4461V-9.3.5</ProductID>
            <ProductID>P-4461V-9.3.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="337" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-26272</Title>
      <Notes>
         <Note Audience="All" Ordinal="337" Title="Details" Type="Details">Vulnerability in the Oracle Commerce Merchandising product of Oracle Commerce (component: Experience Manager, Business Control Center  (CKEditor)).  Supported versions that are affected are 11.1.0, 11.2.0 and  11.3.0-11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Merchandising.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Merchandising. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-26272</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9349V-11.1.0</ProductID>
            <ProductID>P-9349V-11.2.0</ProductID>
            <ProductID>P-9349V-11.3.0-11.3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Commerce Merchandising</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2792990.1</URL>
            <ProductID>P-9349V-11.1.0</ProductID>
            <ProductID>P-9349V-11.2.0</ProductID>
            <ProductID>P-9349V-11.3.0-11.3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="338" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-27568</Title>
      <Notes>
         <Note Audience="All" Ordinal="338" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: REST Services (netplex json-smart-v1)).  Supported versions that are affected are 8.58 and  8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-27568</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>PeopleSoft Enterprise PT PeopleTools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788006.1</URL>
            <ProductID>P-5085V-8.58</ProductID>
            <ProductID>P-5085V-8.59</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="339" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-27807</Title>
      <Notes>
         <Note Audience="All" Ordinal="339" Title="Details" Type="Details">Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Segment (Apache PDFbox)).   The supported version that is affected is 19.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Customer Management and Segmentation Foundation.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Customer Management and Segmentation Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Customer Management and Segmentation Foundation accessible data as well as  unauthorized read access to a subset of Oracle Retail Customer Management and Segmentation Foundation accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-27807</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13388V-19.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Retail Customer Management and Segmentation Foundation</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783353.1</URL>
            <ProductID>P-13388V-19.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="340" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-27906</Title>
      <Notes>
         <Note Audience="All" Ordinal="340" Title="Details" Type="Details">Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Clean Content SDK (Apache PDFBox)).   The supported version that is affected is 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-27906</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Outside In Technology</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2773670.1</URL>
            <ProductID>P-2276V-8.5.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="341" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-27906</Title>
      <Notes>
         <Note Audience="All" Ordinal="341" Title="Details" Type="Details">Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Core (Apache PDFbox)).  Supported versions that are affected are 17.7-17.12, 18.8, 19.12 and  20.12. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Primavera Unifier executes to compromise Primavera Unifier.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Primavera Unifier. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-27906</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10354V-17.7-17.12</ProductID>
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
            <ProductID>P-10354V-20.12</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Primavera Unifier</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2783281.1</URL>
            <ProductID>P-10354V-17.7-17.12</ProductID>
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
            <ProductID>P-10354V-20.12</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="342" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-29921</Title>
      <Notes>
         <Note Audience="All" Ordinal="342" Title="Details" Type="Details">Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Python interpreter and runtime (CPython)).  Supported versions that are affected are Oracle GraalVM Enterprise Edition: 20.3.2 and  21.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle GraalVM Enterprise Edition. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-29921</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13497V-Oracle GraalVM Enterprise Edition:20.3.2</ProductID>
            <ProductID>P-13497V-Oracle GraalVM Enterprise Edition:21.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>GraalVM Enterprise Edition</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787003.1</URL>
            <ProductID>P-13497V-Oracle GraalVM Enterprise Edition:20.3.2</ProductID>
            <ProductID>P-13497V-Oracle GraalVM Enterprise Edition:21.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="343" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-3156</Title>
      <Notes>
         <Note Audience="All" Ordinal="343" Title="Details" Type="Details">Vulnerability in the MICROS Compact Workstation 3 product of Oracle Food and Beverage Applications (component: Workstation 310 (Sudo)).   The supported version that is affected is 310. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MICROS Compact Workstation 3 executes to compromise MICROS Compact Workstation 3.  Successful attacks of this vulnerability can result in takeover of MICROS Compact Workstation 3. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-3156</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13794V-310</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MICROS Compact Workstation 3</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2758251.1</URL>
            <ProductID>P-13794V-310</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="344" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-3156</Title>
      <Notes>
         <Note Audience="All" Ordinal="344" Title="Details" Type="Details">Vulnerability in the MICROS ES400 Series product of Oracle Food and Beverage Applications (component: Express Station 4 (Sudo)).  Supported versions that are affected are 400-410. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MICROS ES400 Series executes to compromise MICROS ES400 Series.  Successful attacks of this vulnerability can result in takeover of MICROS ES400 Series. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-3156</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-14212V-400-410</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MICROS ES400 Series</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2758251.1</URL>
            <ProductID>P-14212V-400-410</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="345" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-3156</Title>
      <Notes>
         <Note Audience="All" Ordinal="345" Title="Details" Type="Details">Vulnerability in the MICROS Kitchen Display System Hardware product of Oracle Food and Beverage Applications (component: Kitchen Display System 210 (Sudo)).   The supported version that is affected is 210. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MICROS Kitchen Display System Hardware executes to compromise MICROS Kitchen Display System Hardware.  Successful attacks of this vulnerability can result in takeover of MICROS Kitchen Display System Hardware. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-3156</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11641V-210</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MICROS Kitchen Display System Hardware</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2758251.1</URL>
            <ProductID>P-11641V-210</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="346" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-3156</Title>
      <Notes>
         <Note Audience="All" Ordinal="346" Title="Details" Type="Details">Vulnerability in the MICROS Workstation 5A product of Oracle Food and Beverage Applications (component: Workstation 5A (Sudo)).   The supported version that is affected is 5A. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MICROS Workstation 5A executes to compromise MICROS Workstation 5A.  Successful attacks of this vulnerability can result in takeover of MICROS Workstation 5A. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-3156</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11636V-5A</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MICROS Workstation 5A</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2758251.1</URL>
            <ProductID>P-11636V-5A</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="347" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-3156</Title>
      <Notes>
         <Note Audience="All" Ordinal="347" Title="Details" Type="Details">Vulnerability in the MICROS Workstation 6 product of Oracle Food and Beverage Applications (component: Workstation 6 (Sudo)).  Supported versions that are affected are 610-655. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MICROS Workstation 6 executes to compromise MICROS Workstation 6.  Successful attacks of this vulnerability can result in takeover of MICROS Workstation 6. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-3156</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11628V-610-655</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MICROS Workstation 6</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2758251.1</URL>
            <ProductID>P-11628V-610-655</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="348" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-3177</Title>
      <Notes>
         <Note Audience="All" Ordinal="348" Title="Details" Type="Details">Vulnerability in the Oracle Communications Offline Mediation Controller product of Oracle Communications Applications (component: UDC CORE (Python)).   The supported version that is affected is 12.0.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Offline Mediation Controller.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Offline Mediation Controller. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-3177</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2269V-12.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Offline Mediation Controller</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2785182.1</URL>
            <ProductID>P-2269V-12.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="349" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-3177</Title>
      <Notes>
         <Note Audience="All" Ordinal="349" Title="Details" Type="Details">Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Operating System Image).   The supported version that is affected is 8.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle ZFS Storage Appliance Kit.  Successful attacks of this vulnerability can result in takeover of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-3177</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10026V-8.8</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Sun ZFS Storage Appliance Kit (AK) Software</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788472.1</URL>
            <ProductID>P-10026V-8.8</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="350" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-3345</Title>
      <Notes>
         <Note Audience="All" Ordinal="350" Title="Details" Type="Details">Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Accounts Receivable (libgcrypt)).   The supported version that is affected is 12.0.0.3.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Billing and Revenue Management executes to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-3345</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2136V-12.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>Communications Billing and Revenue Management</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2785183.1</URL>
            <ProductID>P-2136V-12.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="351" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-3450</Title>
      <Notes>
         <Note Audience="All" Ordinal="351" Title="Details" Type="Details">Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++ (OpenSSL)).  Supported versions that are affected are 8.0.23 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Connectors accessible data as well as  unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-3450</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8576V-8.0.23 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.4</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Connectors</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8576V-8.0.23 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="352" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-3450</Title>
      <Notes>
         <Note Audience="All" Ordinal="352" Title="Details" Type="Details">Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC (OpenSSL)).  Supported versions that are affected are 8.0.23 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Connectors accessible data as well as  unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-3450</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8576V-8.0.23 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.4</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Connectors</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8576V-8.0.23 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="353" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-3450</Title>
      <Notes>
         <Note Audience="All" Ordinal="353" Title="Details" Type="Details">Vulnerability in the MySQL Enterprise Monitor product of Oracle MySQL (component: Monitoring: General (OpenSSL)).  Supported versions that are affected are 8.0.23 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise MySQL Enterprise Monitor.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Enterprise Monitor accessible data as well as  unauthorized access to critical data or complete access to all MySQL Enterprise Monitor accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-3450</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8480V-8.0.23 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.4</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>MySQL Enterprise Monitor</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2787955.1</URL>
            <ProductID>P-8480V-8.0.23 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="354" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2021-3450</Title>
      <Notes>
         <Note Audience="All" Ordinal="354" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security (OpenSSL)).  Supported versions that are affected are 8.57 and  8.58. 8.59. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2021-3450</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58. 8.59</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.4</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>PeopleSoft Enterprise PT PeopleTools</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://support.oracle.com/rs?type=doc&amp;amp;id=2788006.1</URL>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58. 8.59</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
</cvrf:cvrfdoc>
